Home Blog Page 162

New InterPlanetary Storm Malware Variant Targets IoT Devices in Asia

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Deemed as an “unusual” security threat upon its discovery last year, the InterPlanetary Storm malware has resurfaced into the wild with a few add-on capabilities. It is now targeting Mac and Android-based IoT devices in addition to the Windows and Linux-based machines, with its primary targets set in Asia.

 Key Highlights 

  • The InterPlanetary Storm malware has resurfaced and now targeting Mac and Android-based IoT devices along with its primary targets, the Windows, and Linux-based machines.
  • Researchers have found nearly 13,500 devices being affected by this variant.
  • Majority (62%) of the machines infected by the malware are in Asia.

New Kid on the Block

The researchers at Barracuda have been studying the activity of the operators behind this malware for long and recently found that the malware itself is building a botnet. They fear that this botnet has already infected roughly 13,500 machines across 84 different countries around the globe, with a majority (62%) of them based in Asia.

The percentage-wise break-up of the locations of all infected machines is as follows:

  • 59% of infected machines are in Hong Kong, South Korea, and Taiwan
  • 8% are in Russia and Ukraine
  • 6% are in Brazil
  • 5% are in the United States and Canada
  • 3% are in Sweden
  • 3% are in China
  • All other countries are 1% or less

The InterPlanetary Storm malware, which was discovered in May 2019, uses the InterPlanetary File System (IPFS) p2p network and its underlying libp2p implementation. It first targeted Windows machines; however, the new variant, discovered in June 2020, is capable of attacking Linux and Android-based machines.  It is also targeting IoT devices, such as TVs that run on Android operating systems, and Linux-based machines, such as routers with ill-configured SSH service.

InterPlanetary Storm Malware Infection Routine

The new variant gains access to machines by running a dictionary attack against SSH servers. It can also gain entry by accessing open ADB (Android Debug Bridge) servers. The malware detects the CPU architecture and the OS on its victim’s machine, and then run through the ARM-based machines, which is a CPU based on reduced instruction set computer architecture (RISC), commonly used in routers and other IoT devices.

James Forbes-May, Vice President of APAC for Barracuda, said, “While the botnet that this malware is building does not have clear functionality yet, it gives the campaign operators a backdoor into the infected devices so they can later be used for cryptomining, DDoS, or other large-scale attacks.”

Other Features

Barracuda researchers found several unique features designed to help the malware protect itself once it has infected a machine. These include automatically updating itself to the latest available version; installing a service using a Go daemon package and killing other processes on the machine that pose a threat to the malware, such as debuggers and competing malware.

Forbes-May added, “In order to protect against such attacks, it’s incredibly important to properly configure SSH access on all devices. This means using keys instead of passwords, which will make access more secure. When password login is enabled and the service itself is accessible, the malware can exploit the ill-configured attack surface. This is an issue common with routers and IoT devices, so they make easy targets for this malware.

Using a cloud security posture management tool to monitor SSH access control to eliminate any configuration mistakes, which can be catastrophic, is crucial while deploying an MFA-enabled VPN connection and segmenting your networks, rather than granting access to broad IP networks, can provide an additional layer of security against this kind of attack.

HP Device Manager Susceptible to Dictionary Attacks

CISA vulnerabilities, Microsoft Vulnerabilities, HP Device Manager Susceptible to Dictionary Attacks

Security experts from IT giant HP announced that it has discovered multiple security vulnerabilities in certain versions of its HP Device Manager, a software that allows system administrators to manage their HP Thin Client devices. In a security advisory, HP stated the vulnerabilities could allow malicious actors to remotely gain unauthorized access to resources and also SYSTEM privileges. The flaws could also expose the Device Manager to dictionary attacks due to weak cipher implementation. In dictionary attacks, hackers try to obtain illicit access to a system by using a large set of words to generate potential passwords.

The issue came to light after security researcher Nick Bloor reported about the vulnerabilities. Bloor stated that an HP developer put a backdoor database user account in HP Device Manager, which leads to unauthenticated remote command execution as SYSTEM.

“Do you or your clients use HP thin clients and manage them with HP Device Manager? I strongly advise you, firstly, to log on to all servers running HP Device Manager and set a strong password for the ‘dm_postgres’ user of the ‘hpdmdb’ Postgres database on TCP port 40006,” Bloor added.

