Home Blog Page 172

“Attackers are looking to break into your organization either by a broken VPN or RDP protocols”

It’s not every day that one gets to meet an influential person from the world of cybersecurity. CISO MAG caught up with Yotam Gutman, Marketing Director at SentinelOne. He once served as Lt. Commander in the Israel Navy. He was chosen as one of the top 5 Security Influencers to Follow on LinkedIn.

Lt. Commander (Ret.) Israel Navy, Gutman has filled several operational, technical, and business positions at defense, HLS, Intelligence, and cybersecurity companies, and provided consulting services for numerous others. He joined SentinelOne 8 months ago to oversee local marketing activities in Israel and contribute to the global content marketing team. Gutman founded and managed the Cybersecurity Marketing Professionals Community, which includes over 300 marketing professionals from more than 170 cyber companies.

In a Zoom call with Brian Pereira, Principal Editor, CISO MAG, Gutman tells us about his journey from the Israeli Navy to Homeland Security and then to a cybersecurity startup ecosystem in Israel, finally becoming the Marketing Director at SentinelOne. He also discusses how SentinelOne grew from a startup to a global organization in less than a decade.

Edited excerpts from the interview follow:


You served the Israeli Navy but how did you get into cybersecurity? What are your core interests in this field?

My route into cybersecurity was a peculiar one. Like most Israelis, I served in the armed forces, specifically in the Israeli Navy, where I was an officer for six and a half years, starting with serving on missile ships.  Later, I served as an instructor at the naval academy. On completion of service, I started working with Israeli defense companies, which worked extensively with India. After that, I moved to Homeland Security, and you will recall the terrorist attacks in Mumbai, around 2008. Israeli companies work with governments and organizations all over the world to improve their internal security, smart cities, and border security. Four years later, I saw that form of terrorism is starting to decline and that there is an emerging field called cybersecurity.

In 2010, there was a cyberattack on Iran’s nuclear facility (Stuxnet), and that incident highlighted the need to secure not just the IT infrastructure and the data that resides within but also the physical infrastructure.

Pursuing the current opportunities, I have worked with Israeli startups–there are 350 cybersecurity startups in Israel that are divided into roughly 150 cybersecurity product categories, collectively. My niche within that was to take my previous experience, product skills, pre-sale skills, marketing skills, and help those companies with their product offerings. And for the past six years, I moved between companies until I found my current position.

During this time, I met hundreds of local marketers and professionals and there was much sharing in communities, and we also established a community of like-minded professionals to share information about cybersecurity and marketing. Currently, this community has 350 members from all the major cybersecurity companies in Israel.

Can you tell us the story of SentinelOne and how it scaled up so quickly? How did you land up at SentinelOne? What are you involved in these days?

SentinelOne was established more than seven years ago and it was just like any other startup. People (in the company) knew one another from the military service and they came up with an idea to improve endpoint security. SentinelOne grew very rapidly and most of the company is now located overseas. The HQ is in the U.S. and they now have a large presence in the EU. We just established the first Asia Pacific HQ in Singapore. So, it has grown very quickly, and we now have 500 employees and many customers.

I got into it through one of the people in the community, who is also an ex-Israeli Navy. He suggested that I help them boost their marketing efforts on the local front. SentinelOne has been investing in brand awareness and brand recognition globally, especially in the North American market. And in the local market, it never got sufficient attention. But when it got to a point where we needed to recruit about 100 people each year, the lack of public awareness became a challenge.

I joined about a year ago. I began as a consultant and then I saw it as a good fit, and later joined full time, last January.

On the local front, I am helping with recruitment marketing, and we look for the top talent in cybersecurity and technology, in general. I’m also part of the global marketing team made up of content marketers, product marketers, people who are tech-savvy — and we create content that generates leads. We publish that content in many channels.

As an outsider, I was impressed with SentinelOne as it achieved something very few companies in the world, especially here in Israel, are able to do on that scale. Last year we did a business of $100 mn globally and this year we hope to increase that.

Even the pandemic has not made a dent in our sales. So, I am envisioning great things for this company.

How did you help customers when the pandemic was announced in March?

When this happened, we were among the first to inform customers about the risks of working from home. We conducted a webinar in early March to inform them. We also reached out to our existing customers and offered to extend the number of licenses. Since they were sending workers home, they would be looking to buy new licenses. That’s not something they were expecting. That’s not something that was budgeted. We offered that to them for a period of 90 days and this was also available to new customers.

