Home Blog Page 168

Understanding the Cybersecurity Standards Enabling Trusted IIoT Connections

Industrial IoT

Today’s exponential industrial internet of things (IIoT) growth creates a crucial need for robust cybersecurity practices and well-defined standards that provide customers with confidence that their connected devices will operate securely throughout their entire lifecycle.

By Max Wandera, Director, Product Cybersecurity Center of Excellence at Eaton

By 2025, 41.6 billion connected devices will be generating 79.4 zettabytes (ZB) of data that will need to be securely maintained and processed. Analysts forecast that this increase in connected devices and the data they generate will continue to grow exponentially. Our world is also becoming increasingly electrified. The increase in critical data and computing is expected to require four times more electricity over the next decade.

A world with amped-up connectivity and electrical demand needs confidence that electrical power systems are constructed with trusted products. Cybersecurity is a must-have for product development, much like safety and quality. This means strict procedures and cybersecurity protocols need to be integrated at every phase of product development that involves people, processes, and technologies.

Cybersecurity Certifications for Connected Products


For power management devices that are connected, UL created its 2900 Standard for Software Cybersecurity for Network-Connectable Products (UL 2900). These guidelines were the first of their kind and include processes to test devices for security vulnerabilities, software weaknesses, and malware. This standard confirms that the device manufacturer meets the guidelines for:

  • Risk management processes
  • Evaluation and testing for the presence of vulnerabilities, software weaknesses, and malware
  • Requirements for security risk controls in the architecture and product design

UL also provides a Cybersecurity Client Lab Validation program for manufacturers, which certifies testing laboratories with the global capability to test products with intelligence or embedded logic to key aspects of its 2900 standard. By purchasing products tested in these specialized labs, customers can rest easier, knowing their devices are compliant with the industry’s highest cybersecurity requirements before they’re installed in critical systems.

Similarly, the International Electrotechnical Commission (IEC) adopted the 62443 series of standards, which provides a framework to address the cybersecurity of Industrial Control Systems. These standards provide requirements for all the principal roles across the system lifecycle – from product design and development through integration, installation, operation, and support. In 2018, the IEC added 62443-4-2 to improve the security of products.

Just as product cybersecurity certifications are needed to support trusted connectivity, it is equally important to validate that manufacturers apply secure product development principles to product development. This can be confirmed through an accredited Secure Development Lifecycle (SDL) that provides assurance that cybersecurity has been embedded throughout the entire product development process.

What is a Secure Development Lifecycle (SDL)?

SDL was created in response to an increase in virus and malware outbreaks at the turn of the 21st century. This approach to product development places cybersecurity front and center from inception to deployment and lifecycle maintenance. SDL can help manufacturers stay ahead of cybercriminals by managing cybersecurity risks throughout the entire lifecycle of a product or solution.

As an early spearhead of the SDL initiative, Microsoft made its SDL tools, processes, and guidelines widely available. Since then, SDL has been widely adopted across industries including electrical and critical infrastructure. Today, SDL is a proven strategy to address risk proactively with a system-wide defensive approach.

For manufacturers, adopting an SDL approach that has been validated by a third-party is critical to creating trusted environments. It’s the third-party certification that gives customers confidence in the processes and technologies they’re applying, much like safety certifications and standards in the National Electric Code.

Standards for SDL Build Confidence 

Although SDL is not an inherent code or standard, it does dictate how cybersecurity should be integrated into processes for product procurement, design, implementation, and testing teams.

IEC 62443-4-1 lays out guidelines for secure product lifecycle development in the electrical industry. The IEC guideline specifies process requirements for the secure development of products used in industrial automation and control systems. It defines a secure development lifecycle for developing and maintaining secure products. These guidelines can be applied to new or existing processes for developing, maintaining, and retiring hardware, software, or firmware for new or existing products.

Third-party validation for SDL processes is important because it provides customers with confidence and helps reduce risk by confirming that the technologies and processes they’re applying comply with proven industry guidelines. At Eaton, we take SDL very seriously to proactively manage cybersecurity risks in products through a framework involving threat modeling, requirements analysis, implementation, verification, and ongoing maintenance.

Product cybersecurity risks are managed through a Secure Development Lifecycle (SDL) with protocols in place for threat modeling, requirements analysis, implementation, verification, and ongoing maintenance. Image courtesy of Eaton.

How SDL Protects Electrical Systems in the Long Term?


