Home Blog Page 146

Streamline Your Compliance Needs with ByteChek

cybersecurity compliance

Cybersecurity assessment is the need of the hour for all organizations as security breaches become daily news for organizations around the globe. But these assessments and audits are not a walk in the park. It can be very overwhelming, and many of the processes can be too laborious and time-consuming at times.

SPONSORED CONTENT

To resolve this issue and to speed up the process of proving compliance, ByteChek, a SaaS–based company, has been newly established to automate IT audits and streamline cybersecurity reporting. AJ Yawn, a former Captain in the U.S. Army and cloud security industry expert, along with Jeff Cook, a CPA with over 20 years of experience in accounting and auditing, describes the founding ideology behind ByteChek as: “Make Compliance Suck Less.”

What ByteChek’s Platform Offers

ByteChek’s platform is well suited for companies of all sizes. It provides security programs, automates cybersecurity readiness assessments, and completes SOC 2 audits faster – all from a single platform.

Related News:

Compliance: A Chief Tenet for the Future of Cybersecurity

The platform allows companies to quickly build their information security policy, ground up, utilizing the ByteChek information security policy generator. The ByteChek platform then connects with the applications companies use every day to eliminate evidence collection and vague auditor requests.

AJ Yawn - ByteChek

“We make it easier for companies of all sizes to achieve their cybersecurity compliance goals. With so many frameworks out there, compliance can be confusing, time-consuming, and too much paper pushing. By focusing on security instead of compliance frameworks, we eliminate the confusion, make compliance faster and ultimately more valuable to security practitioners and executives”

– AJ Yawn, Co-Founder, and CEO, ByteChek

Regulatory standards have become more complex, and thus maintaining compliance to pass audits has become more tedious. However, this platform helps automate the processes involved with maintaining compliance, saving companies some valuable time and money.

The ByteChek platform is powered by its proprietary “ByteChek Engine” that automatically assesses controls according to AICPA and audit standards. Additionally, ByteChek provides cybersecurity advisory and SOC 2 assessment services, which are based on the audit and cybersecurity experience of the ByteChek’s leadership team.

Jeff Cook - ByteChek

“Automation and AI is a big part of being future-ready in our industry. Thus, we designed our platform with an anticipatory mindset to make IT audits and reporting easier.”

– Jeff Cook, Co-Founder, and CFO, ByteChek

 

Microsoft’s November Patch Tuesday is Here! Know Which Flaws are Fixed

Brand Phishing Attacks

Microsoft released the official patches for over 112 newly discovered vulnerabilities as part of its November 2020 Patch Tuesday. The technology giant stated the latest fixes address 17 critical-rated flaws, 93 important, and 12 low-rated flaws, including an actively exploited zero-day flaw, which was disclosed by Google’s security team recently.

The security release consists of updates for various Microsoft products, which include:

  • Microsoft Windows
  • Office and Office Services and Web Apps
  • Internet Explorer
  • Edge
  • ChakraCore
  • Exchange Server
  • Microsoft Dynamics
  • Windows Codecs Library
  • Azure Sphere
  • Windows Defender
  • Microsoft Teams
  • Visual Studio

“The Microsoft Security Response Center has been scoring Windows and Browser vulnerabilities since 2016. Now we are scoring every vulnerability and displaying the details that make up that score in the new version of the Security Update Guide,” Microsoft said.

Last month Microsoft released updates to fix 129 vulnerabilities: 23 of which were deemed critical, 105 were important, and the rest were moderate in severity. The patches addressed vulnerabilities in Microsoft Windows, the Edge browser, ChakraCore, Internet Explorer, SQL Server, Office and Office Services and Web Apps, Microsoft Dynamics, Visual Studio, Exchange Server, ASP.NET, OneDrive, and Azure DevOps.

