Home Blog Page 144

Ransomware Attacks Continue to Impact Digital and Security Transformation

Ransomware attacks, ransomware, Sinclair Broadcast group

A recent survey from CrowdStrike highlighted the continued spread of ransomware and the need for acceleration of both digital and security transformation. In its “2020 CrowdStrike Global Security Attitude Survey,” the cybersecurity firm revealed the growing concern of nation-state intrusions or ransomware attacks, with 56% of organizations reporting a ransomware attack in the last year.

“The COVID-19 pandemic catalyzed increasing concerns around ransomware attacks, with many organizations resorting to paying the ransom. The shifts from a question of if an organization will experience a ransomware attack to a matter of when an organization will inevitably pay a ransom,” the report global attitude stated.

Key Findings

  • Among those hit by ransomware, 27% chose to pay the ransom, costing organizations on average $1.1 million owed to hackers.
  • Concern around ransomware attacks continues to increase, with the stark increase in this year’s findings (54%) compared to 2019 (42%) and 2018 (46%).
  • 71% of cybersecurity experts globally are more worried about ransomware attacks due to COVID-19.
  • The APAC region is suffering the most when paying the ransom with the highest average payout at $1.18 million, followed by EMEA at $1.06 million and the U.S. at $0.99 million.
  • Nearly, 73% believe nation-state sponsored cyberattacks will pose the single biggest threat to organizations like theirs in 2021. In fact, concerns around nation-states have steadily increased, as 63% of cybersecurity experts view nation-states as one of the cyber criminals most likely to cause concern, consistently rising from 2018 (54%) and 2019 (59%).
  • 89% are fearful that growing international tensions are likely to result in a considerable increase in cyberthreats for organizations.
  • 61% of respondents’ organizations have spent more than $1 million on digital transformation over the past three years.
  • 90% of respondents’ organizations have spent a minimum of $100,000 to adapt to the COVID-19 pandemic.
  • 66% of respondents have modernized their security tools and/or increased the rollout of cloud technologies as employees have moved to work remotely.
  • 78% of respondents have a more positive outlook on their organization’s overarching security strategy and architecture over the next 12 months.

Michael Sentonas, Chief Technology Officer at CrowdStrike, said, “This year has been especially challenging for organizations of all sizes around the world, with both the proliferation of ransomware and growing tensions from nation-state actors posing a massive threat to regions worldwide. Now more than ever, organizations are finding ways to rapidly undergo digital transformation to bring their security to the cloud to keep pace with modern-day threats and secure their ‘work from anywhere’ operations.”

Surge in Online Shopping is a Special Offer for Cybercriminals: McAfee

Ask Yourself These 4 Questions Before Shopping Online

Despite the awareness on increased risks and scams in the e-commerce sector, customers still plan to shop more online with a whopping 36% of Americans stating that they are hitting the digital links. According to a survey from McAfee, 60% of consumers felt that cyber scams become more prevalent during the holiday season. In its survey report, “2020 Holiday Season: State of Today’s Digital e-Shopper”, McAfee revealed that online shopping activity increased, with 49% stating they are buying more from virtual stores since the onset of COVID-19. Nearly, 18% of consumers are even shopping online daily, while 34% shop online 3-5 days a week.

McAfee said that it noticed over 419 cyberthreats per minute in Q2 2020, which is a surge of 12% compared to the previous year. While 79% of those respondents above the age of 65 believe there is a greater cyber risk due to COVID-19 than less (70%) of respondents between the age of 18-24 said the same. 27% of respondents between the ages 18 to 24 check if emails or text messages on discounts and deals sent to them are authentic.

In addition, McAfee stated that the National Retail Federation (NRF) reported 54% of consumers wish to receive gift cards this holiday season. The survey proved that 35% of respondents plan to fulfill this request by purchasing more online gift cards this year.

