Home Blog Page 155

Update Before it’s Late: SonicWall VPN Portal Critical Flaw Could Result in DoS Attacks

Nearly 800,000 SonicWall VPNs Were Affected Due to Portal Critical Flaw

A stack-based buffer overflow flaw in SonicWall Network Security Appliance (NSA) could affect nearly 800,000 SonicWall VPNs across the globe, if not patched. According to security researcher Craig Young from Tripwire VERT, the vulnerability CVE-2020-5135 can be exploited by an unauthenticated HTTP request involving a custom protocol handler. The issue exists in the HTTP/HTTPS service, which is used for product management and for SSL VPN remote access.

What is the Impact?

An attacker can abuse the vulnerability to launch a persistent denial of service (DoS) and remote code execution (RCE) attacks. The vulnerability has affected HTTP server banner indicated 795,357 hosts till now. The flaw exists pre-authentication and within a component (SSLVPN), which is exposed online.


Complete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!


The vulnerable versions include:

  • SonicOS 6.5.4.7-79n and earlier
  • SonicOS 6.5.1.11-4n and earlier
  • SonicOS 6.0.5.3-93o and earlier
  • SonicOSv 6.5.4.4-44v-21-794 and earlier
  • SonicOS 7.0.0.0-1

Required Remediation

SonicWall stated it released a patch to remediate the vulnerability. The company asked users to take SSL VPN portals offline for temporary mitigation before patching.

SonicWall recommended its users to update their portals with the following versions to fix the flaw:

  • SonicOS 6.5.4.7-83n
  • SonicOS 6.5.1.12-1n
  • SonicOS 6.0.5.3-94o
  • SonicOS 6.5.4.v-21s-987
  • Gen 7 7.0.0.0-2 and onwards

“Immediately upon discovery, SonicWall researchers conducted extensive testing and code review to confirm the third-party research. This analysis led to the discovery of additional unique vulnerabilities to virtual and hardware appliances requiring Common Vulnerabilities and Exposures (CVE) listings based on the Common Vulnerability Scoring System (CVSS). The team worked to duplicate the issues and develop, test and release patches for the affected products. At this time, SonicWall is not aware of a vulnerability that has been exploited or that any customer has been impacted,” SonicWall said in a statement.

Related story: What are the Best VPN Services in 2020?

Social Engineering: Life Blood of Data Exploitation (Phishing)

phishing scam, fake CV phishing scam

What do Jeffrey Dahmer, Ted Bundy, Wayne Gacy, Dennis Rader, and Frank Abigail all have in common, aside from the obvious fact that they are all criminals?  They are also all master manipulators that utilize the art of social engineering to outwit their unsuspecting victims into providing them with the object or objects that they desire.  They appear as angels of light but are no more than ravenous wolves in sheep’s clothing. There are six components of an information system: Humans, Hardware, Software, Data, Network Communication, and Policies; with the human being the weakest link of the six.

By Zachery S. Mitcham, MSA, CCISO, CSIH, VP and Chief Information Security Officer, SURGE Professional Services-Group
Social engineering is the art of utilizing deception to manipulate a subject into providing the manipulator with the object or objects they are seeking to obtain. Pretexting is often used in order to present a false perception of having creditability via sources universally known to be valid. It is a dangerous combination to be gullible and greedy. Social engineers prey on the gullible and greedy using the full range of human emotions to exploit their weaknesses via various scams, of which the most popular being phishing.  They have the uncanny ability to influence their victim to comply with their demands.

Phishing is an age-old process of scamming a victim out of something by utilizing bait that appears to be legitimate. Prior to the age of computing, phishing was conducted mainly through chain mail but has evolved over the years in cyberspace via electronic mail. One of the most popular phishing scams is the Nigerian 419 scam, which is named after the Nigerian criminal code that addresses the crime.

Information security professionals normally eliminate the idea of social norms when investigating cybercrime.  Otherwise, you will be led into morose mole tunnels going nowhere. They understand that the social engineering cybercriminal capitalizes on unsuspecting targets of opportunity. Implicit biases can lead to the demise of the possessor. Human behavior can work to your disadvantage if left unchecked. You profile one while unwittingly becoming a victim of the transgressions of another. These inherent and natural tendencies can lead to breaches of security. The most successful cybersecurity investigators have a thorough understanding of the sophisticated criminal mind.