A “defense in depth” mechanism that is effective today may not be effective tomorrow because the vulnerabilities keep evolving. Therefore administrators of industrial control system networks must be ever-alert to changes in cybersecurity landscape and work to prevent any potential vulnerabilities.

The cybersecurity process certifications outlined by IEC provide customers with confidence that manufacturers have instilled the organization-wide approaches needed to ensure robust cybersecurity over the lifecycle of any given product.

Unifying Global Cybersecurity Standards for Connected Products


The security of a network or system is only as strong as its weakest link. Organizations should employ basic cybersecurity hygiene and continuously analyze emerging threats to ensure systems are deployed securely. Additionally, companies should take inventory of everything connected to their networks and employ a zero-trust model.

As more manufacturers and industries build and deploy IIoT devices, the security and safety of systems providing essential operations become more important and more difficult to manage. These complexities are due, in part, to a lack of a global, universally accepted cybersecurity standard and conformance assessment scheme designed to validate connected products.

The economic challenges to safeguarding IIoT ecosystems spawn from the complex manufacturing supply chain and the difficulty of assigning clear liabilities to manufacturers and system integrators for any vulnerabilities introduced. Most products and systems assemblies consist of components from different suppliers. Where should the element of trust begin and end if there is no global conformity assessment scheme to ensure that products and systems are designed to be compliant with the global standards defined by the industry?

There is currently a multitude of different standards and regulations created by various organizations, countries, and regional alliances across the globe. All these standards and regulations address the urgent need to secure our connected world; however, they also create the potential for confusion and the possibility of weak links in critical infrastructure ecosystems. A unified global conformance assessment would address these challenges and more. The time to drive this singular certification is now. We’re working with leaders across the industry to do just that.

About the Author

Max WanderaAs director of the Cybersecurity Center of Excellence at Eaton, Max Wandera provides leadership and oversight for the research, design, development, and implementation of security technologies for products, systems, and software applications. In his position, he is also responsible for Eaton’s Secure Product Development Lifecycle Policy and compliance.

Wandera holds Global Information Assurance Certification (GIAC) Security Leadership and Certified Information Systems Security Professional (CISSP) accreditations. His expertise enables him to act as the voice of Eaton on product cybersecurity matters and lead cross-functional collaboration with corporate officers, industry leaders, and government entities including the Cybersecurity and Infrastructure Security Agency (CISA) to shape the future of cybersecurity and trusted connectivity.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Zhenhua Data Leak: Is China Spying and Collecting Data on Indians?

Infosec-China

Chinese firm Zhenhua Data Information Technology has been accused of collecting data on millions of people worldwide. The Chinese tech company has reported links with the country’s military and intelligence networks, and thus, this action could be an act of espionage, according to Internet 2.0, an Australia-based cybersecurity consultancy that discovered this hidden data trove. This dataset consists of the personal information of nearly 250,000 people worldwide, including 10,000 Indians that consists of prominent personalities like Narendra Modi, Ramnath Kovind, Ratan Tata, Sachin Tendulkar, etc.

 Key Highlights 

  • China-based Zhenhua Data Information Technology Ltd. has been accused of spying, collecting, and storing personal information of nearly 250,000 people worldwide including prominent and critically acclaimed people.
  • The majority of the discovered dataset contains the personal information of 52,000 Americans, 36,000 Australians, 10,000 each of Britain and India, and nearly 800 New Zealand nationals.
  • The Zhenhua data leak was first unearthed by American academic Christopher Balding who shared the findings with an Australian cybersecurity consultancy, Internet 2.0, for recovery and analysis.
  • The Government of India (GoI) has constituted an expert committee under the National Cyber Security Coordinator to study the reports, evaluate their implications, assess any violations of law, and submit its recommendations within 30 days.

Findings of the Zhenhua Data Leak

The researchers at Internet 2.0, received a copy of the database from American academic Christopher Balding. They further retrieved and assessed this database that was left unsecured on the Internet. The database called the Overseas Key Information Database (OKIDB) consisted of useful personal and social media information of known personalities.

As per The Indian Express, “(The information library) includes content not just from news sources, forums, but also from papers, patents, bidding documents, even positions of recruitment.”

China’s Response

The Chinese Foreign Ministry spokesperson Wang Wenbin, however, distanced the government’s involvement with the company in question. He said, “I noticed the company’s response that the report is seriously untrue. The company said clearly that it is a private company, and its clients are research institutions and business groups. Instead of collecting data, it only mobilizes data, which is open and available online.”