Judith Bitterli, VP of Consumer Marketing, said, “Many are wondering what this year’s holiday season will look like as consumer shopping behaviors continue to evolve and adapt to the challenges faced throughout 2020. With results showing the growing prevalence of online shopping, consumers need to be aware of how cybercriminals are looking to take advantage and take the necessary steps to protect themselves- and their loved ones- this holiday season.” 

How to Shop Safe Online

In order to stay safe while shopping online, McAfee advises:

  • Employ multi-factor authentication to double check the authenticity of digital users and add an additional layer of security to protect personal data and information.
  • Browse with caution and be vigilant on what you are clicking, as it may be a malware or phishing links.

Related Story: Ask Yourself These 4 Questions Before Shopping Online

“Relying heavily on firewalls does nothing against determined adversaries”

Tim Bandos was recently announced as the Chief Information Security Officer (CISO) for Digital Guardian. He has over 15 years of experience to the position including his five years as VP of cybersecurity at Digital Guardian. Prior to joining Digital Guardian, Bandos was Director of Cybersecurity for Dupont where he was responsible for overseeing internal controls, incident response, and threat intelligence.

In a recent interview with Augustin Kurian from CISO MAG, Tim spoke about console management, blockchain, effective implementation of USB control and encryption, shadow IoT among several other trends.

In most enterprises, the endpoint security realm is about managing multiple management consoles, each reporting their point of view on devices’ health. The situation becomes complicated when the may-a-time consoles can’t even agree on the inventory count as each of them reports independent numbers with considerable time spent on reconciliation. You have been tasked with the development of DG EDR. How do you think this problem can be fixed? 

This particular problem around asset inventory plagues many organizations and there are varying reasons why they all report disparate numbers amongst each other. Some security solutions may not support certain operating system types, or as devices go offline, they’re not properly being updated in the list. I believe relying entirely on a technology to do this is not the best approach. It requires a process as well to adequately account for all IT assets in your inventory, which gets continuously updated and reviewed. Network scanners can do a great job at identifying live nodes on a network and even identifying potential rogue endpoints. Coupling that data with your inventory list is essential, in addition to knowing the primary usage of the device and whether it stores sensitive data. This upfront work will dramatically increase your success in rolling out an EDR program. If you miss even a single device, such as an externally facing RDP server used for remote access, it could be used as an entrance vector by an adversary. If that turns out to be the case, your visibility into detecting that attack is now zero. So, acquiring complete coverage will require a bit of upfront work first to ensure your entire enterprise is being monitored appropriately.

How do you see the uptake for managed security services today, as compared to, say, two years ago? From which types of businesses (small, medium, large) do you see the maximum uptake for outsourced security services? (Nearly half of all cyberattacks in the U.S. target SMBs). What is driving demand for managed security services?

I’ve seen a dramatic increase in SMBs latching on to managed security services over the last several years given the number of benefits that can be derived out of the partnership. One of the most difficult challenges is hiring employees with the right level of skills to cover the broad swath of capabilities required to sufficiently protect an organization. Take Incident Response for example – if a cyberattack occurs, you would need a fleet of resources with the ability to conduct digital forensics, log analysis, possibly reverse engineering, and more. Managed security services provide these capabilities on Day 1 and you no longer have to rely on the single IT guy wearing 15 different hats. The benefits of a managed solution, such as more time to focus on your business, lowering your costs in multiple areas, quick access to expertise, etc., all drive this growing demand we’ve observed recently.

How do you think MSMEs are handling cybersecurity post-COVID-19? You have pointed out that there are hundreds of terabytes of potentially sensitive, unencrypted corporate data floating around at any given time due to an increase in the volume of data downloaded to USB media by employees since the onset of COVID-19. What are your suggestions for smaller companies for effective implementation of USB control and encryption?

