https://youtu.be/DWnFKnZyrq0?list=PLRmoLV6UOL5w5YhhAWxBS8J-ZOwp07GCV
Disinformation Threat! Data of Over 186 Mn U.S. Voters Found on Darknet
Ever since the U.S. election campaigns began, there have been concerns over rising disinformation campaigns. Security experts from Trustwave SpiderLabs stated they found a massive database that contained detailed information about U.S. voters and consumers kept for sale on the hackers site RaidForums.com and various other darknet forums. “This data can be useful for all sorts of scams and in particular, can be useful to target voters based on their voting history,” Trustwave said.
Voter List on Sale!
The hackers claimed that the leaked voter database includes names, addresses, age, gender, and political affiliation of 186 million voters in the U.S. Trustwave stated that cybercriminals could abuse the exposed database to perform various social engineering scams and spread disinformation that may potentially impact the elections. Threat actors have obtained the voters’ information from publicly available government resources and various data breaches. Cybercriminals have found ways to monetize the information, ranging from a few hundred to thousand dollars, payable in bitcoins.
“The thread about this database was entirely removed from the forum. Most likely the forum administrator did that to avoid unnecessary attention from researchers and law enforcement agencies. However, we established contact with the seller who said the voter database is still available to purchase,” Trustwave said.
Not the First Sale!
This is not the first time threat actors are selling voter information on the darknet. Earlier, the voter databases of around 35 million U.S. citizens were peddled on a hacking forum. It is found that cybercriminals obtained unauthorized access to the U.S. voter registration databases and put them for sale in dark web forums. The database holds personal information like names, phone numbers, address details, and voting history. They also said the data is priced between $150 and $12,500, affecting over 19 States in the U.S.
Unsecured Election Infrastructure
According to a survey from Venafi, 70% of cybersecurity professionals most likely believe their local governments cannot defend election infrastructure against cyberattacks from domestic and foreign threat actors. The survey, based on election infrastructure cybersecurity, also disclosed that 75% of security experts consider that the spread of malicious information is the biggest cyber risk to election integrity.
New Normal Effect! 85% of Organizations Say Cybersecurity is More Important than Ever
Networking and hardware company Cisco stated that organizations became most concerned about data sharing during the COVID-19 pandemic. In its dual research studies, the company revealed the security challenges that organizations face while supporting employees and customers in remote working conditions. It also highlighted that increasing cybersecurity spending will make organizations and consumers ready for the current working conditions.
According to Cisco’s Future of Secure Remote Work Report, most organizations across the globe are only somewhat prepared to support a remote workforce environment. The report also found:
- 85% of organizations said that cybersecurity is extremely important or more important than before COVID-19.
- Secure access is the top cybersecurity challenge faced by the largest proportion of organizations (62%) when supporting remote workers.
- One in two respondents said endpoints, including corporate laptops (56%) and personal devices (54%), are a challenge to protect in a remote environment.
- 66% of respondents indicated that the COVID-19 situation will result in an increase in cybersecurity
Cisco’s second annual Consumer Privacy Survey revealed that consumers globally are worried about the privacy of remote working tools and are uncertain about organizations data security policies. Findings include:
- 60% of respondents are concerned about the privacy of remote collaboration tools.
- 53% want privacy laws maintained, with little or no exception for pandemic-related data.
- 48% feel they are unable to effectively protect their data today, and the main reason is that they cannot figure out what companies are doing with their data.
- 56% believe governments should play the primary role in protecting consumer data, and consumers around the world are highly supportive of the privacy laws enacted in their country.
Jeetu Patel, SVP and GM of Cisco’s Security & Applications business, said, “Security and privacy are among the most significant social and economic issues of our lifetime. Cybersecurity historically has been overly complex. With this new way of working here to stay and organizations looking to increase their investment in cybersecurity, there’s a unique opportunity to transform the way we approach security as an industry to better meet the needs of our customers and end-users.”
Harvey Jang, VP, Chief Privacy Officer, Cisco, “Privacy is much more than just a compliance obligation. It is a fundamental human right and business imperative that is critical to building and maintaining customer trust. The core privacy and ethical principles of transparency, fairness, and accountability will guide us in this new, digital-first world.”