CISA Advice to Patch Microsoft Flaws

Recently, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) issued an advisory for enterprises’ specifically asking them to apply required patches for the two Microsoft vulnerabilities – RCE Windows Codecs (CVE-2020-17022) and Visual Studio Code (CVE-2020-17023). With CVE-2020-17023 requiring an update, coupled with an out-of-band advisory, both CISA and Quinlan have encouraged administrators to patch this vulnerability quickly. While Microsoft stated that there is no exploitation observed in the wild, the follow up of the CISA advisory suggests that administrators should review the patches and apply the updates if necessary. Read the full story here…

Why Europeans Don’t Trust U.S. Organizations with their Data

EU Joint Cyber Unit

A study from pCloud, a European file-sharing and cloud storage provider, revealed that 82% of Europeans do not trust U.S. technology firms with their personal files, citing their biggest concerns such as data being used for commercial gains (51%) and the possibility of hacks (43%).

The study, which polled over 4,500 people across the U.K., France, and Germany, stated that 82% admitted they would rather have their data stored in Europe than in the U.S., while 74% said they check the security features offered before choosing a provider. Nearly, 68% of users said they would feel more confident putting files in the cloud if the provider was not able to see what was being stored there. Most of the respondents said they use these services to boost the memory of their personal and work devices (51%), to retain a secure backup of files (43%), and to share information with family, friends, and colleagues (36%).

Tunio Zafer, CEO at pCloud, said, “With families, friends and businesses forced apart by Coronavirus, we have seen a huge uptake in cloud services to connect people at this most challenging of times. This study found that 71% of people will use cloud storage and file sharing solutions more in the post-Covid world. However, it is clear that Europe demands better than ‘big tech’ is offering, having been burned one too many times.”

“While we are seeing significant growth in the cloud market, people are becoming more savvy as a result. Whether it is for business or personal use, the industry as a whole must do more to address security issues, which are clearly having an impact on users who feel increasingly emboldened to challenge providers.” Zafer added.

“Unified solutions could hold the key in enforcing endpoint security policies”

Endpoint Security Interview with Karmesh Gupta

The exponential increase in endpoints in the last nine months has hugely contributed to a dramatic rise in network and endpoint perimeter breaches. However, there is one man who seems to be fighting fire with fire by providing a unified solution that is changing the face of network and endpoint cybersecurity not just in India but around the globe. Meet Karmesh Gupta, the change that you may know, but the man you didn’t.

Karmesh is the CEO of the Indian cybersecurity-based product suite provider, WiJungle. Honored by Forbes as the best “30 Under 30 Asia 2020,” he has not always had a smooth ride. It was rough, patchy, full of bumps, and only after two failed attempts, did he make it big. Karmesh humbly says, “Persistence did pay.” His company’s unique cybersecurity offering in the network and endpoint security domain is ringing bells around the globe (which already has a product reach in 30+ countries).

It is the end of the year and endpoint security has grabbed headlines almost all year round. So, in a fireside chat with Mihir Bagwe, Tech Writer at CISO MAG, Karmesh helped us gain deeper insights into the trenches of network and endpoint security.

The edited excerpts of his interview follow:

1. The Readiness Quotient

Endpoint Security Interview - Karmesh Gupta

A.

Yes, in the case of large businesses, who already had the required infrastructure for business continuity during the pandemic.

No, in the case of SMBs, who either didn’t have the required products for remote work enablement or were managed by third-party vendors. In both these cases, the movement started happening around the first week of lockdown.

Specifically referring to our customer base, only 12% of the people were using the remote work enablement function of our product before COVID, while within the initial 10 days of lockdown, this number rose to 80%.

2. Pre and Post-COVID Strategies

Endpoint Security Interview

A. Between the pre-COVID and post-COVID era, there has been a shift from network security-centric policies to endpoint-centric policies as endpoints have become the first entry point for any threat. Policy enforcement around Endpoint Data Leakage Prevention (DLP), Host-based Intrusion Prevention Systems (IPS), Ransomware Protection & Application Filter have been the prime adoptions/amendments in the overall strategy.

