Home Blog Page 173

Online Education at Risk! DDoS Attacks on E-Learning Platforms Increase by 550%

DDoS Attacks

With organizations across the world continuing their operations remotely, opportunistic cybercriminals are taking advantage of this situation by targeting online e-learning platforms. Hackers have set their sight on the education industry with various kinds of phishing attacks, fake domains, and other malicious activities. A survey from Kaspersky revealed that there has been a surge in distributed denial-of-service (DDoS) attacks on online educational services in 2020, compared to 2019. In a DDoS attack, threat actors try to make a targeted system or service unavailable to its users by flooding with unwanted incoming traffic from different sources.

Kaspersky’s researchers discovered that the total number of DDoS attacks increased by 80% in the Q1 of 2020, compared to Q1 2019. Between January and June 2020, the number of DDoS attacks affecting educational services increased by 350%, compared to the corresponding months in 2019, with the largest rise reported in January 2020, by 550%.

Key Findings

  • For each month from February to June, the number of DDoS attacks that affected educational resources out of the total number of attacks was 350-500% greater in 2020 than in the corresponding month in 2019.
  • From January to June 2020, the total number of unique users that encountered various threats distributed under the guise of popular online learning platforms/video conferencing applications was 168,550, a 20,455% increase when compared to the same period for 2019.
  • From January to June 2020, the platform most used as a lure was Zoom, with 5% of the users that encountered various threats encountering them via files that contained the name Zoom. The second most common platform used as a lure was Moodle, followed by Google Classroom, Coursera, Google Meet, Blackboard, and edX.
  • By far the most common threats encountered in 2020 were downloaders and adware, which were encountered in 98.77% of the total registered infection attempts. Various classes of trojans followed adware.
  • For threats distributed under the guise of popular platforms for conducting online classes in 2020, the greatest number of infection attempts registered came from Russia (21%) followed by Germany (21.25%), Austria (1.44%), Italy (1%), and Brazil (1%).

“As long as online learning continues to grow in popularity, cybercriminals will attempt to exploit this fact for their own gain. That means educational organizations will continue to face a growing number of cyber risks – into this fall and beyond. Fortunately, engaging – and secure – online academic experiences are possible. Educational institutions just need to review their cybersecurity programs and adopt appropriate measures to better secure their online learning environments and resources,” Kaspersky said.

Cyberattacks Reported on E-Learning Platforms

In the recent past, hackers targeted multiple e-learning portals to steal users’ personal information. India-based online learning platform Unacademy also suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe.

Vaccine Released Against Phishing, Vishing, Smishing, and Identity Compromises

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

Have you ever responded to an unsolicited email from a barrister located in Western Africa who, out of the blue, contacted you? For some inexplicable reason, he saw you as a kind and generous person who undeniably deserved his late client’s inheritance of millions of British Pounds. Well, I have! I just wanted to see what the scam was about. After a couple of email exchanges during which I received photos of the recently deceased client–always dressed in the same clothes, including in the framed photo that was clumsily photoshopped and pasted on top of a casket–I was asked to send $500 via Western Union to Nigeria to pay for the paperwork and get the process started…

By Nick Roquefort-Villeneuve, Director of Marketing at 1Kosmos

Phishing, Vishing, and Smishing in a Nutshell

The Nigerian inheritance email is a prime example of a phishing attack. And along with technological advances, other types of attacks have appeared in recent years, such as vishing and smishing. Let’s take a quick look at what they are:

  • Phishing is a type of social engineering attack used to steal user data, which includes login credentials and credit card numbers, for example. Phishing happens when an ill-intentioned individual, posing as a trusted entity, dupes a victim into opening an email, instant message, or text message.
  • Vishing is similar to phishing, except the criminal tries to gain information over the phone. If you want to see an example of vishing and spend a lovely time with your family this weekend, watch the movie “Identity Thief” starring Melissa McCarthy and Jason Bateman.
  • Finally, smishing is short for SMS Phishing. Hackers send bogus links via text instead of email.