Google Rolls Out Patch to Fix Zero-Day Vulnerability in Chrome
An actively exploited zero-day vulnerability put many Google Chrome users at a very “High” risk. Taking note of the severity of the vulnerability and the subsequent damages caused if exploited successfully, Google has released an emergency patch to fix it. The stable version of Chrome 86.0.4240.111 is now available for Windows, Mac, and Linux, which also consists of four other medium to high severity vulnerabilities.
Chrome’s Zero-Day Vulnerability
The vulnerability, which was reported by Sergei Glazunov of Google Project Zero on October 19, was said to be an arbitrary code execution (ACE) vulnerability that was actively exploited in the wild. Going through the brief technical details made available by Google, it can be said that the zero-day being tracked under CVE-2020-15999 is a heap buffer overflow bug in the FreeType font rendering library that’s included with standard Chrome distributions.
Related News:
Hackers use Firefox ‘Zero-day’ bug to attack against Coinbase employees
Talking more about the seriousness of damages that the bug could potentially cause, Rody Quinlan, Security Response Manager at Tenable, said, “The zero-day is a memory corruption flaw [CVE-2020-15999] described as a ‘heap buffer overflow in FreeType.’ Successful exploitation of heap buffer overflows could lead to memory leakage which could potentially be used to lead to arbitrary code execution. As the Chrome flaw is being actively exploited in the wild, users are urged to update their browsers as soon as possible to reduce the risk of compromise.”
Other Fixes
Along with the CVE-2020-15999 high priority security fix, which had a turnaround time of less than 24 hours, Google also fixed four other – medium to high severity – vulnerabilities in Chrome’s 86.0.4240.111 version. Here is the complete list:
- CVE-2020-16000, Severity – High: Inappropriate implementation in Blink. Reported by amaebi_jp on 2020-09-06.
- CVE-2020-16001, Severity – High: Use after free in media. Reported by Khalil Zhani on 2020-10-05.
- CVE-2020-16002, Severity – High: Use after free in PDFium. Reported by Weipeng Jiang (@Krace) from Codesafe Team of Legendsec at Qi’anxin Group on 2020-10-13.
- CVE-2020-15999, Severity – High: Heap buffer overflow in Freetype. Reported by Sergei Glazunov of Google Project Zero on 2020-10-19.
- CVE-2020-16003, Severity – Medium: Use after free in printing. Reported by Khalil Zhani on 2020-10-04.
Related News:
Researcher Discovers Unpatched Zero-Day Flaw affecting Latest Android Phones
CERT NZ Warns About Kiwis’ “Complacency Behavior” Towards Cybersecurity
The Cyber Smart Week for New Zealand, which started on October 19, continues to raise awareness on the importance of security in protecting personal data. CERT NZ, a government entity that supports organizations and individuals affected by cyberattacks, emphasizes on the security measures Kiwis (New Zealanders) need to take to be more cyber resilient.
According to a research by CERT NZ, the volume of financially motivated cyberattacks surged over the last six months in the country. While 87% of New Zealanders agree that security of their personal information is important to them, 40% said that taking the necessary precautions to safeguard their data online is inconvenient. Nearly, 32% of Kiwis do not check the privacy settings on their social media accounts. And 30% do not use two-factor authentication (2FA) when logging into an online account.
CERT NZ urged individuals to follow certain security steps to build cyber resilience. These include:
- Use a password manager to keep track of each strong and unique password you have for every online account.
- Turn on two-factor authentication to add an extra layer of security to your logins and accounts.
- Update your devices and operating systems to defend against bugs and viruses.
- Check your privacy settings to know and control who sees your stuff.
Related Stories:
CERT NZ Director Rob Pope, said, “CERT NZ’s incident data, and information provided by our global partners tells us that cyberattacks have become more sophisticated, persistent and harder to detect than ever before. Your personal information is highly valuable to attackers regardless of who you are, so it is important that more Kiwis get serious about protecting themselves online. Steps like using a password manager, two-factor authentication, updating devices and checking privacy settings are the basics to building your cyber defense.”