I believe it’s been difficult for some MSME’s to properly address cybersecurity-related concerns during this pandemic. Implementing controls and purchasing technology during a time when funds and even resources may be strapped is a considerable challenge. We’ve seen this play out with the amount of data egress occurring across our managed services customer base; specifically to USB devices and various cloud storage sites. It comes down to the culture and workflow you’re looking to set in your organization. Having policies in place that prevent USB usage can be enforced with Group Policy Object  (GPO ) settings along with requiring users to encrypt their PCs with something like BitLocker. When it comes to filesharing and interacting with sensitive data, it’s important to store them in a technology that provides you control over permissions, the ability to encrypt, password protect, classify, etc. Services like OneDrive or Dropbox have these types of features, which can provide a significant level of comfort with how your employees access, interact with, and share sensitive information such as financial, legal, or HR data.

The virtualization of computing, software-defined storage, and networking has given birth to hyperconverged infrastructures. Implicit trust is gone and has made way for a more effective practice- explicit identity-based trust. The rapid shift to work-from-home has accelerated the adoption of Zero Trust frameworks. Do you believe Zero Trust-as-a-Service will be a necessary component of security strategies for 2021 and beyond? 

Absolutely. I believe you’ll see a significant increase in the adoption of a Zero Trust-as-a-Service model being used in security strategies beyond 2021. We’ve learned over the years that relying heavily on network security such as firewalls does almost nothing for you when faced with determined adversaries. Also, as organizations move more of their workloads to the cloud, it only becomes more imperative to protect and restrict those whom have access and ensure you have the right level of visibility. This approach will require more granular perimeter enforcements based on who the user is, where they are located, and other elements of data to determine the level of trust that’s granted. Implementing this type of strategy is not something that’ll occur overnight. My recommendation to organizations looking to embrace the Zero Trust model is to first design it and try to avoid the incorporation of legacy systems that aren’t fully capable of taking this journey. For larger and more complex businesses, this may be a multi-year project depending on your IT environment. But for smaller and medium-sized companies, it could be a great opportunity to completely transform how they approach cybersecurity that’ll ultimately protect them from advances being made by threat actors.

Read a longer version of this interview in the next issue of CISO MAG.

Subscribe here

Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

‘Mudge’ is Twitter’s New Head of Security

Celebrated hacker Peiter Zatko AKA ‘Mudge’ will take over as the new Head of Security for Twitter. He would be taking his office after a 45- to 60-day review of the platform’s current measures and practices. Reports indicate that Zatko will directly report to CEO Jack Dorsey. In an exclusive with Reuters Zatko also said he will examine “information security, site integrity, physical security, platform integrity — which starts to touch on abuse and manipulation of the platform — and engineering.”

For the uninitiated, Peiter Zatko is among one of the most high-profile hackers in the world. He was also a member of L0pht, a hacker collective that testified in front of Congress on “Weak Computer Security in Government.” During his time with L0pht, Mudge highlighted several security vulnerabilities and also campaigned for safer cyberspace. He has also been credited with releasing several cybersecurity advisories and is also the author of L0phtCrack, a password cracking software.

He has also served in several leadership roles in agencies like DARPA and was also a part of Google’s Advanced Technology and Projects division.

“Looks like the cat is out of the bag. I’m very excited to be joining the executive team at Twitter! I truly believe in the mission of (equitably) serving the public conversation. I will do my best!” Zatko tweeted about his appointment.

This is the second key cybersecurity-related appointment Twitter has in the last couple of months following the mega hack. The short message platform had also come under severe criticism following the account breach of several global leaders and other verified high-profile accounts. During the attack, hackers broke into the backend admin tools and plugged cryptocurrency scams into the high-profile accounts. Following the attack, Twitter had locked and suspended all operations of the affected accounts to investigate the cause and extent of the breach. It also wanted to make sure whether any additional user information was compromised and if any backdoors were created for future account takeovers.

Toward the end of September, Twitter appointed cybersecurity veteran Rinki Sethi as the Chief Information Security Officer.