All of the above attacks are designed to compromise essentially 5 types of data: credentials (passwords, usernames, pin numbers), personal data (name, address, email address), internal data (sales projections, product roadmaps), medical (treatment information, insurance claims) and bank (account numbers, credit card information).

The Consequences of Phishing, Vishing, and Smishing Attacks

Now, a few staggering statistics:

  • 1 in every 99 emails is a phishing attack (Check Point Research)
  • 32% of data breaches involve phishing (Verizon Data Breach Investigations Report)
  • 29% of data breaches involve the use of stolen credentials (Verizon Data Breach Investigations Report)
  • 64% of organizations have experienced a phishing attack in the past year (Check Point Research)
  • 22% of organizations list phishing as their greatest security threat (EY Global Information)

The average cost per compromised record is $150 (Per IBM’s Cost of a Data Breach Report). Reportedly, 5.2 million records were stolen in Marriott’s most recent breach, so allow me to do the math for you: a potential cost of $780 million.  In fairness, no one is immune to a data breach. The average breach costs businesses $3.92 million. The costs can be broken down into several different categories, including loss of productivity, damaged reputation, direct monetary loss, compliance fines, etc.

Is there a remedy or better, a vaccine, against these forms of cyberattacks?

The Vaccine to Protect Against Phishing, Vishing, and Smishing Attacks

With regard to users’ authentication, there is a vaccine of sorts, and it leverages advanced biometrics as well as Blockchain technology. 1Kosmos BlockID is the next-generation contact-free authentication solution that goes far beyond what 2FA, MFA and most passwordless applications on the market have to offer. The company’s platform is built on three pillars: Enrollment, authentication, and verifiable credentials. The goal is to always focus on ID proofing, which is the irrefutable approach that is used to verify and authenticate the identity of an employee or a customer who accesses a system or application.

Enrollment Process

The enrollment of employees and customers in the BlockID mobile app consists of triangulating a given claim (ID photo, address, last name, etc.) with a multitude of company or government-issued documents (driver’s license, passport, etc.) as well as sources of truth (AAMVA, State Department, passport’s issuing country, passport chip, credit cards, bank account, etc.), including biometrics like a liveness test. The liveness test is performed to verify if the biometric traits of an individual are from a living person rather than an artificial or lifeless person. This biometric feature is essential because, ultimately, facial spoofing which is the task of creating false facial verification by using a photo, video, mask, or a different substitute for an authorized person’s face is not too difficult if someone really wants to impersonate you. BlockID’s enrollment reaches the highest level of identity assurance per the NIST 800-63-3 guidelines, or IAL3.

Authentication Process

The biometric identifier BlockID leverages for authentication is a liveness test. Each time a user needs to authenticate to access a critical system or transact financially, he or she performs a liveness test. If it doesn’t match the liveness test performed during the enrollment process, the authentication fails. Moreover, a liveness test offers the added benefit of requiring users to capture a live video of themselves, which has a frightening effect on criminals who’d rather not share their face with the company they are targeting. BlockID’s authentication process reaches the highest level of authentication assurance per the NIST 800-63-3 guidelines, or AAL3.

Verification Process

The verification process leverages the attributes BlockID triangulates during the enrollment phase as well as verifiable credentials in their digital form. Verifiable credentials are tamper-evident credentials that have authorship that can be cryptographically verified. Users can share them through API calls with third parties and with explicit consent. Thus, the BlockID verification process eliminates all tedious back-and-forth communication between verifiers and issuers, since the verifier no longer has to contact the issuer to confirm the credential, thus eliminating data verification costs in the process. Our verification process is fully W3C compliant. It means that the digital credentials we leverage respond to a specific standard and format and go through a secure and vetted verification process, so they can’t be shared or leveraged to commit fraud. Moreover, they respect a robust privacy strategy, so they can comply with regulatory requirements across legal jurisdictions. Finally, the attestations that verifiable credentials make are backed by the Decentralized Identifiers (DIDs), a technology that enables verifiable, decentralized digital identity.

Lastly, BlockID’s distributed ledger technology stores users’ data encrypted and creates a permanent, immutable record that is invulnerable to tampering.