“It appears that the majority of Kiwis know they should be cyber smart, but some are not acting on it. The results are concerning. They reveal approximately a third of New Zealanders are more vulnerable to a cyberattack, meaning their data could be accessed and their identity stolen, enabling the attacker to conduct a range of criminal activities, including online fraud. We all lock our homes to stop burglars from stealing our valuable possessions. It is no different in the online world,” Pope added.
To address the surge in malware, phishing, and DDoS attacks, EC Council’s CISO MAG has planned a crisp half day virtual engagement, The Australia CISO Confluence, to create more awareness on the need for cybersecurity and its related implications in these testing times. Register here.
Credential-based Attacks are on the Rise: Is Your Organization Prepared to Fight Them?
Every year, National Cyber Security Awareness Month provides organizations with the opportunity to examine the major issues faced by security teams and arm themselves against potential threats to their business. As much of the workforce traded the traditional four walls of the office for at-home setups earlier this year, and COVID-19 provided nation-state actors with ample opportunities to expand credential theft. They particularly homed in on organizations in government, health care, and education with an intense focus on those working towards vaccine research.
By Trevor Daughney, VP, product marketing, Exabeam
In our modern remote work landscape, new issues have emerged as employees connect to sub-par security on home networks, share their corporate devices among household members and engage in other risky behaviors that would not normally draw concern within the confines of traditional office space. This distributed enterprise forces organizations across sectors to ask themselves whether or not they’re prepared to combat credential-based attacks.
As recent headlines can confirm, credential-based attacks don’t discriminate based on industry or company size. In April, Nintendo experienced credential-stuffing attacks, and in September, the United States Cybersecurity and Infrastructure Security Agency (CISA) published an analysis report detailing the malware attack on a federal agency’s enterprise network. In the report, CISA noted the threat actor leveraged compromised credentials to exploit weaknesses in the agency’s firewall. Just as NCSAM began, Microsoft published the Digital Defense Report showing the increasing sophistication of cyberthreats, which confirmed the effects of the pandemic on targeted industries and provided additional evidence pointing to a rise in credential-based attacks.
Credential-based attacks make it harder for a SOC to detect and respond to attackers, allowing adversaries to access private data and high-value assets. We’ve also seen credentials impacted mid-way through the attack by switching between user accounts or by escalating the privileges of a compromised user. Looking to remain one step ahead of security teams, hackers utilize these attacks to make it more difficult to detect and respond to their activity and to access other areas of the network.
Traditional cybersecurity investigation techniques are no longer enough to place organizations ahead of bad actors looking to compromise their systems and attack their data. Thus, more advanced approaches are needed today to prevent this dangerous lateral network movement. Organizations looking to modernize their systems and counter credential-based attacks can find success by adding intelligence to their SIEMs and implementing machine-learning-based analytics. The static rules of a SIEM will typically not fire if an attacker logs into a network – using stolen credentials, or as a malicious insider. Moreover, even if the SIEM provides an alert, without context, the security team is not able to tie the events together to provide the security team with a full picture of the attack chain. Threat actors can wait days, weeks, or even months before making their first lateral movement, which makes them extremely hard to detect without all the details.
By relying more on data analytics and machine learning, security teams are able to identify a user’s intent. Behavioral analytics starts with first establishing a baseline of a user’s typical behavior, comparing typical behavior to that which appears out of the norm, such as anomalous lateral movement. Security teams can then automatically stitch together various log sources into a timeline to detect anomalous behavior. In this fashion, behavioral analytics can also help combat insider threats, who may be engaging in permitted, but unusual, activity.
Employees outside of the SOC also have a role to play. In this year’s Verizon Data Breach Investigations Report, credential theft accounted for 67% of breaches and raised concerns around the vulnerability of remote workers. Therefore, security teams must continue to stress and repeat best password practices such as never using the same password twice, using complex passwords, and turning on multi-factor authentication.
As credential-based attacks gain notoriety and organizations become increasingly aware of the risks and consequences associated with them, security teams have responded by establishing baseline industry best practices to arm employees with the knowledge required to combat these threats. These include continuous employee education around good password hygiene, reminders to look for suspicious links or email addresses and an emphasis on the importance of avoiding the co-mingling of personal and professional email accounts. For security teams, prevention also involves closely monitoring user behaviors, allowing for early detection of malicious events, and establishing rigorous access controls, especially for users with privileged access.