Victims of social engineering often feel sad and embarrassed. They are reluctant to report the crime depending on its magnitude. And the CISO to comes the rescue! In order to get to the root cause of the to determine the damage caused to the enterprise, the CISO must put the victim at ease by letting them know that they are not alone in their unwitting entanglement.

These are some tips that can assist you with an anti-social engineering strategy for your enterprise: Employ Sociological education tools by developing a comprehensive Information Security Awareness and Training program addressing all six basic components that make up the information system. The majority of security threats that exist on the network are a direct result of insider threats caused by humans, no matter if they are unintentional or deliberate. The most effective way an organization can mitigate the damaged caused by insider threats is to develop effective security awareness and training program that is ongoing and mandatory.

Deploy enterprise technological tools that protect your human capital against themselves.

Digital Rights Management (DRM) and Data Loss Prevention (DLP) serve as effective defensive tools that protect from the exfiltration enterprise data in the event that it falls into the wrong hands.

On a macro level, local and universal government agencies must be seamlessly collaborative in addressing this cybercrime and bringing cybercriminals to justice.

Security is everyone’s business. So, let’s together create a ubiquitous culture of informed secure consumers. Each one reaching one, each one teaching one. Lifting as we climb. We can change the world one head at a time!


About the Author

Zachery S. MitchamZachery S. Mitcham, MSA, CCISO, CSIH is the VP and Chief Information Security Officer at SURGE Professional Services-Group. He is a 20-year veteran of the United States Army where he retired as a Major. He earned his BBA in Business Administration from Mercer UniversityEugene W. Stetson School of Business and Economics. He also earned an MSA in Administration from Central Michigan University. Zachery graduated from the United States Army School of Information Technology where he earned a diploma with a concentration in systems automation. He completed a graduate studies professional development program earning a Strategic Management Graduate Certificate at Harvard University extension school. Mr. Mitcham holds several computer security certificates from various institutions of higher education to include Stanford, Villanova, Carnegie-Mellon Universities, and the University of Central Florida. He is certified as a Chief Information Security Officer by the EC-Council and a Certified Computer Security Incident Handler from the Software Engineering Institute at Carnegie Mellon University. Zachery received his Information Systems Security Management credentials as an Information Systems Security Officer from the Department of Defense Intelligence Information Systems Accreditations Course in Kaiserslautern, Germany.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

CISA Advises Enterprises to Patch Two Critical Microsoft Vulnerabilities

Critical Patch Tuesday Vulnerabilities

Last week, Microsoft released the Patch Tuesday Update for October 2020. For the first time in seven consecutive months it fixed less than 100 vulnerabilities, 87 to be precise. The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has taken note of the entire list of fixed vulnerabilities, and on Friday issued an advisory for enterprises’ specifically asking them to apply required patches for the two Microsoft vulnerabilities – RCE Windows Codecs and Visual Studio Code – in last week’s Patch Tuesday update.

The two CVEs, CVE-2020-17022 and CVE-2020-17023, had a CVSS rating of 7.8 and were highlighted as “important” by Microsoft. Talking about the severity of the vulnerabilities disclosed, Tenable’s Security Response Manager, Rody Quinlan, said, “The former is a remote code execution (RCE) vulnerability in the Microsoft Windows Codecs Library given how it handles objects in memory, specifically versions prior to 1.0.32762.0 or 1.0.32763.0 of the High-Efficiency Video Coding (HVEC) video codecs. However, the latter is an RCE vulnerability in Visual Studio Code that can be triggered by the opening of a malicious “package.json” file. This vulnerability stems from an unsuccessful patch for CVE-2020-16881 released as part of Microsoft’s regular Patch Tuesday updates in September.”

Related News:
October Patch Tuesday Alert! Microsoft Fixes 87 Vulnerabilities Including 11 Critical Ones

Quinlan also explained that although these are RCEs, both require a degree of social engineering to exploit. In the case of CVE-2020-17022, a threat actor would need to convince a victim to use a program to process a maliciously crafted image file. For CVE-2020-17023, a threat actor must convince a victim to clone a repository, with a malicious “package.json” and open it in Visual Studio Code. But there is one similarity between the two. If exploited successfully, either of the vulnerability results in the execution of arbitrary code on the target system.


CISO MAG Endpoint Security SurveyComplete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!!!