Lazarus Strikes Again, Attacks Supply Chain in South Korea

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Security researchers from ESET found cybercriminals linked to North-Korean Lazarus group targeting South Korean supply-chains. It was found that attackers exploited legitimate South Korean security software and digital certificates stolen from two different companies to distribute their malware. The hacker group also used illicitly obtained code to sign the malware samples.

Lazarus Supply Chain Attacks

ESET’s researchers stated that South Koreans are often asked to download additional security software while visiting government or banking services online. It is found that attackers abused this process to deploy Lazarus malware from a compromised legitimate website.

“To understand this novel supply-chain attack, you should be aware that WIZVERA VeraPort, referred to as an integration installation program, is a South Korean application that helps manage such additional security software. When WIZVERA VeraPort is installed, users receive and install all necessary software required by a specific website. Minimal user interaction is required to start such software installation. Usually this software is used by government and banking websites in South Korea. For some of these websites it’s mandatory to have WIZVERA VeraPort installed,” explains Anton Cherepanov, ESET researcher who led the investigation into the attack.

“The attackers camouflaged the Lazarus malware samples as legitimate software. These samples have similar file names, icons, and resources as legitimate South Korean software. It’s the combination of compromised websites with WIZVERA VeraPort support and specific VeraPort configuration options that allows attackers to perform this attack,” says Peter Kálnai, ESET researcher who analyzed the Lazarus attack with Cherepanov.

The Lazarus Timeline

The Lazarus hacking Group was involved in multiple cyberattacks earlier. In 2018, Kaspersky uncovered AppleJeus, a malicious operation by Lazarus Group to intrude on cryptocurrency exchanges and applications. In December 2019, the researchers discovered a malware dubbed as “Fileless” distributed by the Lazarus group.  For full story click here…

No More “Zoombombers” on Zoom Calls; Zoom Upgrades its Cybersecurity Feature

zoombombers

Video conferencing app maker, Zoom, has launched a new feature in its latest update that will help the conference hosts to block uninvited guests known as “Zoombombers,” from entering the calls. Zoom calls this new feature, “At Risk Meeting Notifier.”

What is “Zoombombing”

Zoombombing attack is an instance where uninvited guests connect to a Zoom meeting room and disrupt the meeting by doing non-contextual things like hurling insults, playing pornographic content, or making threats to other participants. Typically, a Zoombombing incident takes place when participants knowingly or unknowingly shares a Zoom meeting ID (and sometimes its password) on social media, or discussion forums like Reddit and Quora threads.

How “At Risk Meeting Notifier” Will Help

The At Risk Meeting Notifierfeature will constantly run on Zoom’s backend servers. It is a fully automated process with no manual intervention required. This feature constantly scans and compares the Zoom’s Meeting ID of the conference call against the posts published across social media platforms and certain open web resources like Reddit and Quora.

Upon finding a match, Zoom automatically sends an alert to the meeting host informing them of the match via email. The hosts can then take remedial measures of blocking that Zoombomber by changing the password or scheduling a new meeting to avoid a possible hijack of the meeting.

Related Podcast:

Episode #3: How Zoom is Enhancing Security and Evolving its Product

How to Stop a Zoombomber if he is Already in the Meeting

There is a possibility that participants may leak the meeting credentials to a Zoombomber purposely to cause chaos. So, to stop a Zoombomber who has already entered a meeting, Zoom has introduced a Suspend Participant Activities option under the security icon. When the host clicks on this option, all video, audio, in-meeting chat, annotations, screen sharing, and recording is suspended, and all breakout rooms are ended. This should shut down the Zoombomber’s activity immediately. From there, Zoom will ask the host if they want to report a user, and if they do, that user will be removed from the meeting and Zoom’s security team will be notified.