By implementing a combination of behavioral analytics and smart password practices, security teams will be better prepared to thwart current and future credential-based attacks across the organization.
About the Author
Trevor Daughney is an executive with a track record of building high performing teams to take enterprise cybersecurity SaaS and software technology and turn them into successful global businesses. Prior to Exabeam, he led enterprise product marketing at McAfee, Ping Identity, and Symantec. Trevor approaches marketing with a global mindset and builds on his experiences living and working in the US, Canada, and Asia. He has an MBA from the University of California, Berkeley.
Disclaimer
Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.
Related story: Media Industry Becomes a Common Ground for Credential Stuffing Attacks
Cyber Risks During a Merger and Acquisition
TikTok was recently in the news as it was on the verge of being acquired by a U.S. company or a consortium for billions of dollars. What potential cyber risks are there for the acquiring U.S. company? Tons. The wildly popular social media video sharing service is a Chinese company accused of purposefully undermining the security of U.S. citizens, and could potentially be influenced by its foreign government intelligence apparatus. If there was ever a case that exemplifies the justifications for having a bullet-proof merger & acquisition cybersecurity plan, it would be TikTok.
By Matthew Rosenquist, CISO, Eclipz
Although such potentially scandalous deals highlight the security concerns, nowadays every merger and acquisition brings with it many potential digital risks. From small to large, simple to complex, all M&A deals involving technology have cybersecurity baggage and challenges.
Security does not happen by default
Mergers and Acquisitions represent a significant risk to organizations as integration and data sharing can expose assets to confidentiality, integrity, and availability threats. Security must identify the risks across a broad scope of areas.
Connecting the networks could open a plethora of new dangers, especially if the acquired network is vulnerable or already compromised, as it puts at risk all the digital assets and services from the acquiring company. If any of the new personnel, suppliers, partners, or vendors are disgruntled or working on behalf of external parties seeking to gain leverage, there can be serious insider risks. Lack of security, process, oversight, and controls can undermine the value of the acquiring assets, diminishing the return-on-investment. If the integration isn’t done well, valuable assets including talent, operational stability, and future generation of intellectual property can rapidly diminish. If things go sideways, an acquisition can create a situation for the acquiring entity of regulatory non-compliance that brings with it an erosion of customer goodwill, negative press, lawsuits, legal injunctions, and other serious penalties.
Years ago, I built and led Intel Corporation’s M&A cybersecurity capability and processes. Throughout my career, I have been involved in over one-hundred and twenty mergers, acquisitions, divestitures, site closures, and joint ventures. I have published a variety of articles and presentations on this topic, spoken to many audiences, and advised other organizations on best practices.
M&A cybersecurity work is typically frantic, unpredictable, and oftentimes ambiguous. It demands executive sponsorship, strong leadership, great flexibility, and a willingness to rapidly adapt to emerging problems. It can press the boundaries of good security practices and test the mettle of the strongest cybersecurity organizations.
It is often dreaded by traditional security operations folks who are entrenched in the comfort of controlling a consistent, predictable, and structured environment. M&A’s are chaotic and rarely comply with corporate security policies. It is an art as much as it is a science when considering the technical, behavioral, and process aspects that must be comprehended and addressed.
Top 8 Key Learnings for M&A Cybersecurity
1. Security does not happen by default. As the complexities of M&A deals emerge, those involved move aggressively to solve problems. In the rush and pressure, security is often deprioritized in tactical decisions that eventually manifest into strategic issues. Cybersecurity must be involved both at the early planning stages, and stay engaged until the last closure maneuver is completed.
2. The unwavering support of executive management is crucial. A set of risk objectives must be defined, and the security team should be communicating the progress and necessary controls to meet those goals. Cybersecurity flows across all domains of the entire M&A team, and therefore must be a part of the leadership team.
3. Understanding the value proposition and goals of the M&A is crucial to identifying risks, knowing what to evaluate, and strategically planning the right balance of controls.
4. For regulated industries and sensitive intellectual property related acquisitions, profiling the data is key. Knowing what data is involved, its sensitivity, who has logical/physical access, and where it is physically located is necessary. It will be needed to ensure regulatory, legal, and IP confidentiality protection.