3 Main Benefits to Conclude…

BlockID creates a paradigm shift in the passwordless industry by bringing 3 main benefits:

  • BlockID proofs the identity of an organization’s employees and customers. In other words, the organization can be certain that its employees and customers are who they say they are… Always. Indeed, the levels of identity and authentication assurance per the NIST 800-63-3 guidelines that BlockID reaches simply make impersonation impossible and giving away or sharing purposely credentials a worthless enterprise.
  • The costs of deploying 2FA and MFA solutions that require hardware is eliminated. So is the cost of installing biometrics stations throughout a facility for fingerprint or iris recognition, for example. BlockID is an app installed on the user’s smartphone that gives physical and logical access to whoever authenticates successfully.
  • Distributed ledger technology is immune to hacking. Therefore, the potentiality of a data breach is eliminated. This is why BlockID leverages this technology to securely store users’ identity information encrypted, with access controlled by the user (GDPR compliant).

About the Author

Nicolas Roquefort-VilleneuveNicolas Roquefort-Villeneuve, a French and American bi-national, is the Director of Marketing at 1Kosmos. He is an influential technology and communication marketing executive and an entrepreneur at heart. Roquefort-Villeneuve has 22 years of marketing experience with Fortune 100 companies (Mattel, E*Trade), startups, and as an independent consultant. He is also an award-winning documentary filmmaker. In the last three years, Roquefort-Villeneuve has become an expert in marketing new technologies such as Blockchain. He has earned an MSc in Econometrics from the Université Paris 1 and an MBA from the University of San Francisco.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article. The facts, opinions, and language in the article are entirely those expressed by the author and do not reflect the views of CISO MAG.

Another Web Skimming Attack! Hackers Use Telegram to Pilfer Card Data

Skimming-Attack

Cybercriminals constantly adopt new attack techniques to implement their malicious activities. Recently, Magecart attackers implemented a new web skimming technique by leveraging the popular messaging app Telegram to pilfer card data.

Telegram-Based Skimming Attack

According to Malwarebytes, hackers exploited the Telegram app to send stolen payment details from compromised websites. They used the messaging platform to exfiltrate sensitive data by deploying skimmer codes and traditional Trojans.

“The fraudulent data exchange is conducted via Telegram’s API, which posts payment details into a chat channel. That data was previously encrypted to make identification more difficult. For threat actors, this data exfiltration mechanism is efficient and does not require them to keep up infrastructure that could be taken down or blocked by defenders. They can even receive a notification in real time for each new victim, helping them quickly monetize the stolen cards in underground markets,” Malwarebytes said.

Image Source: Malwarebytes

According to the security researcher AffableKraut — who is the first to disclose the incident in a Twitter thread — the skimmer code checks for web debuggers to evade security detection and looks for sensitive data fields like billing, payment details, credit card number, expiration, and CVV.

Injecting e-skimmers or malicious JavaScript on e-commerce sites to pilfer payment card details is a common technique used by Magecart operators. But this time, they used a new method to exfiltrate data through a message sent to a Telegram channel using an encoded bot ID in the skimmer code.

“Defending against this variant of a skimming attack is a little more tricky since it relies on a legitimate communication service. One could obviously block all connections to Telegram at the network level, but attackers could easily switch to another provider or platform (as they have done before) and still get away with it,” Malwarebytes added.

Facebook’s VDP: A Step Towards Improved Vulnerability Tracking

Facebook Takes Down Hundreds of Fake Accounts Under Coordinated Inauthentic Behavior

Facebook has often been criticized for its non-disclosures across various verticals and policies. However, now it seems that Facebook is finally correcting itself by means of adopting its first Vulnerability Disclosure Policy (VDP). This VDP has been specifically designed for vulnerability reporting of third-party code and systems. Unpatched third-party vulnerabilities often directly or indirectly impact Facebook’s overall performance and security. Thus, it is one of Facebook’s top priorities to get this fixed and the VDP takes care of this.