Things to do If You Receive Mail from the “At Risk Meeting Notifier”

Zoom strongly recommends the following actions if admins receive a notification email from Zoom’s new cybersecurity feature:

  • Firstly, report the public post where the Meeting ID has been published. Ask the site admins to remove the link from their website/platform.
  • Delete the existing meeting and schedule a new one instead with a new Meeting ID and additional authentication of a Password/Passcode. This makes the meeting private.
  • Send the new Meeting ID exclusively to only the participants you trust.
  • Enable the following security settings for your meeting/conference call:
    • Meeting password/passcode
    • Waiting room
    • Meeting registration

Additionally, Zoom recommends that if canceling and rescheduling the public meeting is not possible then convert the meeting to a webinar as this gives the host control over who participates with video, audio, chat, and screen sharing.

Related News:

Zoom Beefs Up Security with Two-Factor Authentication

How to Prevent Zoom Credential Theft

Cybercriminals Move to Cloud! Hackers Selling Credentials via “Cloud of Logs”

Cloud of Logs dark web market

A new research from Trend Micro revealed that cybercriminals are using cloud services to accelerate their attacks, in turn decreasing the amount of time enterprises have to identify and respond to a breach. The research also found an underground market “Cloud of Logs” operated by malicious actors who sell stolen credentials to other hacker forums.

Massive Data Trade on Dark Web

Trend Micro stated that terabytes of stolen data trading in cloud logs are making cyberattacks more widespread and effective globally. Information about internal business data and logins for popular providers like Amazon, Google, Twitter, Facebook, and PayPal are put up on sale on the dark web. Attackers sell these logs of cloud data on a subscription basis for $1,000 per month. Access to a single log can include millions of records, where frequently updated data sets can even fetch higher prices.

Trend Micro warned that easy access to stolen credentials allow cybercriminals to streamline and accelerate the execution of attacks and potentially expand their number of targets.

“Once access is purchased for logs of cloud-based stolen data, the purchaser will use the information for secondary infection. For example, Remote Desktop Protocol (RDP) credentials can be found in these logs and are a popular entry point for criminals targeting enterprises with ransomware. This data is sold via access to the cloud logs in which it is stored. This results in more stolen accounts being monetized, and the time from initial data theft to stolen information being used against an enterprise has decreased from weeks to days or hours,” the report said.

Robert McArdle, director of forward-looking threat research for Trend Micro, said, “The new market for access to cloud logs ensures stolen information can be used more quickly and effectively by the cybercrime community—that’s bad news for enterprise security teams. This new cybercriminal market shows how criminals are using cloud technologies to compromise you. Which also means a business is not exempt from this attack method if they only use on-prem services. All organizations will need to double down on preventative measures and ensure they have the visibility and controls needed to react fast to any incidents that occur.”

Australia CISO Confluence: Cybersecurity in a Hyper Connected Ecosystem

For a slew of cybersecurity experts comprising of CEOs, CISOs, CIOs, Vice Presidents, and executives from over 60 countries, CISO MAG hosted the much-awaited Australia CISO Confluence toward the end of October. The confluence had Rapid7 as the Bronze Partner, AISA as the Media Partner, with ITSMF Australia as the supporting associate. The theme of the confluence was Cybersecurity in a Hyper Connected Ecosystem. The discussion took a virtual format to create awareness on the need for cybersecurity and its related implications in times of a pandemic.

The confluence derived realistic insights from senior industry experts on how to redefine security frameworks, mitigate threats and encourage a new culture of cybersecurity to sustain continuity across the region’s business intensive digital ecosystems. The key discussions in the confluence included:

1. Cyber Security Strategy 2020: Public-Private Partnerships to overhaul the cyber resilience of critical infrastructure networks and systems by Damien Manuel, Chairman, Australian Information Security Association

https://www.youtube.com/watch?v=jKxpubM_opw&t=45s&ab_channel=CISOMAG

During the session, Damien Manuel, Chairman, Australian Information Security Association stressed why public-private collaboration is important, who is really responsible for cybersecurity, and also touched on who will do what in the Australian Cyber Security Strategy 2020. He said collaboration is extremely important as the threat paradigm has significantly changed, especially with the rapid adoption of digital technology in the post-COVID-19 world that we now live in.

