Home Blog Page 174

NCSC Releases Cybersecurity Guidelines with International Allies

Avaddon ransomware, Microsoft and Fortinet flaws, apt

The U.K.’s National Cyber Security Centre (NCSC) joined hands with international cybersecurity agencies from five countries to issue security guidelines that intend to help organizations globally in disclosing data breaches and handling threat actors. The joint security advisory “Technical Approaches to Uncovering and Remediating Malicious Activity” is released in cooperation with the U.S.’s Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre, the New Zealand National Cyber Security Centre and CERT NZ, and the Canadian Communications Security Establishment.

“The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation,” the advisory said.

The advisory revealed the technical approaches for organizations when addressing potential security incidents and includes certain mitigation steps.

Common missteps to avoid when responding to a security incident:

  • Mitigating the affected systems before responders can protect and recover data.
  • Touching adversary infrastructure (Pinging, NSlookup, Browsing, etc.).
  • Preemptively blocking adversary infrastructure.
  • Preemptive credential resets.
  • Failure to preserve or collect log data that could be critical to identifying access to the compromised systems.
  • Communicating over the same network as the incident response is being conducted (ensure all communications are held out-of-band).
  • Only fixing the symptoms, not the root cause.

Mitigations

The advisory also recommended certain practices for organizations to mitigate potential threats to their network. These include:

  • The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/file transfer and remote access services.
  • Restrict or Discontinue Use of Non-approved VPN Services.
  • Shut down or Decommission Unused Services and Systems.
  • Quarantine and Reimage Compromised Hosts.
  • Disable Unnecessary Ports, Protocols, and Services.
  • Restrict or Disable Interactive Login for Service Accounts.
  • Disable Unnecessary Remote Network Administration Tools.
  • Manage Unsecure Remote Desktop Services.
  • Credential Reset and Access Policy Review.

NCSC Director of Operations Paul Chichester said, “Cybersecurity is a global issue that requires a collaborative international effort to protect our most critical assets. This advisory will help organizations understand how to investigate cyber incidents and protect themselves online, and we would urge them to follow the guidance carefully. Working closely with our allies, and with the help of organizations and the wider public, we will continue to strengthen our defenses to make us the hardest possible target for our adversaries.”

CISA Director Chris Krebs said, “With our allied cybersecurity government partners, we work together every day to help improve and strengthen the cybersecurity of organizations and sectors of our economy that are increasingly targeted by criminals and nation states alike. Fortunately, there’s strength in numbers and this unified approach to combining our experiences with a range of malicious actors means that we’re able to extend our defensive umbrella on a global scale.”

75% of CEOs Will be Personally Liable for Cyberattacks by 2024: Gartner

active directory
active directory

Research and advisory firm Gartner estimated that nearly 75% of CEOs will be personally liable for the financial impact due to the growing Cyber-Physical System (CPS) attacks by 2024. In its report, Gartner stated that CPS security incidents can lead to physical damage to people and destruction of assets in a rapid space, and environmental disasters. It also predicted that CPS incidents will increase in the coming years due to lack of focus and investment in cybersecurity.

What is Cyber-Physical System?

A cyber-physical system is a computer system in which a mechanism is controlled by a computer-based algorithm. CPSs are engineered to orchestrate sensing, computation, control, networking, and analytics to communicate with the physical world.

“Cyber-physical systems underpin all connected IT, operational technology (OT) and Internet of Things (IoT) efforts where security considerations span both the cyber and physical worlds, such as asset-intensive, critical infrastructure and clinical health care environments,” Gartner said.

According to Gartner, the financial loss due to CPS attacks will reach over $50 billion by 2023. In addition, the costs to organizations in terms of compensation, litigation, insurance, and regulatory fines will be higher.

Katell Thielemann, Research Vice President at Gartner said, “Regulators and governments will react promptly to an increase in serious incidents resulting from failure to secure CPSs, drastically increasing rules and regulations governing them. In the U.S., the FBI, NSA and Cybersecurity and Infrastructure Security Agency (CISA) have already increased the frequency and details provided around threats to critical infrastructure-related systems, most of which are owned by private industry.”

Thielemann added, “Technology leaders need to help CEOs understand the risks that CPSs represent and the need to dedicate focus and budget to securing them. The more connected CPSs are, the higher the likelihood of an incident occurring. A focus on ORM – or operational resilience management, beyond information-centric cybersecurity is sorely needed.”

It is essential to note that damages in the digital world have an adverse impact in the physical world, since vulnerabilities and risk vectors exist in a cyber-physical spectrum.