Microsoft does not commonly release out-of-band (OOB) patches. However, in the case of CVE-2020-17022, Microsoft notes, “These updates are for optional apps/components that are offered to customers as a download via the Microsoft Store,” hence the OOB patching approach. For CVE-2020-17022, Microsoft notes, “Affected customers will be automatically updated by Microsoft Store.”

With CVE-2020-17023 requiring an update, coupled with an out-of-band advisory, both CISA and Quinlan have encouraged administrators to patch this vulnerability quickly. While Microsoft highlights that there has been no exploitation observed in the wild, the follow up of the CISA advisory suggests that administrators should review the patches and apply the updates if necessary.

Related News:
CISA Issues Advisory on Mitigating Risks Originating from Tor

How Attackers Use Redirector Domains to Target Microsoft and Google Users

phishing campaign, Smishing attacks

Threat intelligence team from GreatHorn uncovered a series of ongoing phishing campaigns targeting users of Microsoft’s Office 365 and Google’s Gmail. The attackers are using imposter open redirector domains and subsidiary domains of various popular brands and sending tens of thousands of emails to corporate account users globally.

The comprehensive and multi-pronged attack campaign has multiple hosting services and web servers that are used to host fraudulent Office 365 login pages. It is also found that malicious links and fraudulent emails/attachments are bypassing users’ security controls and email security platforms. 


CISO MAG Endpoint Security SurveyComplete the Endpoint Security Survey and win lots of amazing prizes.

Take the Survey Now!!!


Spoofing the Popular

GreatHorn researchers stated that phishing actors attempt to steal corporate email credentials, along with malicious JavaScript that deploys various Trojans and malware on any user who visits these fraudulent links/web pages, even if they do not submit their credentials. The attackers are spoofing well-known applications like Microsoft Office, Zoom, and Microsoft Teams to evade detection.

“The phishing webpages impersonate a Microsoft Office 365 login, use the Microsoft logo and request that users enter their password, verify their account, or sign-in. Given this campaign’s breadth and highly targeted nature, the sophistication and complexity suggest that the attackers’ significant coordinated effort is underway,” the researchers said.

Image Courtesy: GreatHorn

The researchers also identified hackers’ attempts to deploy the Cryxos Trojan on multiple browsers, including Chrome and Safari. The domains redirecting the users to the phishing kit and fraudulent login pages include:

  • sony-europe.com (Sony)
  • com (TripAdvisor)
  • co.uk (RAC)

Webpage services hosting the phishing kit include digitaloceanspaces.com (DigitalOcean) and firebasestorage.googleapis.com (Google).

GreatHorn recommended organizations to search their email networks for messages containing URLs that match the threat pattern (http://t.****/r/) and remove if found any. “The GreatHorn Threat Intelligence Team has identified senior executives and finance personnel being targeted within the phishing campaigns. For organizations who are using role-based email security, users within these roles can be placed on more restrictive policies to minimize the risk associated with these attacks,” GreatHorn researchers added.

Microsoft Tops the Chart for Being Most Imitated Brand for Phishing Attacks

Brand Phishing Attacks

Check Point Research, a global cybersecurity solutions provider, has published its Brand Phishing Report for Q3 2020. In its previous report for Q2 2020, Google and Amazon made it to the list of being the most impersonated brands. However, with organizations largely adopting Microsoft for its collaborative offerings of Office suite, it has now become the hot favorite for cybercriminals too, as the report highlights it as the “Most Imitated Brand for Phishing Attacks.”

Microsoft’s Rise to the Top

In the Q3 2020 report, the tech giant rose from the fifth place (relating to 7% of all global brand phishing attempts) to become the table topper (with 19% in the overall share). The researchers at Check Point are attributing this sudden rise to the continued growth of the remote workforce in the ongoing pandemic.


CISO MAG Endpoint Security SurveyComplete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!!!


Threat actors are taking advantage of the mass migration to a remote workforce. They are targeting employees with fake emails asking them to reset their Microsoft Office 365 credentials.

Maya Horowitz, Director, Threat Intelligence & Research, Products at Check Point said, “In this past quarter, we saw the highest increase in email phishing attacks of all platforms compared to Q2, with Microsoft being the most impersonated brand. This has been driven by threat actors taking advantage of the mass migration to remote working forced by the Covid-19 pandemic, to target employees with fake emails asking them to reset their Microsoft Office 365 credentials. As always, we encourage users to be cautious when divulging personal data and credentials to business applications, and to think twice before opening email attachments or links, especially emails that claim to be from companies, such as Microsoft or Google, who are most likely to be impersonated.”