2. Zero trust – Demystified by Ashwin Pal, Director Cybersecurity, Unisys Asia Pacific

https://www.youtube.com/watch?v=_jLjET_dgVA&list=PLRmoLV6UOL5y09q_q8tMUMz6Z-1YqRmeM&index=1&ab_channel=CISOMAG

In this session, Ashwin Pal, Director Cybersecurity, Unisys Asia Pacific spoke about the concept of zero-trust and how it dates 10 years back. He also discussed key components of zero-trust, the relevance of perimeter, the M&M security model, and challenges that come in with the Zero-Trust philosophy and the key lessons to be learned from his own experiences.

3. Tackling Insider Threat Attacks – Salvatore Trimboli, Chief Technology Officer, E.L & C. Baillieu Limited

https://www.youtube.com/watch?v=8fSQf4zevqs&ab_channel=CISOMAG

In this session, Salvatore Trimboli, Chief Technology Officer, E.L & C. Baillieu Limited spoke about the types of insider threats, the prevention techniques, governance, risk assessment, threat program, and culture. He spoke in-depth about prioritizing the security of critical assets, periodic risk assessments, instilling a culture of data security, and implementing threat aversion protocols.

4. Panel Discussion: Deploying a zero-trust architecture to protect critical functionality and services while securing business continuity

https://www.youtube.com/watch?v=lUFR9flQbT4&ab_channel=CISOMAG

Participants of the panel discussion included:

  • Helaine Leggat, Managing Partner, ICT Legal Consulting
  • Rassoul Ghaznavi Zadeh, Director of Information Security, ResMed
  • Daniel Pludek, Chief Technology Officer, Kip McGarth Education Centres
  • Andrew Collins, Chief Information Officer & Chief Security Officer, Sport Integrity Australia
  • Moderator: Kelly Henney, Partner & National Leader Data Privacy Services, KPMG

5. Leveraging cloud and AI to derive a proactive and rapid incident response mechanism

https://www.youtube.com/watch?v=qKkxYSDtDn4&ab_channel=CISOMAG

Participants of the panel discussion included:

  • Andrew Wan, Chief Information Security Officer, The Smith Family
  • Daminda Kumara, Head of Cyber Security and Risk, Wesfarmers Industrial and Safety
  • Wayne Burke, VP & Co-Founder, Cyber2labs LLC
  • Ts. Dr. Aswami Ariffin, SVP Cyber Security Responsive Services Division, CyberSecurity Malaysia, President, DFRS
  • Neil Campbell, Vice President and Head of Asia Pacific & Japan, Rapid7
  • Moderator: Rafael Narezzi, Chief Information Security Officer, WiseEnergy

6. Fireside Chat: Dynamic security countermeasures to enhance data security and privacy

https://www.youtube.com/watch?v=t7mjU3O5194&t=1s&ab_channel=CISOMAG

Participants of the fireside chat included:

  • Nicki Doble, Group Chief Information Officer, Cover More Insurance
  • Amit Chaubey, Head of Cyber Security Risk, Governance & Compliance, Ausgrid
  • Moderator: Jacqueline Kernot, Partner Cyber Security, EY

 

Leaked Document Row! Google CEO Sundar Pichai Apologizes to EU’s Thierry Breton

Google Cybersecurity Action Team Google, EU warns Google

Google CEO, Sundar Pichai, who was under fire from Europe’s industry chief, Thierry Breton, over a leaked internal document has since apologized to Breton. According to a statement from the European Commission, both dignitaries exchanged notes in a video-conference call that was initiated and scheduled by Google much before the leak took place. Breton confronted Pichai on the call stating the leaked document seemed to be proposing ways to counter the EU’s tough new rules for technology companies, and this was not acceptable.

Pichai was taken aback by the document shared with him and had no knowledge of it, neither had any memory of signing-off any such document in the past. Yet, because the harsh words used by Breton like “Internet is not (the) Wild West,” Pichai apologized to Breton. According to Pichai, the manner in which the leak came out portrayed his and Google’s views on EU’s laws in bad light, which he also stated was never the position of the company.