We then started monitoring the threat intelligence landscape, and we have a blog with COVID-related threats. We advise people about IOCs (Indicators of Compromise) and compromised IP addresses.  We also beefed up our support and conduct surveys to measure their level of satisfaction.

How has the SentinelOne product evolved to help remote workers in a decentralized environment? Can it stop ransomware?

The product was initially built as an on-prem solution. We observe that people who work from remote locations connect and then they disconnect and go to a coffee shop and continue working. So, our product can work even in a non-connected environment when you are not connected to the cloud, or where there is no Wi-Fi connection. Our product will still secure you in a robust manner.

We invest in the autonomy of the product. We also invest in the ability to perform a roll-back, specifically for ransomware attacks. Sometimes our systems are able to stop these attacks. So, this is behavioral-based. If it is not a known threat, we will pick it up, but sometimes we could be late by a few seconds. That’s why we make sure that the product allows one to roll back and decrypt some of the files. We were also able to detect new forms of ransomware, create a decryptor, and publish it online for anyone to access.

To counter this, we identify a new device on the network and fingerprint it, and we compare it to other devices in the network. Let’s say it is a security camera. If it starts behaving differently from other cameras, we can then block it through the firewall and prevent it from accessing the external world. So, we can restrict its behavior in a cyberattack.

This is an ongoing battle. We have to keep learning what the attackers are doing and keep training our algorithm to respond to the threat.


Read a longer version of this interview in the October 2020 issue of CISO MAG. Subscribe here.

Hackers Shifting Focus from Enterprises Toward High-Value Individuals

CISO MAG Panel Discussion

For a legion of cybersecurity experts plugged from across the globe, CISO MAG and CYFIRMA recently hosted a panel discussion on “The State of Cybersecurity: Why do Breaches Continue to be Unabated.” The discussion was moderated by Jyoti Punjabi, Deputy Business Head, CISO MAG, and the panel had Kumar Ritesh, Founder and CEO, CYFIRMA; Lim Shih Hsien, Chief Security Officer, SP Group; LOI Liang Yang, ASEAN Security Software Segment Leader, IBM; and Chris Roberts, Researcher, Hacker, CISO. in participation. The discussion took a virtual format to create awareness on the need for cybersecurity and its related implications in times of a pandemic.

The discussion began with an address by Jyoti Punjabi who spoke on the dire straits of cybersecurity due to the ongoing pandemic, and how cybersecurity is still an afterthought for several organizations, even though the industry is worth a trillion. She also highlighted how digital is the new normal, attack vectors are witnessing an exponential uptick, and cyberthreats are increasing manifold. Taking the lead, Kumar Ritesh explained, “There are a number of reasons for this trend. To begin with, the controlled environment posed by the pandemic on us, learning how to operate remotely even for business for whom remote working was unimaginable. The transition wasn’t a planned one but was done over night owing to the situation. I don’t think anything like that has ever happened, where there was such prompt action. And knowingly or unknowingly, we have exploded attack vectors without enough emphasis on cybersecurity.”

Kumar Ritesh has more than two decades of global cybersecurity leadership experience across all facets of the industry. A highly dynamic executive who successfully blends technology expertise with business acumen, he has a strong track record of developing successful cybersecurity strategies, products, policies, standards, and solutions, in addition to running complex cybersecurity programs. Today, Ritesh leads one of the foremost threat discovery and cyber-intelligence company, CYFIRMA, where its cloud-based analytics platform helps organizations decode threats and predict upcoming cyberattacks.

Ritesh added, “In the midst of all of these the bigger concern became geopolitical rifts between states and most of us are facing several state-sponsored attacks most of the time. While we look at ourselves as the defenders, we are set back due to constraints like budget, resources, etc.

“Another interesting trend we noticed from the cyber-intelligence front was that newer nations started to jump into the cybercrime economy. We have seen a big uptick in the last six months where new nations have joined the bandwagon of the cybercrime economy. Apart from that, there has also been a shift in the interest of hackers. They are moving away from enterprises toward high-value individuals, leveraging the work from the home format.”