As per Check Point researchers, Microsoft phishing email aims at stealing credentials. During mid-August, they witnessed a malicious phishing email trying to steal credentials of Microsoft accounts. The attacker was trying to lure the victim into clicking on a malicious link, which redirects the user to a fraudulent Microsoft login page.

Another surprise entry to this list was the first-time entrant for 2020, DHL. It has made it to the top 10 rankings, taking the second spot with 9% of all phishing attempts related to the company. The list of the top phishing brands in Q3 2020, based on their overall appearance in brand phishing attempts, includes:

  1. Microsoft (related to 19% of all brand phishing attempts globally)
  2. DHL (9%)
  3. Google (9%)
  4. PayPal (6%)
  5. Netflix (6%)
  6. Facebook (5%)
  7. Apple (5%)
  8. WhatsApp (5%)
  9. Amazon (4%)
  10. Instagram (4%)

Other Findings

In other findings from the research, the most likely industry to be targeted by brand phishing is technology, with banking and social network following closely. It illustrates a broad spread of some of the best-known and most-used consumer sectors, particularly during the COVID-19 pandemic, wherein individuals are grappling with remote working technology, potential changes to finances, and increased use of social media.

Top phishing brands by platform

During Q3 2020, email phishing was the most prominent type of brand phishing platform, accounting for 44% of the attacks, followed by web and mobile phishing. The top phishing brands exploited by email, web, and mobile phishing attacks are displayed below in ascending order.

Email (44% of all phishing attacks during Q3)
  1. Microsoft
  2. DHL
  3. Apple
Web (43% of all phishing attacks during Q3)
  1. Microsoft
  2. Google
  3. PayPal
Mobile (12% of all phishing attacks during Q3)
  1. WhatsApp
  2. PayPal
  3. Facebook

75% U.S. States and Territories Graded ‘C’ for Poor Cybersecurity

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

A survey from cybersecurity firm SecurityScorecard revealed the overall security posture of all 56 U.S. states and territories, which are leading up to the presidential election. The survey “State of the States” found that over 75% of the states indicating signs of a vulnerable IT infrastructure. The U.S. states were ranked with grades, where grade C states are 3x more likely to experience a cyberattack and grade D are nearly 5x more likely to experience an attack.

Key Findings

  • 75% of the U.S. states and territories’ overall cyberhealth are rated a ‘C’ or below; 35% have a ‘D’ and below
  • States with the highest scores include Kentucky, Kansas, and Michigan
  • States with the lowest scores include North Dakota, Illinois, and Oklahoma
  • Significant security concerns were observed, with two critically important battleground states, Iowa, and Ohio, both of which scored a ‘D’ rating.

 

The survey also highlighted that the states with lower scores are prone to phishing attacks and threats from third-party vendors. “These poor scores have consequences that go beyond elections; the findings show chronic underinvestment in IT by state governments. For instance, combatting COVID-19 requires the federal government to rely on the apparatus of the states. It suggests the need for a massive influx of funds as part of any future stimulus to refresh state IT systems to not only ensure safe and secure elections but save more lives,” said Rob Knake, the former Director for Cybersecurity Policy at the White House in the Obama Administration.

Mitigation Measures

SecurityScorecard also recommended certain practices for the U.S. states to defend against potential attacks. These include:

  • Create dedicated voter and election-specific websites under the domains of the official state domain, rather than using alternative domain names, which can be subjected to typosquatting.
  • Have an IT team specifically tasked and accountable for bolstering voter and election website cybersecurity.
  • States should establish clear lines of authority for updating the information on these sites that includes the two-person rule — no single individual should be able to update information without a second person authorizing it.
  • States and counties should continuously monitor the cybersecurity exposure of all assets associated with election systems and ensure that vendors supplying equipment and services to the election process undergo stringent processes.

Managing IoT Data Security Risks: The Need to Secure Data in Modern Computing

Internet of Things

The demands to defend the information on edge devices have reached a new pinnacle and continues to grow beyond what current capabilities can handle. Legacy cybersecurity systems that ensure the confidentiality, integrity, availability and the proper use of data from edge devices are not sufficient for the growing scale of the Internet of Things (IoT) and Industrial IoT (IIoT). Innovation in technology and process is needed to deliver the robustness necessary to defend against a world of ever-evolving cyber threats.