3. Hidden Risks of Remote Working

Endpoint Security Interview

A.

Due to complete remote working, there has been a significant increase in usage of Virtual Private Network (VPN). As multiple endpoints from around the globe are connecting the corporate network daily, the entry points for perimeter breaches have risen. Moreover, neither every official endpoint in the pre-COVID phase was configured for such utilization, nor the newly added personal devices during this scenario were equipped with concrete BYOD policies.

That’s the reason attackers have shifted their focus to breach the network via making an entry through vulnerable endpoints. It is one of the prime reasons for increased cyberattacks post-pandemic. The only way to resolve this is by having proper endpoint protection policies.

4. Including Endpoints in Our Security Perimeter

Endpoint Security Interview

A. Enforcing the security policies on these endpoints is a challenge, and hence a comprehensive or unified product holds the key to bringing them under the security perimeter. Cloud-based solutions like SDPs or Unified Network Security Platforms could simplify these aspects to a huge extent.

5. Reason to have a Unified Solution

Endpoint Security Interview

A.

The reason is simple. Unified products give you the leverage to efficiently manage the policies and monitor the traffic.

As an example, the unified client application that we provide does the work of both VPN as well as Endpoint Protection. If you already have our network security product, then on subscribing to the endpoint protection, end users are just required to update the client app and endpoint security functions get enforced immediately.  The admins are only required to enable the option of applying the user network security profile on endpoints, and 80% of their configuration task is done by default.

Now imagine the same implementation if an organization would have opted for separate stand-alone products for network and endpoint. It would have doubled the task and turnaround time.

One thing to remember is that SCCs are used in many countries where the protections are significantly less than in the U.S.

6. What’s in the Cloud?

Endpoint Security Interview

A.

‘As a service’ model, for sure, is the key to the future but having said that, cloud comes with its challenges. Whether you are hosting some data on a public/private cloud or using third-party applications, businesses adopting cloud for hosting their data or using third-party applications or both have different challenges.

One of the biggest misconceptions I have witnessed among the small and medium business owners is – ‘Hey, we use AWS or Azure or GCloud and they, by default, provide required security’ or ‘Hey, we use Gmail and it, by default, provides every kind of security.’ They do not understand what kind of security these platforms are talking about and conveying. It makes their cloud open for potential threat actors.

Since the cloud utilization is higher than ever, it needs to be ensured that SMBs at least have basic DDoS protection enabled for their data hosting along with the right access configurations provided by the platform. Moreover, if suitable, they should go for a Cloud WAF and Virtual Firewall.

In the case of third-party applications, if the number of such applications is less, then they still could be managed by proper access configurations, which should be provided by the platform itself. In any other case, one should deploy a CASB.

7. Choosing a Network and Endpoint Security Solution

Endpoint Security Interview

A.

For sure, number one is to go with a unified synchronized solution for easy management and scalability. The form factor of the solution could be cloud or appliance depending on the business operations need. If they have plans to work 100% remotely for some years, then cloud-delivered security makes sense for them.

Number two on the consideration list is the part where we discuss the capabilities. Ensure that network solution includes Zero-Day Protection, and the Endpoint Security Solution has features of DLP along with ransomware protection.

8. Prevention is Better Than Cure

Endpoint Security Interview

A.

As mentioned earlier, there are two aspects.

Firstly, the majority of ransomware attacks in enterprise networks happen as attackers can traverse through the remote endpoints. Hence, the foremost need is to have the right policy and security at both, network as well as the endpoint level.  It is a kind of proactive defense.

Secondly, if the above seems to be a difficult job then one could opt for deception technology such that threat actors could be deceived and their network scan time could be increased to make IT admins aware before a possible security breach occurs. It is a reactive defense.

9. Current Trends

Endpoint Security Interview

A.

The most trending forms that we have observed are:

  1. Malware Attacks (majorly ransomware, Trojans, and spyware): Via phishing, messaging platforms & freeware.
  2. Payment Frauds: Via fake mobile apps, websites, calls, and emails.