Concurring Ritesh’s opinion, LOI Liang Yang said, “I completely agree with Ritesh here. In fact, every other day I am getting messages from someone or the other asking me to help them break into an enterprise. So, yeah, the threats are real.” He added that in the past few months he witnessed a steep increase in the number of attacks from several vectors of cyberthreats.

LOI Liang Yang is a Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker, and CompTIA Security+ cybersecurity consultant. LOI advises large enterprises including multiple fortune 500 companies on security strategy to protect against advanced threats.

LOI has a cybersecurity channel with more than 4 million views and over 170,000 global subscribers tuned to all his cybersecurity tutorials and lectures. LOI also teaches ethical hacking and network defense to the next generation of cybersecurity professionals.

Lim Shih Hsien also shared a similar assessment from a blue team perspective. Lim Shih Hsien is the Chief Security Officer, SP Group. He is currently responsible for managing the cyber and physical security risks for the SP Group, which owns and operates electricity and gas transmission and distribution businesses in Singapore and Australia.

Prior to joining SP in February 2019, Shih Hsien was heading the information security and data privacy functions for The Hong Kong Jockey Club. Before taking on this role in 2011, he was a member of the MOH Holdings P/L management team that was responsible for establishing the security technical architecture and policies for Singapore’s National Electronic Health Record (NEHR). Shih Hsien has also previously held senior positions in Singapore Airlines and Infocomm Development Authority of Singapore.

“We are in different times. There was a time when we were behind a wall, but now there is no perimeter as such, so that is possibly how COVID-19 has changed the world,” added Chris Roberts, Researcher, Hacker, CISO.

Roberts possesses a rich experience within the domain of information security and is globally recognized as one of the pioneering wizards on vulnerability research and counter-threat intelligence. He has worked on a multiplicity of projects specializing in intelligence gathering, DarkNet research, deception technologies, and cryptography with a number of organizations, and has been credited by many of the top Information Technology and Security disciplines.

The panelists also took questions from the audience. You can find the full version of the panel discussion here.

About CISO MAG

CISO MAG, an EC-Council initiative, is a cybersecurity magazine delivering cutting-edge updates about the latest happenings in the cybersecurity world. It is the handbook for CISOs, CXOs, and every responsible stakeholder of a secure Internet space.  Learn more at https://cisomag.com/

About CYFIRMA

Headquartered in Singapore and Tokyo, CYFIRMA is a leading Predictive Cyber Threat Visibility & Intelligence Platform company. Its cloud-based AI and ML powered Cyber Intelligence Analytics Platform (CAP) v2.0 helps organizations proactively identify potential threats at the planning stage of cyberattacks, offers deep insights into their cyber landscape, and amplifies preparedness by keeping the organization’s cybersecurity posture up-to-date, resilient, and ready against upcoming attacks.

CYFIRMA works with many Fortune 500 companies. The company has offices and teams located in Singapore, Tokyo, and India. Official websites: https://www.cyfirma.com/ and https://www.cyfirma.jp/

Digital Point’s Unsecured Database Exposed Records of Over 800,000 Users

Zyxel Devices Vulnerable to Secret Backdoor

An unprotected database belonging to a webmaster forum, Digital Point, exposed more than 800,000 users’ records. Security firm WebsitePlanet and security researcher Jeremiah Fowler found the unsecured Elasticsearch database on July 1, 2020, which contained over 62 million users’ records belonging to 863,412 Digital Point users.

Digital Point is a marketplace for web related services. The company caters to those individuals who maintain or create websites and lets users buy and sell websites, SEO, etc. The leaky database exposed users’ personal details like email addresses, names, internal user ID numbers, internal records, and user posts. “This is an Elastic database set to open and be visible in any browser (publicly accessible) and could have been edited, downloaded, or even deleted data without administrative credentials,” the researchers said.

Potential Impact of the Leak

Exposure of personal information could allow cybercriminals to launch targeted phishing attacks. They could also misuse contact information, email IDs, and other sensitive details to create a fake domain that impersonates a legitimate one. Domain hijacking is commonly used by threats actors to change the registration and ownership information. The criminal has an upper hand, as the domain could be used for malicious activities or sold to a third party. Using a strong password or enabling multi-factor authentication for domain protection is highly recommended.