Facebook’s Vulnerability Disclosure Policy in a Nutshell

The idea behind this policy comes from Facebook’s ideology that “not all bugs are equally sensitive” and “fixing an issue requires close collaboration between researchers at Facebook reporting the issue and the third-party (engineers) responsible for fixing it”.

Facebook said that it will contact the concerned third-party with any security issue that their researchers have found, to which the third-party is obligated to respond within the next 21 days. The response must include the mitigation steps being taken to fix the issue and the security of the impacted people. If the third-party fails to respond within 21 days, the social media giant would reserve the right to disclose the said vulnerability on a public forum so that affected people can take necessary actions.

Similarly, even after the receipt of response, if the third-party fails to fix the vulnerability within the next 90 days, Facebook would again reserve the right to go public about the vulnerability. Facebook, however, also takes into consideration that certain vulnerabilities can take a longer period to be sorted and hence, there could be “some deviations from the actual timeline,” but this change is solely at their disposal.

Facebook’s Other Baby

Facebook’s other company, WhatsApp, also got itself a new channel to publish its security updates. WhatsApp Security Advisories is a directory designed to increase transparency by providing information on all the vulnerabilities addressed in the messaging service provider’s mobile and web applications. This page displays a comprehensive list of WhatsApp security updates and associated Common Vulnerabilities and Exposures (CVEs).

CISA’s VDP

Coincidentally, just a couple of days ago CISA issued directives to government agencies for implementing VDP at the earliest. It has acknowledged that this form of security is for the “public good” and thus stands strongest when the “good faith” security researchers and various governmental organizations collaborate in fortifying the defenses. However, the basis of this can only be laid on the strong foundation of a formal policy that helps finding and reporting of vulnerabilities in a legally authorized manner. Thus, to ease this process for the researchers, CISA recommends VDP to be defined across governmental agencies.

Massive Data Breach! View Media’s Unsecured Database Exposes 38 Mn User Records

106 million Thailand visitors

Online marketing company View Media’s unsecured database, which held 38 million U.S. users’ data, was recently exposed online. According to researchers from CyberNews, the database was hosted on a misconfigured Amazon Web Services (AWS) server, allowing anyone to access users’ personal data like full names, email addresses, residence details, phone numbers, and ZIP codes.

Data Breach Threat

The leaky server contained 5,302 files, including 700 statement of work documents stored in PDF files and 59 CSV and XLS files that contained 38,765,297 records of the U.S. citizens. In addition, the bucket contained tens of thousands of various marketing files like banner advertisements, newsletters, and promotional flyers.

Though the leaky database is now secured, it is unclear whether any threat actors have accessed the data before.

The Aftereffects

Even though the data in the unsecured server did not contain sensitive or financial information like social security numbers (SSNs) or credit card details, hackers can still make use of the available personal details for various malicious activities.

“Scammers can use the names, email addresses, and phone numbers of the exposed people for a wide variety of fraudulent schemes. Simple contact details can be enough for spammers and phishers to launch targeted attacks against 38+ million exposed Americans from multiple angles, such as robocalls, text messages, emails, and social engineering campaigns. Determined cybercriminals can combine the data found in this bucket with other data breaches to build profiles of potential targets for identity theft,” the researchers said.

Increasing Misconfigurations

A cloud security survey by cybersecurity firm Sophos revealed that 70% of organizations suffered at least one public cloud security breach in 2019, with misconfigurations exploited in 66% of reported attacks. The survey report titled “The State of Cloud Security 2020” stated that 50% of organizations that use multi-cloud environments are more likely to suffer a cloud security incident than those using a single cloud. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only 1 in 4 respondents stated lack of staff expertise as a top concern.

Australia Introduces “Code of Practice” for All IoT Devices

IoT attacks

The number of IoT devices like smart TVs and home assistants getting connected over the internet is scaling by the day, and so are the potential threats and malicious cyber activity associated with them. Thus, to address these concerns, Australia has introduced the “Code of Practice,” which is a basic cybersecurity standard for all IoT devices in the country.