10. Future Challenges

Endpoint Security Interview

A.

I don’t think any. The world is already witnessing all the possible permutations and combinations of the challenges during the pandemic.

About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Interviews from the Author:
Other Posts from the Author:

Barracuda Acquires Fyde to Boost Cloud Access Solution

FireEye Acquires Respond Software

Cloud-based security solutions provider Barracuda has acquired Fyde, a Zero Trust Network Access (ZTNA) provider based in Palo Alto, to develop its SASE CloudGen platform by offering users new ZTNA functionalities. Fyde helps organizations in mitigating data breach risks by enabling secure access to critical resources. Fyde’s innovative Zero Trust solution enables secure, reliable, and fast access to cloud or on-premises applications and workloads from any device and location. Barracuda provides cloud-enabled, enterprise-grade security solutions for organizations to protect email, networks, data, and applications.

As per the acquisition deal, Barracuda acquired intellectual properties and other digital assets from Fyde. It integrates Barracuda’s Global Threat Intelligence Infrastructure with Fyde’s technology.

The latest acquisition also offers unique features designed for increasingly complex modern computing environments and to respond to a multitude of situations like:

  • The implementation of secure single authentication on SaaS applications
  • Securing access to applications from BYOD devices
  • The implementation of simultaneous access to multi-cloud and on-site applications
  • Monitoring the security level of mobile devices and protecting them from malicious websites
  • The simplified definition of privileged access and much more

“Teleworking is democratizing, migrations to the cloud are becoming commonplace and traditional professional perimeters are a thing of the past. Fyde offers a powerful ZTNA solution that works with any type of infrastructure, device, and application on a corporate network. This acquisition allows us to offer distributed enterprises a whole new way to modernize remote access, but also to enforce comprehensive security and access policies and to provide seamless connectivity without compromising productivity,” said BJ Jenkins, President and CEO of Barracuda.

Related story: Barracuda Acquires Indian Bot Technology Startup InfiSecure

BOTS Inc. Enters Global Partnership with Cyber Security Group LLC

STC Anomali partnership

BOTS Inc. is an emerging service provider of products and technologies catering to the cybersecurity needs of the manufacturing industry. Their digital robotics automation and AI-based product suite is now set to get the ISO-certified expertise from the Cyber Security Group LLC. On November 10, 2020, BOTS Inc. announced that they have entered a global partnership with the Cybersecurity Group and will soon introduce a new Web Application Firewall (WAF).

The Need for New Web Application Firewall

Attacks on web applications are becoming common these days. As more businesses shift their services online, web applications will increasingly become an easier target for threat actors. Additionally, web attacks are a huge threat to data security and compliance standards. They can lead to a wide range of devastating consequences from service disruptions and shutdowns to information theft and data manipulation.

Thus, to save the business from a cyber failure, an advanced web application firewall is needed. The collaboration of the two giants is offering a new WAF that will help protect the critical workload of businesses with a unique defense-in-depth approach. It provides real-time protection against both bots-based (DDoS) and application, API, user, or infrastructure threats.

The WAF from BOTS/CSG is a comprehensive, layered protection stack that proactively prevents bot-based volumetric attacks, as well as threats that target the application layer, such as SQL, XSS, CSRF, session hijacking, data exfiltration and zero-day vulnerabilities.”

What the BOT Says…

Paul Rosenberg, CEO of BOTS Inc., stated, “Even though DDoS attacks are still the most known threat, application-level threats have become just as destructive, as they are the hardest to detect and almost impossible to prevent before they damage any mission-critical applications. We analyzed these trends and in collaboration with the CSG have developed a new WAF. It will combine the availability and load monitoring with the detection and prevention of web application attacks using signatures and heuristics analysis. This ensures continuous protection of applications, users, infrastructures, and security compliance.”