Risks with Unsecured Databases

Every minute is an opportunity for threat actors. A recent security experiment by Comparitech led by cybersecurity researcher Bob Diachenko discovered that cybercriminals attacked a model of an unsecured database 18 times in a single day. In a security alert, Comparitech explained how unauthorized third parties find, gain access, and alter exposed data without any authentication process, leaving users’ privacy at risk. The company set up a honeypot to know how quickly the hackers would attack an Elasticsearch server with a dummy database and fake data in it.

Comparitech left the exposed data from May 11 until May 22, 2020. It found 175 attacks in just eight hours after the server was deployed, and the number of attacks in one day totalled to 22. All attackers were not looking to steal data. Some targeted unsecure servers to mine cryptocurrency, steal passwords, and destroy data.

Israel’s Tower Semiconductor Hit by a Cyberattack

Israel

Israel’s semiconductor and chip manufacturer, Tower Semiconductor, announced of a cyberattack that forced its certain operations to a complete halt. The company authorities said that specific measures were taken to prevent the spread of the cyberattack, however, there was no immediate factual assessment report available that would state the real effect of the damages done.

Tower Semiconductor has operations spread across three different locations around the globe – two in Israel (Migdal Haemek); two in the U.S. (Newport Beach, California and San Antonio, Texas); and at three in Japan where it has partnered with Panasonic Semiconductor Solutions Co. Ltd. It mainly manufactures integrated circuits (ICs) and provides a host of technology solutions for growing markets such as consumer, industrial, automotive, mobile, infrastructure, medical, aerospace, and defense. Thus, this attack could have been targeted by an adversary to lay hands on the company’s trade secrets, contracts, or even intellectual property like the patented designs and processes.

The company has reported the issue to relevant authorities for a quicker resumption of services and stated that it is providing utmost support from their side. It said, “Tower has notified relevant authorities and is working closely with the law enforcement organizations and with a leading team of worldwide (cybersecurity) experts, coordinated with its insurance providers, in order to recover the impacted systems as soon as possible. As a preventive measure, the company halted certain of its servers and proactively held operations in some of its manufacturing facilities, and has done so in a gradual, organized manner.”

No malicious adversaries have taken the responsibility of this cyberattack, and therefore information of the source, intent, and type of the cyberattack is yet to be confirmed.

Israel – The Playfield for Cybercriminals?

On May 21, 2020, Israel reported a cyberattack that defaced websites of the country’s major organizations, political groups, and industrial ranks. The hack took place through a website hosting provider, uPress. uPress released a statement on its official Facebook page stating that the root cause of the cyberattack was a WordPress vulnerability that was exploited successfully by the cybercriminals. It also worked in tandem with the National Cyber Security Authority (NCSA) of Israel to reinstate all the original content to the last known point before the cyberattack took place.

Whistle-Blower Reports to ICO Increase by 34% in the Last Year

Whistle-Blower Reports to ICO Increase by 34% in the Last Year

Ever since the GDPR was introduced, disclosure of security incidents via whistle-blower reports has increased significantly. According to a report from RPC, a legal and consultancy services firm, the increased awareness of online frauds and other malicious attacks led people to report organizations for not following required security measures with the customers’ data they hold. The report revealed that the number of whistle-blower reports disclosed to the Information Commissioner’s Office (ICO) about data breach incidents and the misuse of customer information by organizations jumped 34% to 427 in the last year, from 319 the previous year.

Out of the 427 whistle-blower reports, action was taken on 68 reports, including 23 being taken into consideration for investigations by the ICO. In the previous year, 55 whistle-blower reports were considered for investigation. In addition, the ICO issued over £282 million (US$ 370.253) in fines to a major airline and international hotel group, for having put millions of customers’ data at risk.

Whistle-blower reports on data breaches to the ICO

Image Source: RPC

“Whistleblowing is now a major risk for businesses that fail to deal with a data breach properly, or who have failed to take reasonable steps to protect the data they hold on their customers. This makes it more important than ever for businesses who do fall victim to a data breach to respond quickly and to inform the ICO of the data breach if necessary, within the right deadline and ensure customers are informed when they are exposed to a major risk,” said Richard Breavington, Partner at RPC.

“Whilst the ICO has indicated that it is exercising forbearance during coronavirus, businesses would be wrong to think that is a free pass. With millions of employees continuing to work from home, businesses need to have clear practices in place. For example, recommending multi-factor authentication if employees are using their own devices for work and advising employees to update software regularly so it’s at a lower risk of being hacked into,” Breavington added.

