Home Blog Page 164

Facebook Takes Down Hundreds of Fake Accounts Under Coordinated Inauthentic Behavior

Facebook Takes Down Hundreds of Fake Accounts Under Coordinated Inauthentic Behavior

Facebook has taken down two separate networks that originated from China and the Philippines for violating its Coordinated Inauthentic Behavior (CIB) policy. In an official release, the social networking giant stated that it has removed 155 fake accounts, 11 pages, 9 groups, and 6 Instagram accounts for breaching its guidelines against foreign or government interference. Facebook stated that state-sponsored actors from China are using these accounts to influence public opinion across the Philippines, the U.S., and Southeast Asia.

According to Facebook, the actors behind this network posted global news and current events in Chinese, Filipino, and English languages. They posted about various events including activities in Hong Kong, Beijing’s interests in the South China Sea, content supportive of President Rodrigo Duterte and Sarah Duterte’s potential run in the 2022 Presidential election, issues relevant to the overseas Filipino workers, and content both in support of and against the U.S. presidential candidates Pete Buttigieg, Joe Biden, and Donald Trump.

Facebook’s internal investigation found these networks linked to individuals in the Fujian province of China. The network has over 133,000 accounts with around 61,000 followers. The threat actors spent over $60 for advertisements on Facebook, which are paid in Chinese yuan.

“We identified several clusters of connected activity that relied on fake accounts to pose as locals in countries they targeted, post in Groups, amplify their own content, manage Pages, like and comment on other people’s posts particularly about naval activity in the South China Sea, including U.S. Navy ships. This campaign took operational security steps to conceal their identity and location including, through the use of VPNs. Some of this network’s pages were previously removed for violating our inauthentic behavior and spam policies,” said Nathaniel Gleicher, Facebook’s head of security policy.

The Russian Connection

In another notification, Facebook stated that it also removed three separate networks that have 214 Facebook users, 35 pages, 18 groups, and 34 Instagram accounts for violating its CIB policy.  It is found that the networks are originated from Russia targeting Syria, Ukraine, Turkey, Japan, Armenia, Georgia, Belarus, the U.K., and the U.S.

“The people behind this campaign posted in many languages including English, Ukrainian, Russian, and Arabic as they tailored their activity to each audience. They frequently posted about news and current events, including the Syrian civil war, Turkish domestic politics, geopolitical issues in the Asia-Pacific region, NATO, and the war in Ukraine,” Gleicher stated.

Cyberattacks on ICS See a Downward Trend in H1 2020

Superior Plus, Saudi Aramco data breach

A report from IT security solutions provider, Kaspersky, suggests that industrial control systems (ICS) sectors globally have seen a gradual decline in the number of cyberattacks targeted towards them. However, experts observed that the limited number of attacks have now become more complex, targeted, and exclusive in nature. Let’s have a look at the key highlights of the report.

 Key Highlights 

  • In H1 2020, the percentage of malicious attempts blocked on ICS computers has decreased by 6.6% and has come down to 32.6% as compared to H2 2019.
  • The number was highest in Algeria (58.1%), and lowest in Switzerland (12.7%).
  • Despite the overall percentages of attacked computers seeing a downward trend, researchers found growth in the Oil & Gas sector by 1.6 p.p. (percentage points) to 37.8% and by 1.9 p.p. to 39.9 % for computers used in building automation systems.
  • Cyberattacks on ICS are seeing increased volumes of backdoors, spyware, Win32 exploits and malware families specifically built on the .Net platform.
  • Region wise, Asia and Africa ranked least secured based on the percentage of ICS computers attacked, whereas, southern and eastern regions of Europe were the least secured in the Transatlantic region.

Cyberattacks on ICS Sector

According to the research, 37.8% of computers associated with the ICS sectors suffered a cyberattack in the H1 of 2020. This increased the tally by a mere 2% in comparison to H2 2019. However, this increase is purely associated with the growing number of cyberattacks on ICS sectors of oil and gas along with systems in the building automation space, which again saw a 2% increase and a total of 39.9% of threats in the first half.

cyberattacks on ICS
Image Credit: Kaspersky Report

Researchers are concerned with the growing variety of new variants of standalone malware being used in these cyberattacks. They have particularly seen an uptrend of different computer worms written in script languages such as Python and PowerShell, for disrupting ICS operations. The biggest spike in these detections came between the end of March and mid-June 2020.