The vulnerabilities and affected versions include:

However, HP clarified that the CVE-2020-6925 vulnerability does not impact the users who are using Active Directory authenticated accounts. It also added that the CVE-2020-6927 flaw does not impact customers who are using an external database and have not installed the integrated Postgres service.

HP is stated that it will release security patches for all the vulnerabilities. Meanwhile, the company recommended certain security steps to partially mitigate the issues by:

  • Limiting incoming access to Device Manager ports 1099 and 40002 to trusted IPs or localhost only.
  • Removing the dm_postgres account from the Postgres database.
  • Updating the dm_postgres account password within HP Device Manager Configuration Manager.
  • Creating an inbound rule within Windows Firewall configuration to configure the PostgreSQL listening port (40006) for localhost access only.

“HP is broadly distributing this security bulletin to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action,” HP added.

CYBERSEC Global 2020: Together Against Adversarial Internet

Together Against Adversarial Internet

All those extra cups of coffee, long hours at the desk with our headphones on, and staying glued to our screens for the past three days, sounds tiring! However, it was worth every penny. The curtains have fallen on the 6th edition of the CYBERSEC Global 2020 but not before bringing the European nations together in the fight against adversarial internet.

Over the past three days, the conference gathered over 100 speakers who joined 40 panels and keynotes to discuss matters under the banner of “Together Against Adversarial Internet.” This online binge-conferencing experience gave people an opportunity to learn more about the state of global cybersecurity. For convenience and streamlining the presentations, it was aptly divided into four themes/streams: State, Future, Business, and Defense.

The State Stream

The voices on how cybersecurity should be addressed and worked upon by like-minded states were heard in unison. Different nations have different perspectives, but there was one common answer to it – Collaboration. Everyone agreed that only a collaborative effort can drive remarkable effects in cybersecurity. Even countries such as the U.K., a predominant cyber power in Europe, which also happened to be awarded with 2020 European CYBERSEC Award, shared this point of view. The U.K. assured that their allies are always welcome to use and share their innovative mindset and technology.

Related Posts:

CYBERSEC: Data is Worth More Than You Think!


Another talk of the table between members of various nation-states was setting up effective regulations and compliances that will not limit innovation. Regulations and compliances are necessary, but these should not be so ardent that they become a roadblock for innovators. We need to make some leeway. However, this also does not mean that innovators can get away with anything. Regulations are essential to prevent emerging technologies from getting out of control and being used in malicious ways. This is the real purpose of any form of regulation.

The Future and Business Stream

When it comes to the future of technology and businesses, and its implications on cybersecurity, like-minded countries need to find ways in the new digitized world, but at the same time, they must not forget how great the global Internet has been to the society. Diminishing its role in free information sharing would be a loss to humanity – admitted panelists. There was a great concern that the decoupling of supply chain and Splinternet will be the options that will drive the digital world in the future.

Making the future technologies and businesses more immune to cyberthreats while further developing them is an effort that requires collaboration on many levels. All stakeholders need to be invited to the conversation, from alliances, governments, and regulators, through businesses and academia, up to the individuals.

The Defense Stream

NATO is a binding authority in the European continent. It has often been lauded for the peacekeeping initiatives undertaken in the physical and cyber worlds. Representatives from NATO suggested that “just as we internationally cooperate in exploring outer space, we could find a compromise in using new technologies that are available globally.” NATO has in fact gone ahead and already identified both cyber and outer space as operational domains.

The internet was primarily developed for military use and was later populated towards open and commercial use due to its ease and usability advantages. Many private players also came up with new ideas that have and shall in future be beneficial for defensive forces. This, however, creates security challenges such as in the case of 5G network deployment — the technology that can contribute greatly to further growth of our society. For military use and state security, the infrastructure needs to be set up carefully, with the highest security standards kept in mind.

Closing Notes

CYBERSEC Global 2020 was not just a thought-leadership conference, it was a venue for individual talks between leaders and experts from businesses, governments, NGOs, and many other entities. CYBERSEC has always been a physical conference but unprecedented times require unprecedented solutions. Citing the loss of knowledge and information sharing which could be caused if this event were skipped, the organizers, The Kosciuszko Institute, took the effort of taking it to the online virtual platform.