Zhenhua’s marketing and recruiting documents depict the company as a patriotic firm with the military as its primary target customer. Thus, experts say that it is hard to believe in the statement given out by the company in this regard.

India Looks into the Damages

Meanwhile, the Ministry of External Affairs (MEA) in India has taken up the discussion of the Zhenhua data leak in the ongoing monsoon session of the parliament. The GoI is highly concerned about foreign entities collecting data of Indian nationals without their consent and made this very clear to the Chinese Ambassador to India by raising a voice against it.

The GoI has formed an expert committee under the National Cyber Security Coordinator to study the reports, evaluate their implications, assess any violations of law, and submit its recommendations within 30 days.

eCrime Activities and Hands-on Keyboard Intrusions Rise in H1 2020

Vulnerabilities in Zimbra

A research report from CrowdStrike Inc., the developer of cloud-delivered endpoint protection solutions, revealed that eCrime activities and other malicious actions of state-sponsored actors have increased during the first half of 2020. The “2020 Threat Hunting Report: Insights from the CrowdStrike OverWatch Team” highlighted the intrusion trends and insights into the current landscape of adversary tactics.

The CrowdStrike OverWatch Team stated that they have observed an upsurge in hands-on-keyboard intrusions in the H1 2020 that has already surpassed the total reported intrusions in 2019. The sudden increase in cyberthreats is primarily due to the continued acceleration of eCrime activities by exploiting public fear through COVID-19-themed social engineering techniques.

Key Highlights

  • Sophisticated eCrime activity continues to outpace state-sponsored activity, an upward trend that OverWatch has witnessed over the past three years, accounting for over 80% of interactive intrusions.
  • However, this does not indicate a reduction in nation-state activity, but rather reflects the extraordinary success threat actors have seen with targeted intrusions using ransomware and Ransomware-as-a-Service (RaaS) models, which have contributed to a proliferation of activity from a wider array of eCrime actors.
  • There was a sharp escalation of activity in the manufacturing sector in the first half of 2020 in terms of both the quantity and sophistication of intrusions from both eCriminals and nation states, making it the second most targeted vertical observed by OverWatch.
  • Health care, food, and beverage industries also saw increased targeting, suggesting that adversaries have adjusted their targets to the shifting economic conditions resulting from the pandemic, focusing on industries made vulnerable by complex operating environments that experienced sudden changes in demand.
  • The telecommunications industry continues to be a popular target for the nation-states, specifically China. OverWatch observed six different China-based actors, whose motivations are likely associated with espionage and data theft objectives, conducting campaigns against telecommunications companies in the first half of the year.

Jennifer Ayers, Vice President of OverWatch and Security Response, said, “Just like everything this year, the threat landscape has proven unpredictable and precarious as eCrime and state-sponsored actors have opportunistically taken aim at industries unable to escape the chaos of COVID-19, demonstrating clearly how cyber threat activity is intrinsically linked to global economic and geo-political forces. OverWatch threat hunting data demonstrates how adversaries are keenly attuned to their victim’s environment and ready to pivot to meet changing objectives or emerging opportunities.”

It is time for organizations to implement a layered defense mechanism that incorporates endpoint detection and response (EDR), threat hunting, password management, and employee awareness to enhance their cybersecurity posture.

U.K. NCSC Launches New Vulnerability Reporting Toolkit

NCSC

The U.K.’s National Cyber Security Centre (NCSC) released a new “Vulnerability Reporting Toolkit,” which is intended to help organizations manage their vulnerability disclosure processes in a simplified manner. The Toolkit is helpful for all types of organizations that are planning to implement a vulnerability disclosure process in their system. It provides a comprehensive guide to develop a disclosure program that was built based on three essential components, which include Communication, Policy, and Security.txt.

“Security vulnerabilities are discovered all the time and people want to be able to report them directly to the organization responsible. The NCSC’s Vulnerability Disclosure Toolkit contains the essential components you need to set up your own vulnerability disclosure process,” NCSC said in a statement.

Importance of Vulnerability Reporting

Vulnerability reports from bug hunters provide critical information about existing vulnerabilities in the systems that can be used to fix the issues and improve the security posture. “Having a clearly signposted reporting process demonstrates that your organization takes security seriously. By providing a clear process, organizations can receive the information directly so the vulnerability can be addressed, and the risk of compromise reduced. This process also reduces the reputational damage of public disclosure by providing a way to report, and a defined policy of how the organization will respond,” NCSC added.