5. To prevail, both technical and behavioral security considerations must be incorporated into the business transition plan. Neither must be ignored and in most cases, the combination must be applied to every issue where cybersecurity is at risk. A security-savvy M&A team is the first step to highly effective results.
6. Logical and physical security aspects cannot be separated. Cybersecurity professionals can easily overlook the physical security factors which can jeopardize the confidentiality, integrity, and availability of the business.
7. Great attention must be paid to data retention, transfer, and destruction. “Deal data” can be a vague and changing concept that may be interpreted differently over time, especially in larger transactions. Understanding the scope, expectations, and commitments is a necessity.
8. Managing digital risks requires a community effort. Effective M&A cybersecurity requires a knowledgeable team, good leadership, and broad support to efficiently achieve the stated goals with consistency and comprehensiveness.
Conclusion
The range of tactical issues that an M&A cybersecurity team must understand and explore for each deal is wide and deeply complex. For a quick overview, I published a reference years ago which highlights the most significant Areas of Interest for internal cybersecurity. For acquisitions with products and services, there are a few more aspects to consider.

The complete presentation of M&A Areas of Interest can be found here: https://www.slideshare.net/MatthewRosenquist/mergers-and-acquisition-security
About the Author
Matthew Rosenquist is the Chief Information Security Officer (CISO) for Eclipz, the former Cybersecurity Strategist for Intel Corp, and benefits from 30 diverse years in the fields of cyber, physical, and information security. Mr. Rosenquist specializes in security strategy, measuring value, developing best-practices for cost-effective capabilities, and establishing organizations that deliver optimal levels of cybersecurity, privacy, ethics, and safety. As a cybersecurity strategist, he identifies emerging risks and opportunities to help organizations balance threats, costs, and usability factors to achieve an optimal level of security. Mr. Rosenquist is very active in the industry. He is an experienced keynote speaker, collaborates with industry partners to tackle pressing problems, and has published acclaimed articles, white papers, blogs, and videos on a wide range of cybersecurity topics. Mr. Rosenquist is a member of multiple advisory boards and consults on best-practices and emerging risks to academic, business, and government audiences across the globe.
Disclaimer
All views are personal and attributed to the author(s). The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.
Lapse in Security! Pfizers Inadvertently Exposes PII of U.S. Prescription Drug Users
Global pharmaceutical company Pfizer inadvertently exposed Personal Identifiable Information (PII) of hundreds of prescription drug users in the U.S. after its misconfigured Google Cloud Storage bucket was left online. According to security experts from vpnMentor, the bucket contained prescriptions and transcripts between users of various Pfizer drugs like Lyrica, Chantix, and cancer treatments Ibrance, and Aromasin, and the company’s interactive voice response (IVR) customer support software.
The misconfigured bucket leaked hundreds of transcripts including their personal data like full names, home addresses, email addresses, phone numbers, partial details of health, and medical status. The misconfigured cloud bucket is now secured after vpnMentor’s researchers reported the issue.
What’s the Impact?
While there is no information on whether any threat actors accessed the leaky database, vpnMentor’s researchers stated that cybercriminals could exploit the leaked data by targeting drug users in phishing campaigns and other fraudulent schemes.
“If cybercriminals succeeded in tricking a victim into providing additional PII data, they could use this to pursue various forms of fraud, including total identity theft. In doing so, they could destroy a person’s financial well-being and create tremendous difficulty in their personal lives. Furthermore, there is a high probability the people exposed in these transcripts are experiencing ill health, physically, and emotionally,” the researchers added.
Worth of Medical Data
A survey from cybersecurity firm Carbon Black stated the rate of cyberattacks on the health care industry appears to be increasing exponentially. Carbon Black disclosed what is happening to the Personal Health Information (PHI) that was stolen by cybercriminals. The survey, which involved 20 of the health care industry’s Chief Information Security Officers (CISOs), found the health care sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It is said that personal health information is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.