Samir Saran, CEO of Observer Research Foundation from India, said, “What 9/11 had been for the security, COVID-19 is for the digitization”. This is a great summary of what we are witnessing today and a call to action in the nearest future. Solid technological advantage and engraving security into the DNA of the digital world can have the decisive impact on the world we live in. But this needs to be done in a collaborative manner, which is why standing united in the fight against adversarial internet is the need of the hour.

Related Posts:

CYBERSEC: Make Cybersecurity a Global Effort

Data Breach Affected 2Mn Users of Indian E-Learning Platform Edureka

School apps sharing students’ data

Security researchers from SafetyDetectives discovered an unsecured Elasticsearch server belonging to an Indian e-learning platform Edureka, which exposed the personal information of around 2 million users. The researchers stated that the server was left online without password protection, allowing open access to the information in it.

The researchers found the vulnerability on August 1, 2020, with prominent security flaws. The leaky database was secured after SafetyDetectives reported the issue to the Indian Computer Emergency Response Team (CERT-In). The server, located in the U.S. and hosted by AWS, exposed more than 45 million records totaling to 27 gigabytes, including first names, email addresses, phone numbers, country of residence, login activity records, Auth token information, and courses/information users had accessed previously.

The Breach Impact

The data breach could impact users if the exposed information falls into the wrong hands. Cybercriminals could exploit the stolen personal information to launch various socially engineered attacks and phishing scams.

“Users’ contact details could be harnessed to conduct a wide variety of scams while personal information from the leak could be used to encourage click-throughs and malware downloads. Personal information is also used by hackers to build up rapport and trust, with a view of carrying out a larger magnitude intrusion in the future. With access to highly sensitive information, Edureka’s compromised server security could have been devastating to entire organizations such as other universities, companies, or government departments,” SafetyDetectives said.

E-Learning Platforms @ Risk

There has been a surge in the usage of online learning platforms during the ongoing pandemic. In the recent past, hackers targeted multiple e-learning portals to steal users’ personal information. India-based online learning platform Unacademy also suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe.

Twitter Appoints Cybersecurity Veteran Rinki Sethi as CISO

After leaving the position of CISO vacant for months, Twitter has finally hired cybersecurity veteran Rinki Sethi to the role. Sethi will report to Nick Tornow, Platform Lead of Twitter. In her role, she will work closely with teams such as the Privacy & Data Protection and will address key initiatives to ensure the staff and the company’s board stays up to date on cybersecurity-related issues. She will also oversee Twitter’s cybersecurity and information security posture, Enterprise Risk, Security Risk, Application Security, Detection & Response, etc.

Sethi has served several security leadership roles in a few of the largest technology companies in the world. Prior to Twitter, Sethi was the Vice President and CISO of cloud data management company, Rubrik. Prior to that, she served as the Vice President for Information Security at IBM. She was also the Vice President for Information Security at cybersecurity firm Palo Alto Networks as well as Director & Head of Product Security at Intuit. In a career spanning more than two decades in information security, Sethi has also helmed several leadership roles in companies like eBay, Walmart, and PG&E.

“Today, I’m thrilled to welcome @rinkisethi as the new CISO of @twitter. An inspiring and experienced leader, Rinki comes to us via Rubrik, IBM, and Palo Alto Networks. At Twitter, she will lead our growing InfoSec team, protecting our customers and our company to earn trust,” Nick Tornow tweeted.

The position of CISO had been lying vacant for almost close to a year now, since Mike Convertino stepped down from his role in December 2019. The short message platform had also come under severe criticism following the account breach of several global leaders and other verified high-profile accounts. During the attack hackers broke into the backend admin tools and plugged cryptocurrency scams into the high-profile accounts.

Following the attack, Twitter had locked and suspended all operations of the affected accounts to investigate the cause and extent of the breach. It also wanted to make sure whether any additional user information was compromised and if any backdoors were created for future account takeovers.

Among the affected verified account holders were Jeff Bezos (Amazon CEO), Bill Gates (Microsoft Co-Founder), Elon Musk (Tesla and SpaceX CEO), Warren Buffet (Berkshire Hathaway CEO), Barack Obama (The Former U.S. President), Michael Bloomberg (The Former New York Mayor), Joe Biden (presumptive Democratic nominee for President), Benjamin Netanyahu (Israeli Prime Minister) Kanye West (Rapper) and wife Kim Kardashian (T.V. Celebrity), Wiz Khalifa (Rapper) Apple (Corporate Account), Uber (Corporate Account) and many more.