How to Respond to Vulnerability Reports

The NCSC recommended certain steps to effectively respond to a vulnerability report, these include:

  • Do not ignore the report. Respond promptly to the finder (bug hunter) and thank them. Feedback encourages engagement and they will be more inclined to help you again in the future.
  • Pass the report to someone in your organization who is responsible for the affected product or service. If it is managed by a third-party, discuss the report with them.
  • Avoid forcing the finder to sign documents such as non-disclosure agreement (NDA) as the individual is simply looking to ensure the vulnerability is fixed.
  • If you need more information to confirm and fix the issue, you should politely request that additional information from the finder.
  • Once you have decided on a course of action, let the finder know that the issue is being managed. You do not need to provide lots of technical information or commit to timescales.
  • If the issue takes time to fix, you should send periodic updates back to the finder.
  • Once the issue is fixed, let the finder know. They might be able to retest the issue to confirm the fix.
  • Consider publicly acknowledging and thanking the finder as this creates a sense of trust and transparency.

“The toolkit is not an all-encompassing answer to vulnerability disclosure. If you do not have a vulnerability disclosure process, then the toolkit can help you create one. We believe it is worth establishing a process in advance. The toolkit is deliberately easy to implement, so you can adopt it at short notice. Even if you already have a process in place, take a look at the toolkit as it may help you to improve on what you have already set up,” NCSC concluded.

To help prevent growing cyberattacks, vulnerability reporting will be embedded into the U.K. government’s legislative framework, which will require makers of smart devices to provide a public point of contact as part of a vulnerability disclosure policy.

Telstra Forms Alliance with ACSC and Services Australia to Eradicate Phishing Texts Spoofing

Cryptocurrency scams in Australia

Australia has been a hotbed for cyberattacks and the country’s Prime Minister, Scott Morrison, has been very vocal about it. Owing to the surge in cyberattacks, especially targeted towards the country’s critical infrastructure, Morrison recently allocated AU$1.66 billion (approximately US$1.19 billion) funds to bolster the cybersecurity defenses for enterprises. However, as a personal recommendation, he also asked businesses to ramp up their own defenses and help the greater cause of defending Australian citizens from such malicious activities. In response to his request, Telstra has now taken the initiative and partnered with the ACSC and Services Australia to launch a pilot project for block phishing texts from reaching Telstra’s customers.

How to make SMS’s Safer

Telstra’s announcement created curiosity as to how exactly blocking phishing texts would be possible. To clear the air, it explained, “when a text message is sent over our network, using information called “metadata”, we can identify and reject illegitimate phishing text messages impersonating a specified SenderID before they reach Telstra customers.”

Telstra has worked closely with the ACSC and Services Australia to create an officially approved list of sources associated with SenderIDs, like myGov or Centrelink. This means that any message with a SenderID that originates from an unapproved source will be blocked from transmitting it through to the Telstra customers.

Anyone and Everyone is a Target

Telstra believes that at a time when scammers are taking increasing advantage of the COVID-19 pandemic, anyone and everyone with a connected device in hand is a potential target for them. It also shared a screengrab to demonstrate how scammers are convincingly producing phishing texts and links to make their customers believe in the authenticity of the text message.

block phishing texts
Image Credit: Telstra Exchange

It is to be noted that scammers impersonate names of government agencies to increase their chances at appearing legitimate.

Phase One of the project is currently being rolled out, while the other is anticipated to be rolled out in the next few months to help protect larger groups of customers from such malicious scammers.

Telstra’s CEO, Andy Penn said, “Cybercriminals continue to target Australians through SMS phishing campaigns by sending them text messages that attempt to redirect them to malicious websites. Being able to stop these scammers in their tracks will go a long way to protecting our customers With so many Australians now working from home as well as relying on Government assistance through Services Australia, it’s vital that we constantly evolve our approach in defending against malicious activity on our networks. It is now more important than ever to protect its customers.”

Strategic Alliance! Abnormal Security and Microsoft to Deliver Comprehensive Email Security

Abnormal Security Partners with Microsoft to Boost Cybersecurity

Cybersecurity solutions provider Abnormal Security announced its strategic alliance with Microsoft to provide comprehensive cloud email security and other cybersecurity solutions to organizations. The partnership integrates Abnormal’s security platform with Microsoft Azure to further enhance existing capabilities for advanced security.

Based in San Francisco, CA., Abnormal Security protects organizations from advanced targeted attacks including spear-phishing and business email compromise attacks. Its cloud-native architecture and AI platform provide an inside-out understanding of people and organizational processes to prevent targeted email attacks.