Related News:

MicroWorld and CERT-In Collaborate to Enhance Overall Cybersecurity in India

Tanium and Google Cloud Partnership Marks the Beginning of a New “Chronicle”

Web Application Threat! U.S. Retailers More Vulnerable than European Counterparts

Web Application Attacks on U.S. EU

Outpost24, an innovator in identifying and managing cybersecurity exposure, stated that online sales surged by 30% globally in the wake of the pandemic, which also attracted various targeted cyberattacks. In its latest survey, “2020 Web Application Security for Retail & Ecommerce Report,” Outpost24 highlighted the web application security analysis for the top 20 retailers in the U.S. and EU. The research revealed that U.S. retailers have a larger attack surface with an average risk exposure score of 35.1 (out of 42.33) vs. an average score of 30.8 for EU retailers.

“With web applications accounting for 43% of data breaches in 2019, this research brings this to the top of the boardroom agenda in 2020 and digs deeper into the overall retail attack surface – taking a magnifying glass and critical view into the potential risks of the web applications that we all know and shop with regularly,” the report stated. 

Key Findings:

  • U.S. retailers run 3,357 web applications over 401 domains, with 8% of them considered as suspect and 22% of them running on old components containing known vulnerabilities
  • EU retailers run 2,799 applications over 509 domains, with 4% considered as suspect and 27% of them are running on old components containing known vulnerabilities
  • Security mechanisms (95); active content (93.3) and degree of distribution (81.5) are the average top three attack vectors identified across U.S. and EU retailers
  • 90% of the top 10 EU retailers are running outdated jQuery vs 50% for U.S. retail
  • U.S. retailers more up to date than EU retailers in the use of modern application technologies, however with new technology adoption they are twice more likely than their EU counterparts in running shadow IT which creates more potential risks for U.S. retailers

The research also found retailers using outdated servers to run their applications from Amazon S3 to older versions of the Apache Server. Outpost24 recommended retailers to ensure their servers are updated with the latest upgrade and close down servers that are no longer in use to prevent web servers from various attack vectors.

Pay2Key Alert! Israel Firms Targeted with New Ransomware

Ransomware attacks, LockBit Ransomware

Multiple organizations in Israel have reported several cyberattacks in which attackers targeted them using a new strain of ransomware named “Pay2Key”. According to CheckPoint research, threat actors illicitly obtained the foothold and remotely controlled the infection within the compromised networks. The Pay2Key ransomware is written in C++ and compiled using MSVC++ 2015. It also makes use of third-party libraries like Boost.

“The investigation so far indicates the attacker may have gained access to the organizations’ networks some time before the attack but presented an ability to make a rapid move of spreading the ransomware within an hour to the entire network. After completing the infection phase, the victims received a customized ransom note, with a relatively low demand of 7-9 bitcoins (~$110K-$140K),” the researchers said.

Key findings:

  • Previously unknown ransomware dubbed Pay2Key, carries targeted attacks against Israeli companies
  • Initial infection is presumably made through RDP connection
  • Lateral movement is made using psexec.exe to execute the ransomware on the different machines within the organization
  • Special attention was given to the design of the network communication in order to reduce the noise a large number of encrypted machines may generate while contacting the Command and Control servers
  • The encryption scheme is solid – using the AES and RSA algorithms

“While the attack is still under investigation, the recent Pay2Key ransomware attacks indicate a new threat actor is joining the trend of targeted ransomware attacks – presenting well designed operation to maximize damage and minimize exposure. The attack was observed targeting the Israeli private sector so far, but looking at the presented tactics, techniques, and procedures we see a potent actor who has no technical reason to limit his targets list to Israel. The incidents are still under investigation, and we will update this blogpost with new findings if any new findings come to light,” the researchers added.