The Need for “Code of Practice” Cybersecurity Standard

In 2019, the number of active IoT devices connected to the internet globally was merely 7.6 billion. However, a research from Transforma Insights suggests that this number will stand tall at nearly 24.1 billion by 2030, thereby generating a revenue of more than $1.5 trillion, at 11% CAGR.

Australia has been counted as a digitally advanced country and its digital security standards have been regarded as few of the best. A testimony to this is the fact that a study on global comparison of cybersecurity defenses ranked Australia as the world’s 15th most secure country. It jumped 12 spots in this ranking from the previous year, which shows their continuous commitment towards raising the bar for cybersecurity standards.

However, until now there were no guidelines or security standards defined for the IoT devices in the country. Many of these devices are developed with functionality as a priority, and not security. Cybersecurity of these devices is often absent or an afterthought. Thus, to change this purview and improve the cybersecurity quotient of the IoT devices in Australia, the Department of Home Affairs, in partnership with the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), has developed and introduced the “Code of Practice.”

The 13 Principles of the “Code of Practice”

The ACSC has defined 13 cybersecurity principles for consumer IoT devices, as per the global industry standards, needs of Australian people, and other applicable compliances. They are:

  1. No duplicated default or weak passwords.
  2. Implement a vulnerability disclosure policy.
  3. Keep software securely updated.
  4. Securely store credentials.
  5. Ensure that personal data is protected.
  6. Minimize exposed attack surfaces.
  7. Ensure communication security.
  8. Ensure software integrity.
  9. Make systems resilient to outages.
  10. Monitor system telemetry data.
  11. Make it easy for consumers to delete personal data.
  12. Make installation and maintenance of devices easy.
  13. Validate input data.

In addition to this, the ACSC has also released tips for consumers to secure their personal IoT devices.

Europe was the First in Line

This is not the first time that a country has implemented cybersecurity standards for IoT devices. Earlier, in June 2020, the European Telecommunications Standards Institute (ETSI) launched a new cybersecurity standard – ETSI EN 303 645 – to establish a cybersecurity baseline for all consumer IoT devices. Apart from the 13 cybersecurity measures provided in this standard and already defined GDPR compliance policies for data protection, the ETSI EN 303 645 standard also provides five specific data protection provisions for consumer IoT devices.

Proofpoint And CyberArk Extend Partnership to Mitigate Cyberattacks

Abnormal Security Partners with Microsoft to Boost Cybersecurity

Enterprise cybersecurity and compliance company Proofpoint announced that it is extending its partnership with CyberArk, a company offering privileged account security. The alliance integrates Proofpoint’s targeted attack protection platform with CyberArk’s privileged access security solutions to help organizations identify their Very Attacked People (VAP) and deploy additional security policies to remediate attacks against privileged users and high-risk assets.

With the new partnership, global organizations can now use a combination of Proofpoint’s Targeted Attack Protection (TAP) and CyberArk’s Privileged Access Security to identify and manage privileged access and revoke privileged access for potentially compromised users.

CyberArk provides privileged access management services globally. It offers enterprises a critical layer of IT security to protect their critical data, infrastructure, and digital assets on-premises, in the cloud, and throughout the DevOps pipeline. With an integrated suite of cloud-based solutions, Proofpoint helps global companies to prevent targeted threats, safeguard their data, and make their users more resilient against cyberattacks.

Bhagwat Swaroop, Executive Vice President of Industry Solutions and Business Development for Proofpoint, said, “Threat actors are exceptionally adept at targeting individuals with privileged access to extremely sensitive data — and organizations need the ability to seamlessly protect those users, across their ecosystem of security solutions.”

Adam Bosnian, Executive Vice President of Global Business Development at CyberArk, said, “Privileged users are just as vulnerable to email-based cyberattacks as anyone in an organization, however the systems and environments they manage are so critical to the business that a breach can be devastating. With Proofpoint Targeted Attack Prevention feeding information to CyberArk about ‘very attacked’ privileged users in an organization, we can immediately — and automatically — apply remediation measures to help stop targeted threats before they can reach their intended destination.”