By Andy Brown, CEO and Co-Founder, Sand Hill East; and Matthew Rosenquist, CISO, Eclipz

A policy framework is required that is specifically crafted for edge environments and implemented through technical controls and configuration. A structure of robust architectures and practices must protect the data from exposure, exploitation, and manipulation. They must be designed for sustainability over the extended lifecycle of these types of products, and adapt to the new tactics of emerging threats.

Since their inception, internet-connected devices have become vastly more complex, capable, and specialized. To improve performance and responsiveness, much of the computing is now pushed closer to end-users, thus becoming edge devices. These act as sensors capable of providing valuable data to localized feedback loops. Continuous streams of information enable real-time insights into operations, potential issues, and emerging opportunities.  Such designs empower organizations around the world to automate processes and make favorable decisions promptly. In short, feedback loops powered by edge devices are fueling the global digital transformation to deliver efficiency and modern automation.

A significant reduction of costs and an increase in functionality have propelled the explosive adoption rates of IoT/IIoT devices. However, the benefits of greater visibility and empowerment come with risks that are unfamiliar and, in many cases, hidden. The exposure and corruption of this feedback data can cause catastrophic downstream impacts for the continuity of operations, protect personal privacy, and people’s safety. The breaching of sensors and the data they create can be wielded for unethical or undesired purposes, to the detriment of organizations, partners, customers, and society.

Secure the data

Data security has emerged as a crucial requirement for complex automated systems. However, providing trust in digital systems is proving difficult because legacy technologies are not well-suited for a more autonomous world. All major industries are embracing digital technologies for enhanced capabilities, faster results, and better decisions. In doing so, they are also inheriting the risks of undermined systems.

Data provides a competitive advantage. Manufacturing, retail, transportation, defense, and every sector of Critical Infrastructure (CI) are leveraging digital sensors and becoming reliant upon the insights they provide. A continuous stream of the right data is the key to assessing situations and acting decisively. In complex environments, interconnected feedback and decision loops are the backbones of most operational practices. These systems need a constant stream of incoming information to adjust and achieve the desired goals. However, erroneous or tampered data may pose a risk by providing incorrect information that undermines good decisions. Without proper security controls, honest mistakes or malicious attackers can undermine the very foundations of automation and business decisions.

Increased scale and complexity; increased risk

Much of our growing digital ecosystem is or will be reliant on the principles of the simple feedback loop through sensors that provide data for instantaneous decision-making.  There is a race to embrace new technology and adopt automation solutions that deliver a business advantage.  The possibilities are as limitless as our imagination, but so are the associated risks. Sensor data makes possible the automated online processes we have come to take for granted, such as online storefront order processing, shipment logistics, and healthcare monitoring. Manufacturers can increase production speed and improve consistency. Dangerous environments can be monitored and managed for safety. Manipulation of digital sensors and data can make all of these automated processes go wrong. Industry professionals have long expressed concern that most of the billions of IoT and IIoT devices in the world are vulnerable. This reality places global services, national economies, personal privacy, and the safety of people’s lives at an ever-growing risk.

The defense of sensors and edge devices can’t be achieved with the same techniques that evolved with traditional desktops, servers, and laptops. Modern personal computers and servers are built with tremendous computational power, memory, and storage resources to be flexible across a wide range of tasks. IoT sensors and devices are designed with the opposite in mind, generally with a specific purpose to be as economical and streamlined as possible. They are in a different class entirely and do not benefit from an abundance of computing resources.

Current tools fall short

Most cybersecurity tools have evolved to leverage the extensive system resources in personal computers and servers to provide comprehensive protection. These solutions are not compatible due to IoT limitations. Very few solutions are available to meet the specialized needs of something as small as a sensor.

The scale and diversity of the IoT landscape compound the problem. An additional 4 billion IoT devices are predicted to come online in 2020. These systems will add to the vast amount of data already existing for an estimated total of 100 trillion gigabytes by the end of 2020. IoT/IIoT are often deployed in clusters, aren’t very well-protected, and may represent the weakest link that hackers and malicious agents can use to gain a foothold to attack other systems.

The IoT industry has begun to address the first order of issues that resulted from poor designs and the omission of basic security features. As a first step, the focus is on protecting the devices themselves from exploitation. Changing default passwords, removing manufacturer administration and testing backdoors, and requiring user authentication are now standard practices. What has not been addressed is the more difficult problem of fortifying the data and network connections to and from these devices. Vast exposures are still present.

What exactly is at risk?