CSPs Need to Adopt Smarter Ways to Combat Evolving DDoS Attacks

Donny Chong is the Product Director at Nexusguard. He is responsible for designing the company’s solutions for the enterprise. His broad ten-year tenure includes both the technology and telecommunications industries. Chong designed the Nexusguard channel program and built global product marketing practice. His insight and expertise have led the company to become one of the world’s most trusted DDoS defense products and solutions – suitable for premium clients, SMEs, and service providers.

In a recent interaction with Augustin Kurian, Senior Feature Writer at CISO MAG, Chong speaks about the resurgence of DDoS-as-a-service, abuse of DNS vulnerabilities, and the surge in bit-and-piece DDoS attacks and how CSPs are supposed to combat it.

1. The resurgence of DDoS-as-a-service and the growing botnets reinforce the evolving cyber threat of DDoS attacks for enterprises and communications service providers (CSPs). Do you feel the attack surface has been heightened post-COVID-19? 

DDoS Attacks

Yes, without a doubt. In an effort to curb the spread of the ongoing COVID-19 global pandemic, working from home has become the new norm and the dependency on internet connectivity has never been more important. The heavy reliance on the internet, however, has not only led to a huge rise in DNS amplification attacks but also a resurgence in DDoS-for-hire services, which is a trend that will persist and is unlikely to go away anytime soon. As DDoS attacks become more sophisticated and more difficult to stop, exacerbated by the revolution of remote working, CSPs will have to adapt to, and address the new attack methods brought forth by the global pandemic, and look at smarter ways into mitigating and managing DDoS attacks for the post-COVID-19 world.

2. There has been a nearly 570% increase in bit-and-piece DDoS attacks in Q2 2020.  Due to this, the communications service providers (CSPs) were forced to subject entire networks of traffic to risk mitigation. What are the best practices to avoid these threat vectors when attacks are smaller than 30Mbps?

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Given that DDoS attacks have continued to evolve and have become more geared towards attacking the architectural design of CSPs, CSPs need to evolve and adopt smarter ways of learning traffic behavior during peacetime and monitoring traffic from a more comprehensive point of view. While CSPs will do their utmost to carry out the above measures, without AI-driven methods, such actions will only deliver limited results.

In order to implement such strategies properly, the current capabilities of CSPs might be limited, and hence, it would be best to look into purpose-built solutions with “deep learning-based” predictive technologies to more effectively implement this strategy.

3. Hackers have lately been blending multiple attack vectors to launch a wider range of UDP-based attacks making them harder for CSPs to detect. In scenarios like these, CSPs find it difficult to differentiate between malicious traffic and legitimate traffic. This is an alarming trend considering hackers are innovating faster than enterprises. Do you think there is a considerable gap between evolving attack vectors and mitigation strategies?

cyberattacks on U.S. and U.K., Barnes & Noble cyberattack, zero trust

Yes. Cybercriminals have changed tactics, opting to launch more stealthy and methodical attacks designed specifically to bypass existing traditional detection and mitigation technologies. As bit-and-piece attacks become more widely employed, DDoS detection and mitigation are no longer an issue that can be resolved by means of a single on-premise device, cloud-based solution or even an hybrid solution. To fend off this continuing trend, CSPs need to step up and take an integrated approach to implement defense-in-depth and breadth, putting together best-in-class solutions so that they can offer a comprehensive and effective solution. Furthermore, the use of “deep learning-based” predictive methods would be an effective mitigation strategy.

4. Last year, a continued shift to leveraging mobile devices in attacks had created a new breed of botnets that caused the maximum attack durations to spike to more than 40,000 minutes at a time or more than 27 days. Do you think the trend is continuing? Also, is it safe to say that IoT Security has taken a backseat since the onset of COVID-19?

median dwell time, Supercharged AI Cyberattacks are Unavoidable

Yes. Cybercriminals often choose targets that offer the least resistance and the easiest way to generate a powerful attack. As the usage of mobile devices grows, we are seeing more mobile devices becoming compromised and used as a source of an attack. Cybercriminals look at the weakest link, and since IoT devices are vulnerable and easily compromised, they are fast becoming hacking targets, resulting in havoc on our cyberworld.