The report said, “Building-automation systems often belong to contractor organizations, and even when these systems have access to the client’s corporate network, they are not always controlled by the corporate information security team. Given that the decrease in mass attacks is offset by an increase in the number and complexity of targeted attacks, where we see active utilization of various lateral movement tools, building automation systems might turn out to be even less secure than corporate systems within the same network.”

A Pinch of Salt

Although the decline in numbers is encouraging, there is a certain uptick in the complexity and exclusivity of the cyberattacks targeted across various ICS verticals. Overall, ransomware contributed towards only 0.63% of the total cyberattacks on the ICS computers. However, with increased complexity like the one observed in EKANS ransomware attack on several ICS systems in the manufacturing sector, is more disruptive than ever.

Apart from this, Kaspersky researchers also noted malicious activities of several APT groups that are actively targeting the ICS and SCADA systems. The impact of COVID-19 has exposed the threat landscape to remote ICS connectivity. Between February and May 2020, there was a clear growth in the percentage of ICS computers on which attempts to crack RDP passwords through brute force attacks were detected.

cyberattacks on ICS
Image Credit: Kaspersky Report

The global outbreak of the pandemic has led to a shift in the threat landscape, and it is a wake-up call for corporates and CISOs to identify, monitor, and protect data in use, data in motion, and data at rest.

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Operations at multiple banks and telecommunication service providers in Hungary were disrupted due to a distributed-denial-of-service (DDoS) attack launched from servers located in Russia, Vietnam, and China. According to the source, the incident affected the services of Hungarian OTP bank and telecommunications provider Magyar Telekom in certain parts of the capital, Budapest. In a DDoS attack, hackers try to make a targeted system or service unavailable to its users by flooding with unwanted incoming traffic from different sources.

Describing the incident as one of the biggest attacks in Hungary, Magyar Telekom stated that the frequency of data traffic in the current attack was 10 times higher than the amount normally seen in DDoS attacks.

“Russian, Chinese and Vietnamese hackers tried to launch a DDoS attack against Hungarian financial institutions, but they tried to overwhelm the networks of Magyar Telekom as well,” Magyar Telekom said.

DDoS Scare for Banks

DDoS attacks on financial institutions have been on rise. Recently, Australian banking and financial institutions received extortion emails threatening them of possible DDoS attacks against them. The extortioners demanded a ransom that needs to be paid in the form of Monero (XMR) cryptocurrency. The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) is aware of this extortion campaign and issued threat advice to all Australian organizations. The Silence Hacking Crew claimed the responsibility of this threat campaign, however, ACSC was not able to confirm these claims until going to print.

Weaponizing Documents for DDoS Attacks

Many industry experts stressed that DDoS attacks have evolved into weaponized instruments used to disseminate ransomware, as well as launch disruptive attacks against their targets. Attack vectors targeted for weaponization include mobile devices, documents, browsers, with the current favorite being IoT devices. The researchers from Sophos discovered a weaponized document serving the dual purpose of delivering ransomware to the system, as well as exploiting it for potential DDoS attacks. The weaponized document was sent as a spear phishing email which upon opening launched Microsoft Word and initiated embedded macros, which enabled elevated privileges for the malicious document to execute an encoded VBscript.

Remote Workforce: New Normal or Digital Normal? [INFOGRAPHIC]

impacts of coronavirus on businesses, covid-19, work from home, working from home, remote working

2020 has brought many new changes to the world, including new ways of working under social distancing. Working remotely has been increasingly available to employees in recent decades, but only this year has it become the only way of survival for many. Remote workforce has contributed largely to making businesses resilient since the onset of the Pandemic. But what are the exact impacts of this new normal called the digital normal? Let’s dive deep into the key insights and tricks of the trade through the following infographic that will help businesses sharpen their adaptability skills in this digital normal.

Click here to view the infographic on a full screen!

About the Author

Computers In The City is a known London-based IT support company that has developed this infographic highlighting the impacts and benefits of the new normal.