Digital sensors and systems contribute to the safety of employees and customers and are vital components to critical systems. Due to this importance, they are targeted by cyber threats. The more the world relies upon computer-based services, the more the attackers’ leverage when they disrupt or control these systems. As automation increases, the complexity grows, and systems become more sensitive to significant impacts. An increasingly online yet unguarded world creates many possible safety concerns.

After years of warnings from cybersecurity professionals, the predictions came true: attackers turned their attention to IoT devices. Everything from industrial controls, healthcare tools, entertainment systems, vehicles, telecommunications, and home surveillance cameras have been successfully hacked. An IoT-powered botnet brought down significant portions of the Internet on the American eastern seaboard for an uncomfortable amount of time in one attack. Implanted medical defibrillators and pacemakers were shown to be exploitable and had to be replaced in patients. Power plants and regional distribution grids have been targeted. Hackers can also tap into cameras and watch victims in public settings, offices, and in the privacy of their homes. There have been instances of hackers taking control of automobiles and aircraft. Private information has been scraped from retail devices and personal health monitoring devices. Implanted medical devices and emergency room equipment are vulnerable to compromise. The range is incredible, from small sensors and home appliances to the biggest planes, ships, chemical plants, and power distribution networks.

Even a trivial device makes a difference. Sensor data for chemical spills, fires, and unsafe breathing conditions may automatically trigger fire suppression, evacuations, and emergency response. Data that falsely report an unacceptable temperature drop in stored foods might require the assets to be discarded. Worse, if the controls were tampered with and the temperature did drop to unsafe levels without any alarms, then lethal consumables might be released for distribution to the public.

The list of confirmed vulnerable devices grows every week, demonstrating that these systems and the data they generate are at significant risk. The abundance of these dangers, whether actual or potential, requires a greater oversight to support a higher degree of confidence in the technology upon which we all depend. Malicious online attackers breed new threats that can undermine the confidentiality, integrity, and availability of data. Criminals target systems that they can easily manipulate to seize control, commit fraudulent activities, and steal sensitive information. Data, both at-rest, and in-transit must be protected from such attacks, and edge devices are easy targets on the front lines.

Innovation is necessary to safeguard data across the new digital landscape

The traditional model for digital security begins to unravel when enormous numbers of less sophisticated IoT/IIoT devices generate a vast amount of data that is not adequately protected. Current solutions simply don’t operate well within the limitations of IoT deployments. As cybersecurity professionals, we need innovative new technologies and processes to mitigate risks posed by current and emerging threats for this fastest-growing sector of computing devices. Solutions must overcome the challenges that traditional protections are unable to address. Securing devices, network connections, and the data that travels across them are paramount. The future of the Digital Transformation (DT) movement resides in preserving the trust that people place in technology, that it will act for their benefit and not maliciously against them. The solutions of the past become more obsolete as every day passes. Innovation that is specifically tailored to IoT is necessary to safeguard the benefits across the new digital landscape.


About the Authors

Andy Brown currently serves as CEO of Sand Hill East, LLC, which provides strategic management, investment, and marketing services to emerging companies. Brown is also a member of the boards of directors of Guidewire Inc., a public traded company in the PNC insurance business; Zscaler, Inc., a publicly-traded company providing cloud security services; LMRKTS LLC, a company providing FX and Swaps compression utilities; Moogsoft, a next-generation AI-Operations company; SiteHands, a company providing “field engineering as a service,” and Pure Storage, Inc., a publicly-traded software-defined data storage solutions company. He is also CEO and co-owner of Biz Tectonics LLC, a privately-held consulting company. From September 2010 to October 2013, Brown served as Group Chief Technology Officer of UBS, an investment bank. Prior to that, he served in a variety of executive management and leadership roles at a variety of leading banking companies including Bank of America, Merrill Lynch, and Credit Suisse. Brown holds a BSc Honors Degree in Chemical Physics from University College London.

Matthew RosenquistMatthew Rosenquist is the Chief Information Security Officer (CISO) for Eclipz, the former Cybersecurity Strategist for Intel Corp, and benefits from 30 diverse years in the fields of cyber, physical, and information security. Mr. Rosenquist specializes in security strategy, measuring value, developing best-practices for cost-effective capabilities, and establishing organizations that deliver optimal levels of cybersecurity, privacy, ethics, and safety.  As a cybersecurity strategist, he identifies emerging risks and opportunities to help organizations balance threats, costs, and usability factors to achieve an optimal level of security.  Mr. Rosenquist is very active in the industry.  He is an experienced keynote speaker, collaborates with industry partners to tackle pressing problems, and has published acclaimed articles, white papers, blogs, and videos on a wide range of cybersecurity topics.  Mr. Rosenquist is a member of multiple advisory boards and consults on best-practices and emerging risks to academic, business, and government audiences across the globe.