Pro Tips: Things to Remember Before Leveraging IaaS for Cloud Computing

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

Cloud computing is the on-demand availability of computer system resources and computing power with no user’s direct management. To some, it’s a new way of running a business; to others, it’s a way of storing data, but in reality, it’s much more than that. While there are many advantages of cloud computing for businesses, such as reduced maintenance costs, minimum capital expenditure, excellent scaling opportunities, agility, flexibility, and data recovery, there are some downsides. Depending on the cloud computing service model, security challenges differ, and so do solutions. Let’s take the IaaS service model, for example. What are some of the worst things that can happen to businesses using IaaS?

What Is Infrastructure as a Service? 

Being the most common cloud computing service model, IaaS offers the fundamental virtual servers, networking, operating systems, and data storage – on-demand to enterprises. It represents the virtual equivalent of a traditional data center. Those who decide on the IaaS service model don’t have to own any personal hardware or manage its components. It is all managed by the service provider. And they pay for it on a usage basis – with pay-as-you-go payment options. Furthermore, businesses can easily deploy their apps on IaaS. Organizations can deploy their own virtual machines, workloads, and apps on top of the hypervisor layer – in the region and availability zone of their choice. IaaS key features include an enterprise-grade infrastructure, OPEX, flexible features, ease-of-use, and virtual management. There are additional services like performance and usage monitoring, load balancing, and scaling. This makes IaaS ideal for small and medium-sized organizations that look for a cost-effective IT solution.

Security Challenges

Not a single system is entirely safe, and there will always be security issues to address. Some of the most crucial security challenges of IaaS are listed below.

Service Level Agreement (SLA) Issues

Using SLAs guarantees the acceptable level of quality of service (QoS). An SLA contains contract definition, negotiation, monitoring, and enforcement. Contract definition and negotiation are essential to determine the benefits and responsibilities of both sides. Any ambiguity in SLA will leave a client exposed to vulnerabilities since it will affect the system’s security.

Platform Virtualization Issues

This component allows for faster scaling and is one of the fundamental parts of cloud computing. Every virtual machine (VM) should remain in isolation and not have access to other virtual disks, memory, or apps on the same host. When the communication between a VM and a host happens, attackers might exploit some features and gain access to data transfers. Sysadmin could also take advantage of the position and exploit the features.

Computer Hardware Issues

The IaaS interface is stored in distributed physical resources, such as network components, CPUs, and other storage devices. Even though service providers keep the physical components in a secured area, about 70% of attacks happen within the organization. If the attacker physically reaches the machine, two things could happen, depending on their intentions:

  • Denying service by shutting the machine down.
  • Accessing the machine to steal or corrupt data.

Optimal Solutions

There are no perfect solutions to issues that might occur in evolving systems. Service providers need to do their best to keep track of new security solutions and implement them if necessary.

Service Level Agreement (SLA) Solution

To ensure the proper service and trust between the providers and clients, SLA needs to be monitored, together with QoS. Proper monitoring and enforcement of SLA could be delegated to a third party.

Platform Virtualization Solution

Since IaaS is a shared environment, it needs a precise configuration to keep the VMs isolated. Cloud service providers need to work on securing their VMs, and a Trusted Virtual Datacenter can help. TVDc solves both infrastructure and management security problems. It enforces control access schemes on the network, based on security labels and management prototype. It acts as a closed box that prevents tampering or inspecting any content that circulates.

Computer Hardware Solution

The possibility of an attacker shutting down the machine can be minimized by keeping strict control over who has access to the location. When it comes to stealing or corrupting data, the recommended solution is encryption, using both the session ID and the user’s ID for key management.

Other Disadvantages of IaaS

Other issues that happen with IaaS are provider outages, permanent data loss, the vulnerability of applications, lack of expertise. To solve these, companies must focus on staff training. Providers must ensure data and network encryption, use the Cloud Access Security Broker (CASB) tool that identifies data risks, and monitor/audit the anomalies.

Conclusion

Cloud computing is a new way of storing data and running platforms and apps. Infrastructure as a Service is one of three service models of cloud computing, and it has its advantages and disadvantages. While many businesses turn to IaaS, some tend to ignore the other side of the coin. Paying attention to the SLA will ensure both sides are satisfied while the service runs. Virtual Machines can be kept safe with control access schemes such as access control lists (ACLs). Physically located data storage should be kept secured using proper encryption keys. With the implementation of these recommended solutions, Infrastructure as a Service becomes a safe place where businesses can thrive.

EC-Council’s CISO MAG All Set to Host the 2nd Africa CISO Summit in September

2nd Africa CISO Summit

EC-Council’s CISO MAG is all set to host the 2nd edition of its Africa CISO Summit on September 17, 2020, where a vibrant mix of senior cybersecurity experts will deliver key insights on how to redefine security frameworks and efficiently mitigate business risks. Over 300 information security leaders from over 100 of the top companies in the region will grace the event.