But the attacks did not stop there. Last month, Indian Prime Minister Narendra Modi’s Twitter account was also hacked. Crypto scammers hacked the verified Twitter account of the Indian PM’s official website and sent out a series of tweets asking its followers to donate towards the PM National Relief fund in cryptocurrency.

U.K. Conferred With 2020 European CYBERSEC Award

2020 European CYBERSEC Award

Cyberattacks across several verticals in Europe have seen a sharp surge in recent times. A report released by Hiscox highlighted that 61% of the firms in Europe and the U.S. alone experienced a cyber incident in the past year with financial losses accounting to nearly $7,20,000. However, amidst all the negative numbers, the mean cost of all cyber incidents in the U.K. was the second-lowest at less than $2,43,000. The U.K. was also recognized as the most eligible to measure the business impact of a cyber incident. Owing to the cyber readiness and response measures and many other such parameters of judging, the U.K. has now been recognized as a driving force in the fight against adversarial internet and has been awarded the “2020 European CYBERSEC Award.”

U.K. – The Cyber Power

The U.K. is now being considered as a cyber power because of its proactive and innovative approach in building its cyber policies and capabilities. It has not just changed the domestic cyber space but also has an impact on the international cyber space. While giving away the award to the U.K., Izabela Albrycht, President of the Kosciuszko Institute said, “U.K. has collaborated with like-minded countries domestically and internationally. This is exactly the way towards fighting against adversarial internet space.”

The country’s approach to cybersecurity has been remarkable since the last decade. From 2011 to 2016, the U.K. government has funded an £860 million (approximately US$1,112.10 Mn) National Cyber Security Programme that helped in formulating the National Cyber Security Centre (NCSC) in 2016. The main aim of the NCSC was to improve the cybersecurity in the public sector, which it successfully did in the coming years through a range of measures that curbed cybercrime.

Not a Smooth Ride

The road to this point had a few bumps, with a successful WannaCry ransomware attack on National Health Service in 2018 being one of the biggest ones. Learning from their own failures, the British government built a great situational awareness to take appropriate countermeasures. Fortunately, the U.K. believes in sharing. It has time and again shared its expertise and resources with its allies and other friendly countries, recognizing that cybersecurity is a common goal.

The Future Roadmap

Like other weapons and strategies, having enough power to respond is what effectively keeps adversaries away from attacking. This is exactly what the U.K. is now focusing on — developing offensive cyber capabilities and the much-awaited launch of the National Cyber Force. The NCF, which is said to be launched by the end of 2020, will be jointly run by the military and the Government Communications Headquarters (GCH). The U.K. government believes in sharing and collaboration, thus, it has declared that it is open to sharing its offensive capabilities with the NATO allies as and when needed.

Matt Warman, U.K.’s Minister of Digital Infrastructure, who received the prize on behalf of the government, shared the success of the NCSC, among which it is dealing with over 2,000 sophisticated cyberattacks.

Warman said, “I agree that the part of the U.K.’s cybersecurity success is due to the international collaboration with like-minded countries, but introducing a true partnership between government, industry, and the academia environment has been most vital. The awareness of U.K. towards current trends, threats, and capabilities of cybercriminals, be it 5G security or building a cybersecurity ecosystem in private and public sectors, or leading in the regulatory space, has truly been exceptional.”

The European CYBERSEC Award was handed over to the U.K. on day two of the CYBERSEC Global 2020 conference. With over 40 keynotes and panel discussions on varied topics on pressing cybersecurity issues for nation-states, businesses, defense, and future visions, this conference has been more than fruitful in all sense.

4.83 Mn DDoS Attacks Reported Globally in H1 2020

DDoS Attacks

Organizations globally encountered over 4.83 million distributed denial-of-service (DDoS) attacks in the first half of 2020. According to a research from Netsount, cybercriminals attacked health care, e-commerce, and educational service providers with short, complex, and high-throughput attacks designed to target their services. The research “2020 Threat Intelligence Report” stated that more than 929,000 DDoS attacks occurred in May 2020, which is the largest number of attacks reported in a month.