Related News:

Google is the Monopoly Gatekeeper to the Internet, says DoJ

Breton added, “Europe’s position is clear; everyone is welcome on our continent as long as they respect our rules. We need clear and transparent rules, a predictable environment and balanced rights and obligations. Everything that is allowed offline should be authorized online; and everything that is forbidden offline should be banned online.”

Breton’s DSA and DMA draft

Breton is set to announce the new draft rules known as the Digital Services Act (DSA) and the Digital Markets Act (DMA) together with the European Competition Commissioner, Margrethe Vestager, on December 2, 2020. The European Commission believes that these two acts will strengthen the Single Market for digital services and foster innovation and competitiveness of the European online environment.

The new DSA will modify the current legal framework on two counts:

First: It will propose clear rules framing the responsibilities of digital services to address the risks faced by their users and protect their rights.

Second: It will propose rules covering larger online platforms like Google, Facebook, Amazon, etc. that are currently acting as gatekeepers. At the moment, they are setting the rules of the game for their users and competitors. The initiative will ensure that these platforms behave fairly and can be challenged by new entrants and existing competitors, so that consumers have the widest choice, and the Single Market remains competitive and open to innovations.

6 Steps to Boost your Online Security

Penetration Testing, continuous testing, security testing

The year 2020 is certainly considered as the year of change. The pandemic has changed/impacted every facet of life — from the way we used to commute to the way we worked. Even cybercriminals have become more creative with their online scams — leveraging the aftereffects of COVID-19, like remote work. You might be a click away from fraudulent adware or malicious links, leaving yours and the organization’s critical data at risk. Besides following basic security measures, online users must adhere to additional precautions to secure their online presence.

By Rudra Srinivas, Feature Writer, CISO MAG

Below are the six security tips to increase online security:

1. Using Password Manager

We cannot ignore the importance of managing passwords while talking about online security. Using a strong password or passphrase will provide maximum security to your network and the devices you use. However, strong passwords/passphrases are often leaked in data breaches when companies mismanage their user data. Hackers trade stolen credentials on various darknet forums to other bad actors. Having different passwords for every account will reduce the domino effect of brute-force attacks, in which hackers try many passwords with the hope of eventually guessing correctly. Using a password manager like LastPass, Dashlane, or 1 Password will enhance the security of your passwords and encourages the use of separate passwords for each individual account/site.

2. Clear the Cache

We often neglect to clear the cache data until we face some technical issues. Personal data like saved searches, browsing history, and home addresses can be saved into the cookies and cache folders of your internet browser. Therefore, delete your browser cookies and clear the browser history on a regular basis to protect your device/information from cyber risks. Do this from the Settings menu in your browser.

3. Update Regularly

Threat actors often look for new vulnerabilities to exploit and break into your device/network to pilfer sensitive information. Make sure you update your operating system, applications, browser, and device firmware regularly.

4. Using Virtual Private Network

A Virtual Private Network (VPN) helps improve a user’s data privacy and security on the internet. VPNs provide a secure connection for users when joining another network online. It also changes your IP address and location, making your browsing activity safe and private from threat actors. Even if hackers penetrate your network, they still cannot compromise/access your data when a VPN is used.

 5. 2FA

Though two-factor authentications (2FA) make the login process a bit longer, it strengthens users’ internet security. Using 2FA means you have an extra layer of security to your network.

6. Don’t Get Phished by Click Baits

Phishing scams via malicious ads and emails are rampant in the online world. Be vigilant about what you click as they could be malicious. Attackers lure users with phishing links to automatically download malware and infect the device. Never click on links in emails, messages, and social media sites unless they are genuine and received from a known source.

Wrap Up

Attackers are using innovative hacking techniques to break into users’ networks/devices to steal sensitive information. It is our responsibility to secure our endpoints and networks against online intruders.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.