Disclaimer

The views, statistics, and tips provided in the infographic do not reflect the views of CISO MAG and thus we do not assume any responsibility or liability for the same.

Gaming Industry Suffered 10 Billion Cyberattacks in Two Years

battle of galaxy game

Even after the improved security measures, cyberattacks have become common in the online gaming industry. Attackers often target online video games and gamers by compromising their accounts and launching attacks. A research from Akamai Technologies revealed that the gaming industry suffered high volumes of attacks between 2018 and 2020. The research “State of the Internet/Security report, Gaming: You Can’t Solo Security” highlighted that the COVID-19 lockdown resulted in the increase of attack traffic through credential stuffing and phishing attacks.

“Gamers are highly targeted because they have several qualities that criminals look for. They are engaged and active in social communities. For the most part, they have disposable income, and they tend to spend it on their gaming accounts and gaming experiences. When these factors are combined, criminals see the gaming industry as a target-rich environment,” the research stated.

Multiple Attack Vectors

Akamai observed more than 10 billion credential stuffing attacks, 3,000 unique DDoS attacks, and 152 million web application attacks from July 2018 to June 2020 on the gaming industry. Cybercriminals generally launch these kind of attacks by using a set of usernames and password combinations obtained from several darknet websites. In addition, attackers also used phishing techniques to trick the users into revealing their login credentials.

“While video games served as a major outlet for entertainment and social interaction during the COVID-19-driven lockdowns earlier in the year, criminals also took advantage of the pandemic. A notable spike in credential stuffing activity occurred as isolation protocols were instituted around the world. Much of the traffic was the result of criminals testing credentials from old data breaches in attempts to compromise new accounts created using existing username and password combinations,” the research added.

Gamers Turning into Hackers

Another research revealed that most young gamers are increasingly turning into hackers to commit cybercrime. The research found that 82% of teens and young adults recruited by online criminals had developed their cybercrime skills through video gaming. The U.K.’s National Crime Agency (NCA) held a forum and published a special report about the problem. The agency report looks at ways to identify those at risk of hacking, how to intervene before they go too far, and then inspire them to pursue a career in IT security.

Only 44% of Health Care Providers Meet National Standards on Cybersecurity

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

A research from information security provider CynergisTek revealed that only 44% of hospitals and health care providers are following the security protocols outlined by the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF). The research “Moving Forward: Setting the Direction” highlighted that health care supply chain security is one of the lowest ranked areas for NIST CSF conformance.

According to the research, the main factors affecting health care security include poor security planning, lack of organizational focus, inadequate reporting structures and funding, confusion around priorities, lack of necessary staff, and no clear planning. In addition, large health care organizations with high security budgets did not perform well in maintaining cybersecurity posture, rather performed worse than smaller organizations that invested less on security.

“Health care is still behind the curve on security. While health care’s focus on information security has increased over the last 15 years, investment is still lagging. In the age of remote working and an attack surface that has exponentially grown, simply maintaining a security status quo will not cut it. The good news is that issues emerging in our assessments are largely addressable. The bad news is that it is going to require investment in an industry still struggling with financial losses from COVID-19,” said David Finn, EVP of Strategic Innovation at CynergisTek.

“Health care organizations continue to enhance and improve their programs year-over-year. The problem is they are not investing fast enough relative to an innovative and well-resourced adversary. Organizations — that have invested in their programs and had regular risk assessments, devised a plan, addressed prioritized issues stemming from the assessments and leveraged proven strategies like hiring the right staff and evidence-based tools — have seen significant improvements to their NIST CSF conformance scores,” said Caleb Barlow, president, and CEO of CynergisTek.

Health Care Devices at Risk

Most health care organizations in the U.S. are running their medical devices on outdated operating systems, leaving them vulnerable to cyberattacks. According to a research from Atlas VPN, 83% of health care providers in the U.S. are running on outdated software.  Out of the 1.2 million IoT devices used in thousands of health care organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020.