The research also found a 25% surge during the height of pandemic lockdown. “Cybercriminals pounced on pandemic-driven vulnerabilities, launching an unprecedented number of shorter, faster, more complex attacks designed to increase ROI. Attacks were also more complex, as 15-plus vector attacks spiked 2,851 percent in popularity since 2017. Three years ago, such attacks were considered outliers. Now, they are one of the most potent weapons in the DDoS attack arsenal. Meanwhile, we saw single-vector attacks drop 43 percent year over year,” the report said.

Key Findings:

  • A total of 4.83 DDoS attacks were discovered in H1 2020.
  • A 25% growth in DDoS attack frequency was observed during the pandemic lockdown.
  • 15+ vector attacks have spiked 126% Y-o-Y and 2,851% since 2017.
  • A 43% decline was reported in single-vector DDoS attacks in H1 2020.
  • Malicious attempts included Mirai variants, brute-force username/password combinations, and exploitation attempts.

“The DDoS attacks consumed enormous amounts of bandwidth and throughput—and both service providers and enterprises must absorb that traffic as a cost of doing business in the digital economy. But then, cybersecurity math has always favored the bad guys. The latest example is the trend towards fast but complex multi vector attacks. Such scenarios only highlight the vital role of advanced and automated DDoS technology,” the report added.

Weaponizing Documents for DDoS Attacks

Many industry experts stressed that DDoS attacks have evolved into weaponized instruments used to disseminate ransomware, as well as launch disruptive attacks against their targets. Attack vectors targeted for weaponization include mobile devices, documents, browsers, with the current favorite being IoT devices.

The researchers from Sophos discovered a weaponized document serving the dual purpose of delivering ransomware to the system, as well as exploiting it for potential DDoS attacks. The weaponized document was sent as a spear phishing email which upon opening launched Microsoft Word and initiated embedded macros, which enabled elevated privileges for the malicious document to execute an encoded VBscript.

Digital Revolution! 90% of Enterprises Increase their Digital Transformation Budgets

Cybersecurity Investment Estimated to Grow up to 6% in 2020

A survey from the Tata Consultancy Services (TCS), a provider of IT services globally, revealed that around 90% of organizations are increasing their digital transformation budgets amid the pandemic. The survey “Digital Readiness and COVID-19: Assessing the Impact” found six digital capabilities as critical factors for organizations to withstand the effects of the outbreak, these include:

  • End-to-end digital customer experience (CX)
  • AI-based analytics to continually improve the CX
  • Core enterprise systems in the cloud
  • Highly automated core business processes
  • Digital sensors tracking products
  • Key partnerships in digital ecosystems

Key Findings:

  • Among shifts in technology spends due to the pandemic, companies reported maximum increases on collaborative technologies (65%), cybersecurity (56%), cloud-native technologies (51%) and advanced analytics (39%).
  • Higher levels of automation in core business processes is another priority area, already deployed at 23% of companies and under development at 44% of companies.
  • Prior to the pandemic, the average organization surveyed had only 9% of its workforce working mostly from home. That percentage has increased seven-fold and is expected to remain elevated through 2025, when the average company projects 40% of its employees will work largely from home.
  • While 68% of companies have seen revenue declines amid COVID-19, 90% of organizations have either maintained or increased their digital transformation budget.
  • Business initiatives around an end-to-end CX have seen most traction, already deployed at 25% of companies and under development at 44%. Similarly, the use of analytics and AI to improve CX is deployed at 24% and under development at 39% of companies.

The survey findings are based on the responses from 300 senior business leaders from enterprises across North America, Europe, and Asia.

“Before the pandemic, companies’ digital capabilities were rapidly becoming central to their success and business transformation initiatives. The study revealed how several enterprises were not as far along in developing a digital backbone as they hoped. Companies that had embraced digital transformation more whole-heartedly performed better during the pandemic and expect a faster rebound, whereas others are now focused on making necessary investments and racing to catch up,” said Rajashree R, Chief Marketing Officer at TCS.

Why Data Security is Important in Human Resources

Building Pro-Active Security Hygiene Helps in Preventing Ransomware Attacks: Microsoft

Data security began when man realized he needed to protect his information and pass it down from generation to generation. One of the best ways man kept his information safe was by storing it in caves or walls.