No. IoT security has not been neglected since the outbreak of COVID-19. It is and has always been the key focus of the IoT community, which continually strives to improve the security of the IoT landscape.

5. Over the years, Domain Name System Security Extensions (DNSSEC) has been gaining acceptance as the patch and is now causing a new set of problems for organizations. How is the cybersecurity industry responding to this?

DNS attacks

Although tactics to abuse DNS server vulnerabilities will inevitably continue to evolve, we believe that DNSSEC is still of paramount importance. To safeguard against amplification attacks from saturating victim networks and hosts, it is imperative that CSPs, telcos, DNS providers, etc. employ security policies and enhanced security measures. Suggested measures include access control, monitoring of DNS service, detection of abnormal requests, and mitigation of abnormal DNS requests.

6. There has been a lot of talk about the need for DNSSEC. The abuse of DNS was not something that was anticipated even till mid-2019. Do you feel there is still a lack of understanding of the abuse of DNS? Also, was the cybersecurity industry ready to tackle it when it found the problem?

Data breach in 100 U.S. cities

Owing to a lack of security awareness, the abuse of DNS server vulnerabilities is still not taken very seriously. DNS servers built and controlled by CSPs, enterprises, and government organizations, which are well regulated and conform to stringent security standards, pose no real threat. However, anyone can also build their DNS server, with no regulation or enforced security standards that must be adhered to, which most often results in abuse and exploitation by cybercriminals.

7. Last year, China held its lead as a source of DDoS attacks, with 23% of attacks originating in the country. There have also been several accusations on China and its involvement in corporate espionage, and even state-sponsored attacks to steal vaccine development. At a point when the information security space is vulnerable due to remote working and COVID-19, what initiatives can countries adapt to mitigate state-sponsored attacks?

covid-19 vaccine, vaccine

Countries must upgrade and ensure that their critical infrastructure is robust and has the necessary security and response plans in place, to protect critical infrastructures such as utilities, financial systems, and government backbones, in the event of serious incidents.

Countries should develop their own cybersecurity program. Many nations have already established their own cybersecurity agencies, which specialize in cybersecurity of the nation from a country level.


Augustin Kurian

About the Author 

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

 

Is Your Endpoint Device Secure? Take our Endpoint Security Survey and win exciting goodies. Don’t miss out! Take Survey Now!

WordPress Ultimate Member Plugin Vulnerability Can Lead to Three Severe Exploits

Attackers Target 900,000 WordPress Sites in a Week

The Threat Intelligence team from Wordfence discovered multiple vulnerabilities in Ultimate Member, a WordPress plugin installed on over 100,000 sites. Wordfence stated that the flaws are severe and could allow remote attackers to escalate their privileges to those of an administrator to take over WordPress sites. The company urged the admins of WordPress sites who use the Ultimate Member plugin to immediately patch the bugs by updating them with the patched version 2.1.12.

Ultimate Member is a WordPress plugin that provides support for creating websites and enhance user registration and account control on WordPress sites.

According to Wordfence’s researchers, the vulnerabilities exist in three forms: user registration, user login, and user profile management.

“These vulnerabilities are considered very critical as it makes it possible for originally unauthenticated users to easily escalate their privileges to those of an administrator. Once an attacker has administrative access to a WordPress site, they have effectively taken over the entire site and can perform any action, from taking the site offline to further infecting the site with malware,” Wordfence said.

“Attackers could enumerate the current custom Ultimate Members roles and supply a higher privileged role while registering in the role parameter. Also, an attacker could supply a specific capability and then use that to switch to another user account with elevated privileges,” Wordfence added.

700,000 WordPress Users at Risk

In a similar discovery, Wordfence found that the File Manager plugin has over 700,000 active installations, which could allow threat actors to execute commands and upload malicious files on a target site. File Manager is a plugin intended to help WordPress admins manage files on their websites. To read the full story, click here…