Disclaimer

All views are personal and attributed to the author(s). The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

3 Best VPN Services for Zoom in 2020

Fortinet VPN, VPN, VPN devices

Since the beginning of the pandemic, the number of Zoom users has skyrocketed considering most meetings and school lessons were being held online. The platform is user-friendly and free but unfortunately comes with multiple security concerns.

By Joshua Blackborne

But with the advent of Zoom come other sorts of problems. Starting from an alleged hack of half a million accounts to Zoombombing, organizations and people need to take the best security measures at all times.

One way to go about it is to turn to VPN to ensure their zoom meetings are secure and private. This is what you need to know about VPNs for businesses and how to choose the most suitable VPN service for your needs.

VPNs for Business 

VPN refers to Virtual Private Network, a private network that hides the company’s activities, reduces the chance of cyberattacks, and enables communication with international clients by bypassing geo-restrictions.

Most businesses that use this valuable digital tool have remote employees or need to work online to some extent. That could mean holding the occasional Zoom meeting, giving employees remote access to the company’s digital platform, or working while traveling.

Remote work poses security threats, especially for employees who use public Wi-Fi or connect to the company’s systems without previously having their home devices secured. VPNs can aid with most of these issues.

Why You Need a VPN for Zoom 

For most organizations, Zoom has become an essential business tool. As mentioned, the rise in popularity of the Zoom platform is connected to its user-friendly experience but also the worldwide pandemic that accounted for over 300 million users of the platform daily.

However, the popularity of the platform does not equate to the cybersecurity of the system. Zoom is notorious for its cyber vulnerabilities, lack of end-to-end encryption, and privacy concerns.

For companies that need to keep in contact with their international clients, VPNs for business can surpass geo-restrictions, i.e. unblock Zoom in countries that have banned it. What’s more, VPNs significantly increase loading and connection speed.

Top 3 Business VPNs for Zoom 

Nowadays, many VPN services offer to protect your business and set up basic security systems. Which is the best VPN for your business needs depends on the size of the business, systems in use, and other company requirements.   

The top three chosen VPNs are household names in the world of cybersecurity, work with Zoom, and set the standard for any emerging VPN service.

1. CyberGhost

CyberGhost is ideal for businesses that employ remote workers such as freelancers who travel and need to use unsafe public Wi-Fi. They can be downloaded on any device and their services are available in the app stores as well.

It’s one of the most popular VPNs because of its user-friendly interface and blazing fast speeds. CyberGhost is also simple to install taking just a few minutes.

This VPN protects you from common Zoom vulnerabilities by encrypting your data and sending it through a safe and private tunnel that hackers can’t easily target.

2. NordVPN

NordVPN is another excellent choice for businesses that currently have multiple home-based employees. It is compatible with multiple devices and it offers great speed along with thousands of servers worldwide, making sure nothing interrupts the flow of the Zoom meeting.

What makes this VPN one of the leaders in the industry are multiple options when it comes to subscriptions and services. They launched a novel service for businesses NordVPN Teams that features many advanced options for managing your business.

This VPN also takes care of cybersecurity concerns that many Zoom users have. Namely, it protects your personal data using up-to-the-minute encryption. Furthermore, Nord has a strict no-log policy that ensures your data is safe from hackers.

3. Surfshark

Similar to NordVPN and ExpressVPN, Surfshark is big on cybersecurity and offers a VPN service that maximizes your speed, privacy, and more.

Surfshark is an ideal choice for businesses that need to connect multiple devices as it offers unlimited simultaneous connections.

To make sure your Zoom meetings are private and hidden from hacking activities, Surfshark uses 256-bit encryption, creates double VPN private networks, and no-log policy to protect your private information.

It is the most expensive out of the three but with additional features such as a built-in ad-block, Surfshark is a VPN for a business that saves a lot of time and money that you would otherwise spend on cybersecurity tools.

Conclusion 

Businesses that use Zoom need additional cybersecurity measures to protect themselves from data leakage and cyberattacks.