WhatsApp Discloses Six Bugs in its First Security Advisory

Whatsapp

Facebook-owned messaging service provider WhatsApp, in the past week, started a Security Advisories page. On this page, WhatsApp is disclosing all the bugs and vulnerabilities that have been found and fixed to maintain transparency and encourage security researchers to report any other bugs as part of the company’s bug bounty program. In its first Security Advisory update, WhatsApp has already disclosed six vulnerabilities,  which, if exploited properly, would potentially provide remote code execution privilege to the attackers.

What’s WhatsApp Security Advisories

WhatsApp claims to provide users an end-to-end encryption messaging service utilizing the Signal Protocol designed by Open Whisper Systems. With more than two billion registered users, it is an ever-growing platform and handles a very large amount of confidential user data. Taking the learnings from its parent company Facebook, WhatsApp takes the privacy and security of user data very seriously. It reports any discrepancies through timely updates and informs the users about the same through app release notes. However, it states, “Due to the policies and practices of app stores, we cannot always list (entire) security advisories within app release notes.”

Thus, to close this gap and provide a single directory for a comprehensive list of WhatsApp security updates and associated Common Vulnerabilities and Exposures (CVE), the WhatsApp Security Advisories page has been launched.

The Six Vulnerabilities of First WhatsApp Security Advisory

  1. CVE-2020-1894: A stack write overflow in WhatsApp that could have allowed arbitrary code execution when playing a specially crafted push to talk message.
  2. CVE-2020-1891: A user-controlled parameter used in video calls that could have allowed an out-of-bounds write on 32-bit devices.
  3. CVE-2020-1891: A URL validation issue that could have caused the recipient of a sticker message containing deliberately malformed data to load an image from a sender-controlled URL without user interaction.
  4. CVE-2020-1889: A security feature bypass issue that could have allowed for sandbox escape in Electron and escalation of privilege if combined with a remote code execution vulnerability inside the sandboxed renderer process.
  5. CVE-2020-1886: A buffer overflow that could have allowed an out-of-bounds write via a specially crafted video stream after receiving and answering a malicious video call.
  6. CVE-2019-11928: An input validation issue that could have allowed cross-site scripting upon clicking on a link from a specially crafted live location message.

Vulnerabilities Summary

Vulnerability Names

  • Stack write overflow vulnerability.
  • A user-controlled parameter used in a video call.
  • A URL validation issue.
  • Security feature bypass vulnerability.
  • Buffer Overflow vulnerability.
  • An input validation issue.

CVE Numbers & Affected Versions

  • CVE-2020-1894 / WhatsApp for Android prior to v2.20.35, WhatsApp Business for Android prior to v2.20.20, WhatsApp for iPhone prior to v2.20.30, and WhatsApp Business for iPhone prior to v2.20.30
  • CVE-2020-1891 / WhatsApp for Android prior to v2.20.17, WhatsApp Business for Android prior to v2.20.7, WhatsApp for iPhone prior to v2.20.20, and WhatsApp Business for iPhone prior to v2.20.20
  • CVE-2020-1890 / WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2
  • CVE-2020-1889 / WhatsApp Desktop versions prior to v0.3.4932
  • CVE-2020-1886 / WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2
  • CVE-2020-11928 / WhatsApp Desktop versions prior to v0.3.4932

CISO: The Technical Unicorn

A lone sentry stands guard on the eastern end of a towering granite stone wall with sweeping views of the approaching terrain. Bravely, he scans the expansive horizon like an eagle searching for its prey. The sentry maintains a single-minded focus and a determination to identify and eliminate any potential threat at a moment’s notice. The sentry is filled with trepidation knowing an attack is imminent and that he is all that stands between security and total destruction and, in spite of the fear, performs with honor and does his duty.

By David Katz, Partner and Privacy, Cybersecurity and Data Management Team Leader, Adams and Reese

The parallels to the plight of the modern-day CISO as the lone sentry guarding against the barbarian hordes charging the wall, while dramatic, are not far off the mark for comparison. A closer examination of the role of a CISO reveals far more than just the role of a lone sentry, expendable and vulnerable for the collective safety of others and the greater good. Far from expendable, the modern-day CISO should be viewed and equipped like a five-star general responsible for leading a coalition of capable and technologically advanced warfighters against a determined enemy bent on the destruction of our economic and national security. Making the case for such treatment by the C-suite and corporate directors can be challenging and requires a high degree of technical proficiency, emotional and social intelligence, and raw political skills not seen since the days of the Medici in Florence, Italy.