Promon Proves Trump and Biden’s Election Apps are Easy Targets of Cyberattacks
The U.S. Presidential Elections will be held on November 3, 2020. The two candidates, President Donald Trump and Republican candidate Joe Biden are going head-to-head in many states, so much so that even the exit polls present uncertainties. The two have made many public appearances during their presidential campaigns to reach out to the masses and address their concerns. During one such campaign rally held in Tucson, Arizona, Trump sadly played down the grievousness of hacking, stating, “Nobody gets Hacked.” However, days later, Promon, a Norwegian cybersecurity firm, hacked both Trump and Joe Biden’s election apps to prove: “Everything can be hacked.”
“Nobody gets hacked. To get hacked you need somebody with 197 IQ and he needs about 15 percent of your password.”pic.twitter.com/6aR8yU2MVg
— Judy Ruliani (@mshelton) October 19, 2020
Key Highlights
- At a campaign event in Tucson, Arizona on October 21, President Trump made a false claim that “Nobody gets Hacked.”
- Promon cybersecurity firm’s white hat hackers used a well-known Android vulnerability to alter President Trump’s and his rival Joe Biden’s election apps to show nothing is safe.
- Experts at Promon said that the same weakness could be used to steal personal data of app users.
- The claim shocked everyone as President Trump’s Twitter account and hotel chain have both been hacked previously.
What is the Vulnerability?
The white hat hackers at Promon were analyzing the election apps of the two candidates when they discovered that both apps were highly vulnerable to a known and critical Android vulnerability known as StrandHogg. This vulnerability allows malware gangs to hijack legitimate apps and perform malicious operations like phishing. In fact, the 2.0 version of this vulnerability enables cybercriminals to hijack nearly any app running on Android 9.0 devices and below. This further enables stealing of user credentials without any fuss.
Related News:
StrandHogg Vulnerability Hunting All Android Versions
StrandHogg 2.0 Impersonates Real Android Apps to Steal User Data
Promon’s Chief Technology Officer, Tom Lysemose Hansen said, “The president’s statement sadly reflects a widely believed sentiment that secure passwords will protect you from hackers and that hacking, in general, doesn’t affect the average citizen. Sadly, this isn’t the case. Absolutely nothing is ‘unhackable’ and even the most secure, high profile accounts are vulnerable should the user fall victim to a phishing attack which seeks usernames and passwords.” He added, “The claim that ‘nobody gets hacked’ is simply untrue and — given the influence of the president — can have dangerous impacts on the behavior of hundreds of thousands of people.”
So, the bottom line of the entire episode is that “Everything can be hacked,”— yes, even POTUS apps and accounts. So no one should be complacent when it comes to their personal online cybersecurity.
Tell us more about your Endpoint Security knowledge and win lots of amazing goodies!
Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial
Indian pharmaceutical company Dr. Reddy’s Laboratories Ltd. (DRL) was forced to shut down its operations temporarily after a cyberattack hit its data center services, which are located in India, the U.S., the U.K., Brazil, and Russia. While the information on whether any data or facilities have been affected is unknown, the company said it had isolated all of its data center services as a precautionary measure.
Chief Information Officer Mukesh Rathi at DRL, said, “In the wake of a detected cyberattack, we have isolated all data center services to take required preventive actions. We are anticipating all services to be up within 24 hours, and we do not foresee any major impact on our operations due to this incident.”
Target on COVID-19 Vaccine Research?
The security incident occurred after Dr. Reddy’s received approval from the Drugs Controller General of India (DCGI) to conduct clinical trials of the Russian COVID-19 vaccine in India.
Ever since the pandemic began, several attacks have been reported on organizations that are conducting research on COVID-19 vaccine. Recently, the FBI stated that certain state-backed threat actors broke into the U.S. research institutions, which are working on COVID-19-related research. Tonya Ugoretz, Deputy Assistant Director at the FBI and head of the bureau’s Cyber Readiness and Intelligence Branch, warned that foreign government-sponsored hackers have targeted the U.S. in different ways, including attempts to steal information from the national health care sector and COVID-19 research centers.
The U.K.’s National Cyber Security Centre (NCSC), Canada’s Communications Security Establishment (CSE), and the U.S. National Security Agency (NSA) stated that a cyber espionage group APT29 is trying to steal information and intellectual property related to the testing and development of Coronavirus vaccines.