By Pablo Morales, Chief Information Security Officer at Framework Science

In the Middle Ages, information was passed on through the church and the libraries. It was stored in archives or secret vaults. Man wanted to record his story in paintings, books, and even poetry and riddles (remember Nostradamus?). And eventually, security systems have been generated to maintain and secure that information.

Digital data security began in the 70s with the appearance of the first virus called Creeper from a digital point of view. The virus sent a message saying, “I’m the creeper, catch me if you can!” Creeper was propagated through ARPANET, the progenitor of what we know today as the Internet, and thus cybersecurity was born.

In the 80s, data security assumed more importance when the first computer enthusiast clubs were established. Hobbyists created viruses just for experimentation or to show off their skills, with no intention of causing severe damage.

Information Security

It is essential to understand that information is integrated and protected under security measures to keep the organization’s data linked to its shareholders, managers, workers, and clients — safe.

Information security is made up of a set of methodologies and processes aimed at controlling the data that is handled within an organization, to ensure that they do not leave the system without authorization. This is established by a group of professionals and an internal committee, who protect the data in the system, and ensure that only authorized personnel have access to it.

Information security must respond to three essential qualities:

  • The first must be “critical” because the organization must carry out its actions without assuming too many risks.
  • The second must be “valuable” since the data that is handled is essential for the organization’s development.
  • The third must be “sensitive” since only authorized people can access it.

Security Objectives

  • Protect all the organization’s data.
  • Reduce the risks of handling (input and output) of member data and resources of members of the organization.
  • It is necessary to understand that the information is found in different ways:
    • In digital form, in the cloud, or on physical servers or files on electronic media.
    • In physical form, written or printed on paper.
  • It is also necessary to understand that the information is stored, processed, or transmitted in different ways:
    • In written electronic form or in videos.
    • Verbally
    • In written or printed messages.

From a digital point of view, computer security is aimed at protecting systems and equipment for information processing, while data security is aimed at the protection of automatic information processes.

Data security is supported by methodologies, standards, policies, organizational structures, and technologies, among other instruments.

Additionally, apart from protecting the data under any circumstance, the security of information must continue to give life support and continuity to the organization.

Data security requires good administration to manage your process, that is, good planning, organization, management, and, of course, strict controls that protect your data against any circumstance and risks that threaten its confidentiality.

Data Security in Human Resources

Human Resources are an organization’s most valuable asset. Stability and growth depend on human capital, which is why an excellent administration of these resources is required. HR helps maintain harmony and motivation in all personnel and all hierarchical levels to achieve objectives.

A human resources information system must record, store, process, and provide information on the organizational structure in terms of its administrative division, hierarchical levels, and functions. A human resources information system must record, store, process, and provide information on the description of the positions that make up the organization in terms of their objectives and goals; functions, activities, and requirements.

A human resources information system must record, store, process, and give information on human resources’ behavior.

A human resources information system must record, store, process, and provide managers with information for decision-making. This is additional to being the base and pillar for good administration within the organization.

Many organizations do not carry out staff evaluations to know the degree of their commitment, tolerance, and frustration — or if the staff is displeased with the organization, managers, or their colleagues. Timely evaluation helps the security department and human resources to identify a breach, possibly caused by a disgruntled employee. And this alertness is far more critical than having highly secure systems, hardware, and security personnel.

Human Resources should know technology to help the security department identify any risk while sourcing, hiring, training, and during the time the employee is committed to the organization. Training for recruiters is a must because they will be the first ones to get information from the candidate.

Reflections on Data Security in Human Resources

Managers must carry out an inventory of the organization’s information to know the processes and the various departments through which this information passes.

This information in your reception or delivery flow will allow us to identify what part of the process is carried out in each position. Therefore, we can identify the type of information handled by a specific profile.

It is also essential for managers to be familiar with the profiles of various personnel in the organization. An organization’s success depends on fair recruitment and selection of the personnel they will hire. Above all, it ensures the quality and control of the information.

It is necessary for managers to generate an inventory, methodology, and policies that allow them to prioritize the information that is handled within the organization and identify the flows through which it runs and the organizational stations where it is processed.

Few organizations attach importance to information security and pay little attention to the recruitment and selection of personnel to fill the available vacancy. One must apply psychometric, socio-economic trust, and background tests.