Hackers Compromised a Federal Agency: CISA

Regina police station hacking, hacking, email and passwords hacked

The Cybersecurity and Infrastructure Security Agency (CISA), the cybersecurity wing of the U.S. Department of Homeland Security (DHS) has notified  about a cybersecurity incident that targeted an unnamed federal agency. According to CISA, hackers implanted a malware “including multi-stage malware that evaded the affected agency’s anti-malware protection—and gained persistent access through two reverse Socket Secure (SOCKS) proxies that exploited weaknesses in the agency’s firewall.”

Describing the activity by the threat actors, CISA stated that the actor had valid credentials for several users’ Microsoft Office 365 accounts as well as domain administrator accounts. The actors leveraged these accounts and browsed on SharePoint site using an IP address 91.219.236[.]166 and even downloaded a file (Data from Information Repositories: SharePoint [T1213.002]). The hackers also connected multiple times by Transmission Control Protocol (TCP) from IP address 185.86.151[.]223 to the victim organization’s virtual private network (VPN) server.

“After initial access, the threat actor performed Discovery [TA0007] by logging into an agency O365 email account from 91.219.236[.]166 and viewing and downloading help desk email attachments with ‘Intranet access’ and ‘VPN passwords’ in the subject line, despite already having privileged access (Email Collection [T1114], Unsecured Credentials: Credentials In Files [T1552.001]). (Note: these emails did not contain any passwords.) The actor logged into the same email account via Remote Desktop Protocol (RDP) from IP address 207.220.1[.]3 (External Remote Services [T1133]). The actor enumerated the Active Directory and Group Policy key and changed a registry key for the Group Policy (Account Manipulation [T1098]). Immediately afterward, the threat actor used common Microsoft Windows command line processes—conhost, ipconfig, net, query, netstat, ping, and whoami, plink.exe—to enumerate the compromised system and network (Command and Scripting Interpreter [T1059], System Network Configuration Discovery [T1016]),” CISA stated.

The attackers, after accessing the local Active Directory, modified the settings and to have easier access into the federal body’s network, also installed custom malware. “The mounted file share allowed the actor to freely move during its operations while leaving fewer artifacts for forensic analysis,” CISA added.

CISA has also stated that the hackers were able to overcome the agency’s anti-malware protection as well. It is still unclear how the hackers accessed valid credentials, however, there have been speculations that leaks of credentials could have been the result of vulnerability exploits which have been rampant across government networks for a while now.

CISA has also recommended to deploy an enterprise firewall and even block unused ports to the affected organization. Additionally, it also recommended the following best practices like:

  • Implement multi-factor authentication, especially for privileged accounts.
  • Use separate administrative accounts on separate administration workstations.
  • Implement the principle of least privilege on data access.
  • Secure RDP and other remote access solutions using multifactor authentication and “jump boxes” for access.
  • Deploy and maintain endpoint defense tools on all endpoints.
  • Keep software up to date.

 

 

Beyond Limits Raises $133M Series C Investment to Drive Global Expansion of AI Technology

Funding

Beyond Limits,  an industrial and enterprise-grade AI technology company built for the most demanding sectors, including energy, utilities and healthcare, today announced a Series C funding round with $113 million closed and another approximately $20 million committed. This round is led by Group 42, an AI and cloud computing company, and bp ventures, an existing two-time investor and customer of the company.

Today we are seeing unprecedented, world-wide demand for systems that go beyond the limitations of conventional AI. Our cognitive software has the ability to understand situations and place problems in real-world contexts as well as to learn over time.

 

– AJ Abdallat, CEO and Founder of Beyond Limits

Beyond Limits’ Cognitive AI applies human-like reasoning to solve problems, much like how humans form conclusions using inference and logic. This unique approach combines encoded human knowledge with available data sources, allowing systems to adapt and continue to operate in situations where data may be in short supply or missing altogether. As a result, Beyond Limits’ customers are able to elevate operational insights, improve operating conditions, enhance performance at every level, and ultimately increase profits as a result.

bp ventures was established to identify and invest in high-potential, game-changing technology companies that can help us reimagine our global energy system. With this additional investment, we believe that Beyond Limits’ Cognitive AI could help create a more intelligent and sustainable future for the energy sector and indeed across industry as a whole.