The question presented and answered in this article is how the modern-day CISO can position themselves to be successful in the face of such challenges and lead their organizations with confidence and, most importantly, with a full complement of material to assure victory in the face of significant cybersecurity threats.

The Evolving Requirements of the CISO

The CISO’s responsibilities within an organization can vary in scope depending on the management reporting structure within the organization. Typically, the CISO is an executive that is responsible for the organization’s information and data security; however, in recent years some organizations have expanded the role of a CISO to encompass more of direct management and decision-making role in operations and direct reporting to the CEO or directors in their capacity as a vice-president or CSO.

The CISO’s evolving duties include an interwoven set of responsibilities that combine complex technical operations with underlying business operations. The resulting outcome is that in many instances the success of business operations from a security perspective is dependent on those technical operations overseen by the CISO. These unique responsibilities are not shared or governed by any other individual business owner within the organization. This evolution is one of the many elements that make the role of the modern CISO very challenging and unique to all other executives. The dependency here puts tremendous pressure on the CISO to ensure that security does not impede the business operations, yet any failure of security which leads to an operational failure will likely be blamed on the CISO.

As an example, the CISO must make decisions concerning expenditures for security architecture that involve planning, purchasing software or hardware, and working with IT operations and networking infrastructure teams to ensure best practices are implemented from a security perspective. Again, in this case, the operations are dependent from a security perspective on the work of the CISO, but the decision making from a business perspective is removed from the CISO. To the extent a conflict develops between the security and business teams around network architecture planning, the CISO must adeptly navigate and make the case without impeding the business and ensure the ultimate decision-makers for the business have the information necessary to adopt the best practices even if this may be an impact to operations.

The second example of this interwoven set of responsibilities and dependencies occurs in the security domain of access and identity management. This area of responsibility requires the CISO to ensure that only authorized individuals have access to restricted data and restricted systems. Here, the CISO’s responsibilities are interwoven with the human resources department. In this case, the operation is dependent on the CISO to ensure only authorized individuals are granted access to restricted data and restricted systems. Ultimately, it is the business operators in the form of human resources representatives or individual managers that determine accessibility or control the means by which the CISO is made aware of personnel changes. This creates a potential conflict in that failure to restrict an unauthorized individual can result in a security incident for which the CISO may be held accountable, but the CISO may not ultimately have control over the designation of who is or is not an authorized individual.

In summary, these examples illustrate an existing tension for the modern-day CISO in many organizations. In simple terms, the CISO is accountable for the security of systems and operations for which they may have no ultimate decision-making authority. The CISO must instead rely on their communication and persuasion skills in order to resolve conflict or be in a position to escalate up through management to resolve potential conflicts without alienating their internal business clients. Exacerbating this tension is the fact that corporations are organized to create wealth and value for their shareholders and to secure a profit. Where a conflict arises that forces a decision that could impact profitability over security, it becomes very difficult for management teams and directors, given their primary mandate to make any decision that could imperil profitability. Even if the risk of loss from a security failure could potentially impact profitability, management teams and directors won’t be rewarded for playing it safe at the expense of earnings. To say this creates a difficult position for the CISO is at best an understatement. In light of these dependencies, potential conflicts, lack of decision-making authority, and primary mandate of the corporate form for profitability, the primary question remains: How can the CISO position themselves to be successful, lead their organizations with confidence and obtain all of the necessary resources required to secure their organizations?