Ad Scams Deliver a Bitter Pill to TikTok

TikTok Security Vulnerabilities Could Expose User Data, tiktok, tiktok child data mishandling

The problems for the popular short-video app TikTok don’t seem to subside. After facing a complete ban in India and an impending ban in countries like the U.S. and New Zealand, TikTok is in the soup again over concerns surrounding scammers purchasing ads to promote fake mobile apps, diet pills, and other bogus products and services. According to a recent research by Tenable, TikTok’s popular ‘#ForYou’ page has become a habitat for ad scams.

Satnam Narang, Staff Research Engineer at Tenable, listed four ways scammers are exploiting the TikTok ad network. These include:

  • Easy money offers claims to help users earn money by downloading applications that are either deceitful or questionable in nature. These advertisements promote fake apps, lure users into potential pyramid schemes, request personally identifiable information and, in some cases, encourage users to install mobile device management tools that make it easy to take over users’ devices.
iMoney: The hidden interface behind several apps, including Super Expense. Photo Courtesy: Tenable
  • “Free” offers that come with a price, such as free diet pills ads use fake celebrity endorsements and news articles to dupe users into providing credit card details in exchange for “free” goods, subjecting unsuspecting users to recurring subscription fees.
Fake articles promoting diet pills using the CNN News logo and false claims from notable figures. Photo Courtesy: Tenable
  • Dropshipping schemes promote questionable or extremely overpriced goods offered by dropshipping. While dropshipping itself isn’t necessarily a scam, these offers are problematic when they involve price gouging, counterfeit or questionable goods, or duping buyers into paying for goods they never receive.
Examples of TikTok advertisements promoting dropshipped goods. Photo Courtesy: Tenable
  • Dodgy credit and tuition assistance offers prey on those in dire financial straits by promising to repair credit card history or promoting online classes as a way to access financial aid. In many cases, these ads are merely a ruse to entice users to pay for bogus services or share their personally identifiable information.
TikTok advertisements promoting credit repair using videos of notable celebrities and figures who have no part in the business whatsoever. Photo Courtesy: Tenable

According to Narang, a surge in popularity brings with it challenges toward content moderation and combating abuse, and TikTok is also facing a similar predicament, “which is why it is important for ByteDance — and any new U.S. owner — to prioritize up leveling the app’s content moderation and abuse team in order to curtail these types of questionable ad practices,” he noted, while adding that there is ample room for improvement.

“For users of TikTok, it’s important to recognize that scammers are opportunistic individuals. Scammers see users as a means to an end – the goal is to prey on consumer insecurities and desires to earn fast money, get a good deal on a hot product, lose weight without working out or relieve credit card debt. While we all wish it weren’t so, the reality is there’s no easy way to accomplish these things. TikTok users would do well to be skeptical of many of the advertisements on the platform, because at the end of the day, they’re not always what they appear to be,” Narang concluded.

Tenable also shared its elaborate findings with Amazon, Apple, Facebook, and TikTok. Following which Apple removed iMoney from its App Store. While TikTok has stated that it will “direct this to the right person on our team to review.”

With a major chunk of its user-base under the age 14, the ad scam fiasco for TikTok would be another bitter pill to swallow. Earlier this year, South Korean telecommunication watchdog, Korea Communications Commission (KCC), found TikTok guilty of mishandling child data in the country and thus imposed a 186 million won (i.e. approximately US$155,000) fine.  In February 2020, the company settled with the FTC by agreeing to pay a $5.7 million fine for failing to adhere to the Children’s Online Privacy Protection Act (COPPA). Back then, this was the largest civil penalty ever obtained by FTC in a children’s privacy case.

4 in 10 Companies Expose Unsafe Network Services Online

4 in 10 Companies Expose Unsafe Network Services Online, network and security

A joint research by cyber risk management firm RiskRecon and the cybersecurity research firm Cyentia Institute revealed that a large number of organizations leave their unsecure network services open online, exposing their critical data to risks. According to the research, “Third-Party Security Signals: Exposing the reality of unsafe network services,” nearly 33% of enterprises in the digital supply chain expose unsafe network services like data storage, remote access, and network administration to the internet.