 

– Morag Watson, Senior Vice President, Digital Science and Engineering at bp

Martin Edelman, General Counsel, Group 42, said, “We believe Beyond Limits’ unique AI will bring new levels of efficiency to high-impact sectors and help drive future economic growth.”

The $133M funding will be used to expand Beyond Limits’ business both in the U.S. and abroad, including the launch of Beyond Limits Asia, with regional headquarters in Singapore and operations in Hong Kong, Taipei and Tokyo and further expansion across Europe, the Middle East, Africa and Asia. Beyond Limits Asia will drive investments for joint ventures and strategic partnerships in Asia to expand Beyond Limits’ AI in new verticals including financial services, led by the Hong Kong office, and advanced manufacturing, led the Taiwan office. The funding will also accelerate Beyond Limits’ Cognitive AI application development and SaaS product portfolio and fuel the Beyond Labs R&D program.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article. It cannot guarantee the performance of the mentioned products and technologies.

 

 

Episode #2: Digitization and Cybersecurity in Fourth Industrial Revolution

Security in the Manufacturing domain has always been a concern. When product information, designs, blueprints, and research/test information is digitalized, the security of this data becomes vital to protecting the intellectual property of an organization.

As we embark on the fourth industrial revolution, we see the fusion of OT (operational technology) and IT (information technology). The fusion of the physical space with digital. This also raises security concerns, especially when IoT sensors are used to monitor manufacturing processes and collect data. This data is analyzed using AI and ML algorithms in the cloud.

In recent years, there have been increased cyberattacks on industrial facilities with the intent of damaging equipment, disrupting manufacturing processes, and stealing intellectual property (data). The Stuxnet attack is a well- documented example.

Toshiba Corporation provides solutions in the fields of energy, social infrastructure, electronic devices, and digital products by combining this expertise with digital technology. Its 2020 Cyber security report states the paramount priority for its business operations is to deliver safety and security to everyone.

Toshiba also aims to support people’s lives through cyber-physical system (CPS) technology. CPS analyzes huge amounts of data collected from physical space in cyberspace in order to generate valuable intelligence and feeds it back to physical space.

Takashi Amano, General Manager, Cyber Security Center, Toshiba Corporation talks about the limitations of conventional corporate security systems in the manufacturing domain, and the steps his company has taken to protect intellectual property. He feels there is a need to rebuild the infrastructure in line with the concept of the Zero Trust Network. And he believes that visualization of devices, networks, applications, cloud services, and human behavior is important

Amano is also Technology Executive and CISO, Toshiba Digital Solutions Corporation.

In this episode, he is joined by Kumar Ritesh, Founder and CEO, CYFIRMA.

The edited transcript of Takashi Amano’s responses.

What are the limitations of conventional corporate security systems with regards to protecting intellectual property (IP) related to products and manufacturing (blueprints, product designs, prototypes)? What steps has Toshiba taken to protect such intellectual property?

Takashi Amano: The conventional corporate security systems have been mainly based on the boundary defense and some access control. The idea was to configure the internal network as a closed network with minimal connections to the outside. Access rights to the information like IPs were controlled and intellectual property was protected by narrowing down who could access it. IP management in the manufacturing industry is very complex. The manufacturing industry has various functions, for example, design, manufacturing, quality, maintenance and operation, each department has its own IP. In addition, traditionally, factory manufacturing systems are often managed individually on the network.

On the digital transformation era, regarding the limitations to protect IPs in the manufacturing domain, the meaning of the boundary itself has become gray as the use of the cloud in development infrastructure, business system infrastructure, and the platform for the open innovation efforts with partners. In fact, the conventional corporate security system makes accurate information management difficult.

As the limits of boundary defense are becoming apparent, I feel that there is a need to rebuild the infrastructure in line with the concept of the Zero Trust Network. However, it is difficult to move to such an environment in the short term, and we believe that strengthening the monitoring of the current environment is a priority in the short term.

Visualization is the most important short-term solution. This is because there are more and more unknown attacks these days, not known ones. We believe that visualization of devices, networks, applications, cloud services, and human behavior is important. Examples are EDR for devices and CASB for cloud services.

I think we need to be prepared for a real-time, proactive response rather than a reactive response. Visualization solutions are important solutions for achieving these goals.