The Unicorn Theory

In order to be successful, the modern-day CISO must first possess all of the technical skills required to perform their responsibilities and these skills are not easily acquired or in abundance in the marketplace. Second, the CISO must have all of the communication, emotional and social intelligence, and political skills to consistently and adeptly negotiate the inherent conflicts that exist in the successful performance of their duties and responsibilities within the organization. Like the technical skill-set required, the communications skill-set is also not easily acquired or readily found in the marketplace. It is the combination of both these sets of unique skills that can ultimately lead to the success described above in this article. The evolution of the CISO is a testament to the unique position and challenges inherent in this position. The growing influence and recognition of the CISO as a key position within the management team and the trend in organizations to create an independent line of reporting up to the board of directors is also a recognition of the growing complexity in the duties of the CISO. The CISO must think of themselves as a unicorn: a mythological creature so rare as to have thought not to exist. A CISO must view themselves as both a technical expert but also a polished corporate executive capable of navigating the challenges of the most complex business problems and communicating their solutions clearly while obtaining support from their ultimate business owners. A CISO that can identify and translate complex technical security risks to the business and can provide tactical solutions with a business-minded approach that management can understand in terms of profitability and cost can achieve the desired support and resources even if conflicts exist that appear insurmountable. Working to develop and master these dual skill-sets will ultimately result in all of the necessary resources being obtained in order to perform their duties successfully.

About the Author

David Katz is a partner at Adams and Reese. His practice encompasses privacy law and compliance, data security, data management, and data governance, vendor management, corporate governance, crisis management, regulatory compliance, and ethics. He can be reached at [email protected].

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article. The facts, opinions, and language in the article are entirely those expressed by the author and do not reflect the views of CISO MAG.

700,000 WordPress Users are at Risk Due to a Plugin Flaw

Cybercriminals Tried to Access Database Logins of 1.3 Mn WordPress Sites

Millions of WordPress sites are at cyber risk after researchers discovered a zero-day vulnerability in WordPress’s File Manager plugin. The threat intelligence team from cybersecurity firm Wordfence stated that the File Manager plugin has over 700,000 active installations, which could allow threat actors to execute commands and upload malicious files on a target site. File Manager is a plugin intended to help WordPress admins manage files on their websites. However, the researchers stated that a patch has been released to fix the vulnerability and asked users to update to the latest version 6.9 immediately.

The Vulnerability

The researchers stated that the zero-day vulnerability in the File Manager plugin could allow cybercriminals to execute arbitrary code on a WordPress site.

“While analyzing the vulnerability, we discovered that it was possible to bypass the built-in file upload protection, so we deployed an additional firewall rule for maximum coverage. Wordfence Premium customers received this new firewall rule on September 1, 2020, at 2:56 PM UTC. Free Wordfence users will receive the rule after thirty days on October 1, 2020,” the researchers said.

Threat Summary:

Description: Remote Code Execution
Affected Plugin: File Manager
Plugin Slug: wp-file-manager
Affected Versions: 6.0-6.8
CVSS Score: 10.00 (Critical)
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Patched Versions: 6.9

“The Wordfence firewall has blocked over 450,000 exploit attempts targeting this vulnerability over the past several days. We are seeing attackers attempting to inject random files, all of which appear to begin with the word “hard” or “x.” From our firewall attack data, it appears that attackers may be probing for the vulnerability with empty files and if successful, may attempt to inject a malicious file,” the researchers added.

Over 1.3 Mn WordPress Websites at Risk

Earlier, security experts discovered that cybercriminals targeted around 1.3 million WordPress websites in a single day to steal database login credentials. It is found that hackers tried to steal config files by exploiting known XSS vulnerabilities in WordPress plugins and themes. The attackers tried to download the wp-config.php WordPress configuration file, which contains connection details, authentication unique keys, and salts along with database credentials. In case attackers successfully exploited any vulnerable plugins used by the targeted sites, they could easily steal login credentials from the databases and take control over the websites.

Warner Music Group Suffered Skimming Attack for Three Months

cybercriminal, music

Popular music recording firm Warner Music Group disclosed a security incident in which unknown threat actors compromised a number of its  U.S.-based e-commerce websites and stole customers’ personal information. In a security alert, the company stated that attackers planted a skimming code into the websites’ checkout pages to exfiltrate payment information entered by the visitors.

Prolonged Skimming Attack

Attackers were able to access users’ data for a prolonged period of three months. The information exposed in the incident includes names, email addresses, contact details, billing addresses, shipping addresses, credit card numbers, card expiration dates, and CVV codes.

“Any personal information you entered into one or more of the affected websites between April 25, 2020 and August 5, 2020, after placing an item in your shopping cart was potentially acquired by the unauthorized third-party. While we cannot definitively confirm that your personal information was affected, it is possible that it might have been as your transactions occurred during the period of compromise. If it was, this might have exposed you to a risk of fraudulent transactions being carried out using your details,” Warner Music Group said.