Evan Reiser, Co-founder and CEO at Abnormal Security, said, “When considering the right cloud infrastructure, startups need to look at both the technology platform and the business opportunity. As a cybersecurity company, we were very intrigued with Azure’s inherent security, privacy, and AI offerings and as a startup, Microsoft’s go-to-market support and access to the largest enterprises is unmatched.”

Abnormal’s new security offering will be directly available for purchase on Microsoft’s Azure Marketplace.

Jeffrey Ma, VP Microsoft for Startups said, “Microsoft for Startups helps B2B startups use the Microsoft platform to scale their business quickly and deliver innovative AI-powered solutions to enterprise customers.”

Microsoft’s New Integrations

Recently, automotive cybersecurity firm Upstream Security joined the Microsoft Intelligent Security Association to establish an ecosystem of leading software vendors that have integrated their solutions to better defend against automotive cyberattacks.  Upstream also revealed that its C4 platform and Microsoft Azure Sentinel will help enable detection, investigation, and remediation for threats targeting connected vehicles and smart mobility services. Through this integration, alerts from Upstream C4 can be used to automate responses based on an OEM vehicle manufacturer’s or connected fleet’s unique security policies. Upstream’s C4 platform leverages existing automotive data feeds to detect threats in real-time and delivers cybersecurity insights supported by AutoThreat Intelligence.

Taiwan to Establish Cybersecurity Excellence Center by 2022

Industrial Cybersecurity

In a bid to boost cybersecurity of the nation and to bolster information security talent, Taiwan would be establishing a cybersecurity excellence center in the country by 2022. A budget of NT$818 million (US$28 million) has been earmarked for the initiative, which will not only spearhead cybersecurity innovation but will also address the cybersecurity skill gap in the country. The cybersecurity excellence center is aimed at making Taiwan the Asian hub of high-end information security professionals and innovation.

The excellence center will serve as a corporate base for Taiwan’s cybersecurity infrastructure. Vice President Lai Chin-te while addressing the Taiwan Hackers Annual Conference HITCON 2020, earlier this year, had noted that “with Taiwan aiming to become a smart country to jump on the Industry 4.0 bandwagon like other global countries, information security has become more important than ever.”

According to Liberty Times, the cybersecurity excellence center will focus of three key areas. These include network security, password security and information security. The nation will also proactively drive innovation to defend its infrastructure from the increasing threat vectors like malware campaigns and state-sponsored attacks.

With the nation witnessing an average of 300 million cybersecurity scams and over 30 million attacks every month originating from neighboring countries like China, cybersecurity of Taiwan is of paramount importance. It is estimated that Taiwan’s cybersecurity market is expected to reach a net worth of 78 billion by 2025.

Among the notable cybersecurity initiatives adopted by the country, Department of Cyber Security, Executive Yuan proposed the “Action Plan for Cybersecurity Industry Development (Draft)” based on the conclusions of the Strategy Review Board Meeting (SRB) and the “National Cyber Security Program of Taiwan (2017-2020)” promulgated in November 2017. As of today, the said program, which includes “promoting the cybersecurity industry’s capacity” in the key tasks of promoting the medium-term/long-term development of national cybersecurity infrastructure, has been implemented for three consecutive years,” suggests a study commissioned by the Netherlands Enterprise Agency titled ‘Research of Cyber Security Industry in Taiwan.

PII of 46,000 U.S. Veterans Compromised in a Data Breach

U.S. Military Personnel and Veterans

The U.S. Department of Veterans Affairs (VA) Office of Management disclosed a data breach incident that exposed the sensitive information of around 46,000 veterans. In an official release, the authorities stated that one of the Financial Services Center’s (FSC) application was accessed by unauthorized users through social engineering techniques to divert the payments to community care providers for the Veterans’ treatment.

The FSC took the application offline temporarily and reported the incident to the regulators for further investigation. “To prevent any future improper access to, and modification of information, system access will not be re-enabled until a comprehensive security review is completed by the VA Office of Information Technology,” the notice said.

The FSC stated that it will notify the affected users and take necessary actions to prevent and mitigate any potential damage. The department is also offering free credit monitoring services for the affected Veterans in the data breach. “Veterans whose information was involved are advised to follow the instructions in the letter to protect their data. There is no action needed from Veterans if they did not receive an alert by mail, as their personal information was not involved in the incident,” the notice added.