On the other hand, in the long term, we think it is necessary to incorporate the concept of zero trust network into the entire network and protect it. Since there are a wide variety of access types, locations, and devices, we recognize it is important to check the validity of access and to visualize the flow of information properly.”

How do you see the merger of OT and IT today? To what extent is this happening with critical infrastructure such as power grids and nuclear power plants?

Takashi Amano: In the industrial infrastructure field, we believe that we can create a lot of value by uploading operational data of physical space to cyberspace then analyzing it together with experience and knowledge. We aim to provide value through CPS technology (cyber-physical system), and we believe that the fusion (connection) of physical space (OT) and cyberspace (IT) is essential. Even in the critical infrastructure area, it was traditionally said that OT and IT were completely separated, but nowadays, cloud utilization is also advancing in some industries. We believe that this trend will gradually spread to other industrial fields.

What would be the new norms for security in the fourth industrial revolution (industrial IoT) and how would it differ from traditional security?

Takashi Amano: In a nutshell, the value that industrial IoT brings is a world of data-centric value creation. Among them, how to ensure the reliability of data is an important issue, and we think that it is an issue to establish a consistent data protection policy and mechanism from the edge to the cloud, and we also research and develop technologies that will be useful for it. We are also working on it. In addition, since the supply chain will be connected in an IT manner, it is necessary to ensure supply chain security.

The volume and variety of threats is too much to handle by conventional security defenses. Can there be a solution that is more proactive and warns of attacks before the damage is done? A type of “autonomous security”? What exists today?

Takashi Amano: Technically, I think the use of logs, intelligence, and AI is the key. We believe that technology that utilizes horizontal and vertical intelligence to grasp the movements of attackers in advance, and proactively deal with and respond to risks will be required.

Although the automatic incorporation of horizontal intelligence into management systems is progressing, vertical intelligence is typically provided in text and must be handled by humans. Also, for AI, the context understanding becomes a black box, so humans need to supplement it. We are beginning to work on automating the management system for a proactive response.


 

92% U.S. Organizations Suffered Data Breach Due to Vulnerabilities in Vendor Ecosystems

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

A study from cybersecurity solutions provider BlueVoyant revealed that 92% of organizations in the U.S. suffered a security breach last year due to vulnerabilities in their vendor ecosystem. The study, conducted in cooperation with independent research firm Opinion Matters, highlighted the views and experiences of 1,505 CIOs, CISOs and Chief Procurement Officers in organizations located across the U.S., the U.K., Mexico, Switzerland, and Singapore.

Multiple Pain Points

The study found that organizations are experiencing multiple pain points in their third-party cyber risk management programs. The top three pain points include:

  • Working with suppliers to improve their security performance
  • Prioritizing which risks are urgent and which are not
  • Offboarding suppliers with the rigor we onboarded them

Other Findings include:

  • S. organizations have the highest breach frequency among the surveyed countries.
  • 33% say they have no way of knowing if cyber risk emerges in a third-party vendor; this was the second highest out of all five countries surveyed.
  • Just under one third (31%) monitor their entire supply chain, which means that 69% do not have full visibility. However, this was higher than the global average across all respondents which was 23%.
  • The respondents in the U.S. are monitoring and reporting more frequently than most other countries surveyed, 35% report monthly and 9% report weekly, while 27% only re-assess and report their vendor’s cyber risk position either six-monthly or less frequently.
  • The average headcount in internal and external cyber risk management teams is 10.7.
  • 86% say that budget for third-party cyber risk management is increasing, by an average figure of 45%. This was the second highest budget increase out of the five countries surveyed.
  • Over half (54%) of US organizations think the CISO owns cyber risk while 27% say it belongs to the CIO and 10% say Chief Procurement Officers are responsible.

Jim Penrose, Chief Operating Officer for BlueVoyant, said, “There are signs that U.S. respondents are responding to the severity of the situation, but there is still a concerning lack of visibility into third-party suppliers. This is evident in the number of breaches that U.S. respondents are reporting. The research clearly indicated the reasons behind this high breach frequency with visibility being a major problem and one-third admitting that they have no way of knowing if a risk arises in a third-party vendor.”