 Key Findings 

  • Within the top three unsafe network services, data stores, such as S3 buckets and MySQL databases are the most exposed.
  • Remote access is the second most exposed service; admins should consider restricting the accessibility of these services only to authorized and internal users.
  • Universities are woefully exposed. With a culture that boasts open access to information and collaboration, the education sector has the greatest tendency to expose unsafe network services on non-student systems, with 51.9% of universities running unsafe services.
  • Global regions lack proper security posture. Countries such as the Ukraine, Indonesia, Bulgaria, Mexico and Poland confirm the highest rate of domestically hosted systems running unsafe services.
  • Beware of ElasticSearch and MongoDB. Firms that expose these services to the internet have a 4x to 5x higher rate of severe security findings than those who do not run on internet-facing hosts.
  • Unsafe services uncover other security issues. Failing to patch software and implement web encryption are two of the most prevalent security findings associated with unsafe services.

The findings are based on the evaluation of millions of internet-facing systems across 40,000 commercial and public institutions. Cyentia and RiskRecon analyzed the data in two strategic ways: the direct proportion of internet-facing hosts running unsafe services and the number of organizations exposing unsafe services somewhere across their infrastructure.

Kelly White, CEO and co-founder at RiskRecon said, “Blocking internet access to unsafe network services is one of the most basic security hygiene practices. The fact that one-third of companies in the digital supply chain are failing at one of the most basic cybersecurity practices should serve as a wakeup call to executives and third-party risk management teams. We have a long way to go in hardening the infrastructure that we all depend on to safely operate our businesses and protect consumer data. Risk managers will be well served to leverage objective data to better understand and act on their third-party risk.”

Jay Jacobs, partner and Co-founder, Cyentia Institute, said, “Similar to how medical doctors diagnose illnesses through various outward signs exhibited by their patients, third-party risk programs can perform quick, reliable diagnostics to identify underlying cybersecurity ailments. Not only is the presence of unsafe network services a problem, but the data we examine in this report also shows that they are a symptom of broader problems. Easy, reliable risk like this offers a rare quick win for risk assessments.”

CISA Trusts “Good Faith” Security Researchers; Issues VDP Directive

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

Cybersecurity has been a growing concern in the U.S. since the time tensions between the former and China have escalated. In such a scenario, CISA has acknowledged that this form of virtual security is for the “public good” and thus stands strongest when the “good faith” security researchers and various governmental organizations collaborate in this fight. However, the basis of this can only be laid on the strong foundation of a formal policy that helps finding and reporting of vulnerabilities in a legally authorized manner. Thus, to ease this process for the researchers, CISA recommends vulnerability disclosure policies (VDP) to be defined across governmental agencies.

What is Vulnerability Disclosure Policy?

Currently, most governmental agencies lack a formal mechanism to receive information from security researchers or white-hat hackers about potential security vulnerabilities on their systems. In the draft directive issued by CISA, it clearly states, “Only a few agencies have clearly stated that those who disclose vulnerabilities in good faith are authorized.” The vulnerability disclosure policy changes this. It makes agencies publish policies with detailed descriptions of which systems are in scope, the types of testing that are allowed, and how security researchers can submit vulnerability reports. These policies also cover all internet-accessible systems or services in government agencies – including systems that were not intentionally made internet-accessible.

The VDP also forces all agencies to maintain a tracking mechanism for all vulnerability lifecycles. There would be complete transparency of which phase the vulnerability is in and what measures are being taken to plug it.

The Bug Bounty Consideration

As per the memo sent from the White House, a coordinated vulnerability disclosure (CVD) consists of two components, first VDP and second bug bounty. However, the Office of Management and Budget (OMB) defines the latter as an optional resource. It says, “Federal agencies can leverage a bug bounty as an incentive focused tool to identify vulnerabilities. This type of program, although not required, should be considered in the greater context of an agency’s enterprise risk management program. Federal agencies are encouraged to consider the use of bug bounty programs.”

The recommendations in the directives issued are clear, but it will be interesting to see the timeline for its complete implementation as this is a coordinated framework and involves all federal and governmental agencies.