While it is unclear what amount of personal information was affected in the incident, the company stated that the transactions that occurred during the period of compromise might be exposed to cyber risks.

Appeal to the Affected

Warner Music Group stated that it has taken down the affected e-commerce sites temporarily and urged customers to be vigilant for any unauthorized use of their payment card data or any suspicious emails.

Upon discovering the incident, we immediately launched a thorough forensic investigation with the assistance of leading outside cybersecurity experts and promptly took steps to address and correct the issue. We also notified the relevant credit card providers as well as law enforcement, with whom we continue to cooperate,” the company added.

ACSC’s First Annual Cyber Threat Report Records 59,806 Cybercrimes in One Year

Remote Access Scams

The Australian Cyber Security Centre (ACSC) recorded 59,806 cybercriminal complaints in the past 12 months (From July 2019 to June 2020) and responded to 2,266 legitimate ones at an average of 164 reports per day, or one report every 10 minutes. The First Annual Cyber Threat Report was jointly produced by the ACSC, the Australian Criminal Intelligence Commission (ACIC) and the Australian Federal Police (AFP). The report underlines Australia’s growing concerns about the frequency, scale, and sophistication of cyberthreats targeted at its digital and now critical infrastructure.

 Key Highlights 

  • ACSC recorded 59,806 cybercriminal complaints in the past 12 months beginning from July 2019 to June 2020.
  • It responded to 2,266 legitimate complaints.
  • Two notable spikes were observed in October 2019 and April 2020.
  • The month of April saw the highest spike (318 instances) in cybersecurity incidents, whereas the government sector saw the highest number of incidents (803) in the reporting period.
  • The most common type of cybersecurity incidents ware “Phishing” and “Spearphishing” attacks (27%).

The ACSCs First Annual Cyber Threat Report

A recent survey from the Australian Competition and Consumer Commission (ACCC) revealed that Australians lost over $634 million to scams in 2019 alone which was a 30% increase compared to $489 million in 2018. While ACSC believes that the true cost of cybercrime to the Australian economy is difficult to gauge, it certainly considers cybercrime as one of the most pervasive threats to the country, and the most significant in terms of the overall volume and impact to individuals and businesses.

Overall, the Australian government aims to address these brewing threats and thus asked ACSC to come up with an indicative study that would suffice individuals and businesses to draw mitigation measures. Thus, was born the first unclassified ACSC Annual Cyber Threat Report 2020.

ACSC-Annual-Cyber-Threat-Report
Image Credit: ACSC Annual Cyber Threat Report

During the reporting period, there were two notable spikes in October 2019 and April 2020. As per the ACSC, the first spike corresponds to a wave of Emotet malware campaign and the second in April 2020, was a COVID-19-themed cybercrime. The ACSC makes a special mention of the COVID-19-based cybercrime activity because it is here that it saw a rapid increase in the phishing and spearphishing attacks that account to nearly a quarter (27%) of the total incidents in the past 12 months.

ACSC Annual Cyber Threat Report

Of all the sectors that were studied during the analysis, the government sector saw the highest number of incidents (803) in the reporting period. The ACSC states, “The comparatively higher volume of reports from Commonwealth, State and Territory Governments is due to their close working relationship with the ACSC and their willingness to report incidents.” However, Australia’s critical infrastructure sectors including electricity, water, health, communications, and education, were closely followed by the government sector, accounted for 35% of the incidents responded to by the ACSC.

Australia to Boost Cybersecurity

With the evident surge in cybercrime the Australian Prime Minister, Scott Morrison, recently announced that the country is spending AU$1.66 billion (US$1.19 billion) over the next decade to bolster the cybersecurity defenses for enterprises. Morrison stated, “The increased security investment is aimed to fortify critical infrastructure, boost police efforts to disrupt malicious activities on the dark web and strengthen community awareness on security.”

Reverberating Morrison’s words, Australia’s Defence Minister Linda Reynolds, stated, “The alarming ‘new normal’ of persistent cyberattacks on Australia is blurring the difference between ‘peace and war’. We are now facing an environment where cyber-enabled activities have the potential to drive disinformation and directly support interference in our economy, interference in our political system, and also in what we see as critical infrastructure.”

Apart from the numbers related to the cyberattacks, the ACSC also shared a few useful mitigation steps to help businesses and individuals up their cybersecurity game. Learn more here.