Not the First Time

This is not the first time that cybercriminals targeted the Veterans in the U.S. Earlier, security researchers from Cisco Talos discovered a threat group targeting the U.S. military Veterans via a fake job portal promising help for those looking for jobs. To trick users into finding jobs, hacker group Tortoiseshell targeted Americans who are in search of jobs, especially military Veterans via a phony website, hxxp://hiremilitaryheroes[.]com, which is a lookalike of the legitimate website, https://www.hiringourheroes.org.The phony URL directs the victims to another fake site and prompts them to download an app, which is a malware downloader that deploys spying and other malicious tools.

“Cyber Partisan” Hacker Group Threatens to Mass Hijack Key Public Systems in Belarus

Ransomware gangs

Belarus, the former part of the Soviet Union, has always had a political turmoil since gaining freedom in 1991. But currently, the unrest has reached a level higher as mass protests broke out from August 9, 2020, against the country’s re-elected President Alexander Lukashenko. The demonstrators believe that the results of the recently concluded presidential elections were rigged and have thus warned him of mass hacking operations that can lead to disruption of multiple public services if he failed to comply with their demands.

The Threat from “Cyber Partisans”

A Belarusian hacker group, by the name “Cyber ​​Partisans,” published a direct threat note on a Telegram channel addressing President Lukashenko that they would bring down the critical public control systems in the nation if protesters are continued to be detained. The note was accompanied by a picture hinting the possibility of hacking attempt on the Ministry of Taxes and Duties’ official website.

The published post said,

“Alexander Lukashenko, we address you personally: It will be very painful… first the tax system will go down, then the electricity in the country will run out, then the banking system will go down… Do you need it?”

Additionally, the hackers threatened they would “kill the ruble” and start blocking the bank accounts of people from Lukashenko’s inner circle.

Threat in Australia

Earlier this year, Australian banking and financial institutions received threat emails indicating a possibility of distributed denial of service (DDoS) attacks against them. However, the motive here was different, it was plainly financial gain. To avert the consequences, the extortioners by the name “Silence Hacking Crew” demanded a ransom to be paid in the form of Monero (XMR) cryptocurrency.

Marriott, British Airways, and EasyJet Websites are Vulnerable to Attacks

Domain Name Security

A new investigation from the consumer advocacy organization Which? has uncovered hundreds of critical security vulnerabilities on the websites of popular airlines, hospitality chains, and travel companies. Which? researchers and security experts from 6point6 evaluated the security of websites of 98 companies in the travel industry, including cruise lines and booking sites, in June 2020. The researchers found that Marriott, British Airways, and easyJet were in the top five companies with the most security vulnerabilities. These three firms already suffered data breaches earlier, which resulted in hundreds of millions in fines from data regulators.

A Century of Vulnerabilities

The researchers found 497 flaws on Marriot owned websites, in which 96 vulnerabilities deemed as high severity and 18 ranked as critical. “Three critical vulnerabilities were found on a single website of one of Marriott’s hotel chains, involving errors in the software used to run the website potentially allowing an attacker to target the site’s users and their data,” Which? said.

European airline easyJet, which recently suffered a data breach that compromised details of 9 million customers, was found to have 222 vulnerabilities across  nine of its websites. If exploited, attackers could hijack users’ browsing sessions. EasyJet took down three domains and fixed the vulnerabilities on the other six websites. “None of these subdomains were linked to easyJet.com, and it has seen no evidence of any malicious activity on these sites and none store any customer passwords, credit card details or passport information,” EasyJet’s spokesperson said.

The researchers also discovered 115 vulnerabilities on British Airways’ websites, in which 12 flaws were found to be critical. “We take the protection of our customers’ data very seriously and are continuing to invest heavily in cybersecurity. We have multiple layers of protection in place and are satisfied that we have the right controls to mitigate vulnerabilities identified,” said a British Airways spokesperson.

American Airlines has over 291 potential vulnerabilities across its websites, with seven critical and 30 high-severity flaws. “We use a combination of internal and external cyber professionals to regularly identify and test the security of our systems and continue improving our capabilities,” American Airlines responded.

Critical vulnerabilities in Lastminute.com’s 153 subdomains were also found, which could allow an attacker to manipulate pages, access sensitive information like session cookies, browsing history, and create fake login accounts.

Irrespective of the severity, security vulnerabilities could cause severe damage to an organization’s security infrastructure. Attackers can exploit these flaws for their advantage. Organizations in the travel industry must gear up their cybersecurity measures to protect their customers from cyberattacks. If not, they should be ready to face the punitive actions or hefty fines from the data regulators.