It is a challenge for the security department to know employees’ backgrounds in advance since this department is not involved in the hiring process.

Likewise, in public or private organizations, the people who oversee security and the general personnel are not well paid. This can cause a security breach when someone tries to obtain information.

Amid COVID-19, this has been a challenge for companies, governments, and those who generate information, especially when hiring people has to be done remotely. It is a challenge to established if candidates are capable and committed.

In the end, one of the most critical departments in any company or government should be Human Resources, so that we can prevent a security breach; however, just a few companies and governments understand this.

To conclude, it is worth highlighting and reflecting on a few more points about information security:

  • Network – Involves monitoring the network to detect any suspicious packets or movements.
  • Email – Apart from preventing spam and viruses, it is necessary to keep strict control of what leaves the company through analysis and constant changes of passwords, personnel training, and encryption.
  • Physical Security – Involves keeping the premises secure through different layers of security such as cameras, controlled access, security guards, fire prevention, etc.
  • Encryption – Involves encrypting information from the moment it is generated until it is delivered to the recipient.
  • Mobile Data Security – Refers to keeping all company mobile devices safe by following all the established protocols.

There must be a company commitment to apply all security protocols and hardware, but this commitment has to come from the employee, and this is the key to data security. If there is no commitment from the employee, all the processes and hardware that we have won’t prevent a security breach.

About the Author

Pablo MoralesPablo Morales is the Chief Information Security Officer at Framework Science in Tijuana Baja California. He has over 20 years of experience in the IT industry. He came from being a developer to identifying and understanding possible company risks and providing feasible solutions.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Partial Authentication Bypass Vulnerabilities Affect Multiple Wireless Router Chipsets

MikroTik Devices, ASUS Routers

A security advisory from Synopsys revealed multiple vulnerabilities in the chipsets of wireless routers manufactured by Qualcomm, MediaTek, and Realtek. Referred to as CVE-2019-18989, CVE-2019-18990, and CVE-2019-18991, the partial authentication bypass vulnerabilities could allow an attacker to exploit the authentication process by injecting packets into a WPA2-protected network without a password.

“An attacker can arbitrarily send unencrypted packets and receive encrypted responses. These unencrypted packets are sent from a spoofed MAC address. The vulnerable access point does not drop the plain-text packets and routes them to the network as though they were valid. Response is also received back, but that is encrypted. The only requirement is that there is another properly authenticated client connected to WPA2 network,” Synopsys said.

The Synopsys cybersecurity research center also listed vulnerable chipsets in different wireless routers, which include:

Mediatek:

  • Chipset: MT7620N
  • Devices tested: D-Link DWR-116 V1.06(EU)

Qualcomm (Atheros):

  • Chipset: AR9132
  • Devices tested: Zyxel NBG460N V3.60(AMX.8)
  • Chipset: AR9283
  • Devices tested: Buffalo WHR-G300N V2 V1.85 (R1.18/B1.03)
  • Chipset: AR9285
  • Devices tested: Netgear WNR1000 V.1.0.0.12NA

Realtek:

  • Chipset: RTL8812AR
  • Devices tested: D-Link DIR-850L V1.21WW
  • Chipset: RTL8196D
  • Chipset: RTL8881AN
  • Devices tested: D-Link DIR-809 Rev A3 V1.09 Rev A2
  • Chipset: RTL8192ER
  • Devices tested: D-Link DIR-605L H/W: B2 V2.10

Synopsys stated that it received responses from all the manufacturers after the vulnerability disclosure. While MediaTek and Realtek said the patches will be made available upon request, Qualcomm stated that all the chipsets have reached end-of-life and have been discontinued.

Hackers Exploit Routers for Botnets

Cybersecurity solutions provider Trend Micro warned users about a new wave of attacks targeting home routers. In its research report “Worm War: The Botnet Battle for IoT Territory,” Trend Micro revealed that cybercriminals are using home routers to build botnets. The research found a surge in cyberattacks by exploiting routers, particularly in Q4 2019. Attackers made brute force log-in attempts against routers by using automated software to try common password combinations. The number of attacks increased from around 23 million in September to nearly 249 million attacks in December 2019. In March 2020, around 194 million brute force login attacks were reported.

Also Read: How to Secure Your Router Network