There is a lot to consider when choosing the right VPN for your business. However, top VPN service providers cover most of the security concerns of any business and they’ve become a requirement since more workplaces operate remotely.

Is your business protected?


PAID FEATURE

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

BLAZINGSUN: A New Breach on Joker’s Stash Dark Web

BLAZINGSUN: A New Breach on Joker’s Stash Dark Web

Dickey’s BBQ Pit, a popular barbecue restaurant chain in the U.S., is the latest victim of a data theft. Security experts from cybersecurity firm Gemini Advisory uncovered a data leak incident that appears to have been active since July 2019. Hackers illicitly obtained over three million customers’ credit card information after compromising Dickey’s Point-of-Sale (POS) systems in 156 restaurant locations out of 469.

The data breach came to light after attackers posted the stolen data for sale on Joker’s Stash, a dark web marketplace for trading stolen cards data. The researchers stated that the hackers were advertising a massive collection of payment card details for sale, dubbed “BLAZINGSUN,” at $17 per card. It also found that the payment transactions were processed via the outdated magstripe method.

“BLAZINGSUN would contain 3 million compromised cards with both track 1 and track 2 data. They purportedly came from 35 US states and some countries across Europe and Asia,” the advertisement claimed.

Image Courtesy: Gemini Advisory

While it is unclear how long the attackers were in the network, Dickey’s stated it has reported the incident to the FBI for further investigation. The company also asked its customers to monitor their banking statements for any fraudulent activity. “Based on previous Joker’s Stash major breaches, the records from Dickey’s will likely continue to be added to this marketplace over several months,” the researchers added.

Joker’s Stash – A Hacker’s Marketplace

A similar report from Gemini Advisory revealed that hackers kept payment card details of Wawa’s customers on Joker’s Stash. In an official statement, Wawa confirmed that hackers tried to sell customers’ card information that breached in the security incident occurred on December 10, 2019. The data belonged to 30 million Americans and over one million foreigners from more than 100 different countries. It is believed that Joker’s Stash contains debit/credit card details from the U.S., European, and global cardholders, including their geolocation data like state, city, and ZIP Code.

Ransomware Gang Feasts on Popular Indian Sweets and Snacks Brand Haldiram

Haldiram ransomware attack

The festive season in India has just begun, and although the COVID-19 pandemic has somewhat dampened the celebrations this year, many believe that these festivities could prove to be a positive boost for people and businesses alike, both emotionally and physically. Regional sweets and snacks add to the fervor of these celebrations; however, many people live away in the metro cities and miss these little things dearly. Thus, popular snack brands Haldiram take the onus of delivering happiness by serving their customers with delicacies from across the country to people living in the remotest nooks and corners of India. But it seems Haldiram itself has been served a bitter taste by a ransomware gang, which was able to compromise critical company data and demand a ₹7.5 lakh (approximately US$ 10,220) ransom as a payout.

 Key Highlights 

  • Indian cyber cell officials said that as per preliminary investigation done by the company, the stolen data included financial and employee information, data on payroll, retail sales, purchases, inventory of the company.
  • After initial internal investigations, Haldiram’s Deputy General Manager (DGM) filed an FIR at Noida Police Station where the investigation is still going on.

What Happened

As per the complaint filed by Aziz Khan, DGM I.T. at Haldiram, with Noida’s Police department, the incident first came to light when Haldiram’s servers based in Noida office located in sector 62 behaved abruptly and were cut-off from its other branches. He was quoted saying, “It was found that the company’s data was being diverted through the cyberattack following which the server connection with other branches was cut off. However, by then, substantial data had already been stolen. By 3 am, the ransomware had spread via the corporate network. A complaint was then raised with a cybersecurity company, but all sensitive data had already been encrypted by then.”

Aziz refrained from giving out any further information but said that this looked like a pre-planned attack, as hackers first deleted the backups from the servers, stole the data, and tried extorting money in return. He added, “They left a message on the servers about the ransomware attack and proposed decrypting and returning the data for a ransom of Rs 7.5 lakh.”

The Deputy Commissioner of Police (DCP) in charge of the jurisdiction said the Delhi cyber cell was investigating the case along with specialists from the company appointed cybersecurity firm and shall soon give an update on the case.

Related Stories:
Need for Cyber Training! Survey Finds Security Awareness Gaps in Indian Organizations
India Witnessed Over 1.45 Million Cybersecurity Incidents in Five Years