Registrations are open here.

The event will witness a slew of discussions by Harrison Nnaji, Chief Information Security Officer at First Bank Nigeria; Justin Williams, Executive Group Information Security at MTN Group; Daniel O. Adaramola, Chief Information Security Officer (CISO) at Unity Bank; Zaid Parak, Group Chief Information Security Officer at Discovery Limited; Hassan Hafez, Head of IT at Total Egypt; Prasanna Kumar Burri, Group CIO at Dangote Industries Limited; and Abeer Khedr, Information Security Director at the National Bank of Egypt.

Despite being one of the largest hubs of cybercrime incidents, Africa has leaped forward, thanks to the cybersecurity initiatives taken by both public and private entities. The onset of COVID-19 has also brought to light the reality of evolved and disruptive cyberattacks, which needs to be addressed, thus, placing a major emphasis on the adoption of dynamic technology solutions as well as the development of a future-ready cybersecurity strategy.

With businesses now transitioning into a hyper-connected digital ecosystem and a new remote operational model, the protection of vital business data, financial operations, intellectual properties and critical infrastructure networks are the top priorities. The growing threat profile in the region demands an overhaul of the cybersecurity landscape across the distributed enterprise network to safeguard critical data, sustain enterprise-wide operations, and ensure business continuity.

To ensure the success of a sustainable and digital-first economy, cooperation between the private sector and regulatory entities, skill development, mass awareness, and investments into developing the right cybersecurity framework is crucial.

EC-Council’s CISO MAG believes that visionaries in the industry who have dedicated their lives to the cause of creating a secure cyber world will be responsible for bridging this gap. Hence, the event will address the topics that are more relevant to the cybersecurity industry in Africa like the COVID-19 cyber outlook, safeguarding the domestic business community, inclusive capacity building through the right public-private partnerships, overhauling the cybersecurity strategy to strengthen enterprise-wide defense in times of a pandemic, adopting dynamic endpoint security protocols to protect the distributed enterprise network while mitigating risks, and leveraging analytics to deploy defense-in-depth and enable agile business scalability.

To know more about the event, click here.

About CISO MAG 

CISO MAG, an EC-Council initiative, is a cybersecurity magazine delivering cutting-edge updates about the latest happenings in the cybersecurity world. It is a handbook for CISOs, CXOs, and every responsible stakeholder of secure Internet space.

Events information can be found at https://events.cisomag.com/

For more information, contact: 

Name: Deepali Mistry

Email: [email protected]

Phone: +91-9833151933

Now Trending! Hackers Lure Single Adults with Online Romance Scams

Dating Apps

The FBI is warning users to be vigilant about online romance scams, also known as confidence frauds.  In this fraud trend, cybercriminals exploit people looking for romantic partners on dating websites, apps, or social media networks. The agency noticed that the majority of the victims of romance frauds were single adults over the age of 55 in Utah, Idaho, and Montana.

The consequences of these scams are often financially and emotionally devastating to victims; they rarely get their money back and may not have the ability to recover from the financial loss.

– FBI 

 A $475 Million Scam

The FBI’s Internet Crime Complaint Center (IC3) stated that confidence frauds incurred huge financial losses to victims when compared to other cybercrimes. The IC3 received nearly 100 complaints from victims reporting more than $1 million in losses to romance scams in Idaho last year. Nearly 20,000 complaints related to romance scams were reported to IC3, with losses of more than $475 million.

Protective Measures

The FBI recommended users to follow precautionary measures before developing a romantic relationship with someone online. These include:

  • Research the person’s photo and profile using online searches to see if the material has been used elsewhere.
  • Go slow and ask questions.
  • Beware if the individual seems too perfect or quickly asks you to leave a dating service or social media site to go offline.
  • Beware if the individual attempts to isolate you from friends and family or requests.
  • Beware if the individual promises to meet in person, but then always comes up with an excuse why he or she cannot. If you have not met the person after a few months, for whatever reason, you have good reason to be suspicious.
  • Never send money to anyone you do not know personally.

Rise of Fake Dating Apps

Research from Kaspersky revealed that South Africa is one of the most malware attacked countries via fake dating applications. Nearly 7,734 attacks were detected on 2,548 users in 2019. The country saw a circulation of 1,486 malware threats disguised as over 20 popular dating apps. It is said that South Africa is the most targeted country by fake dating apps accounting to 58% while Kenya reported 10% and Nigeria 4%.

$5 Million Data Breach Suit Filed Against Morgan Stanley

American Cybersecurity Literacy Act

Morgan Stanley, a financial services provider, finds itself stuck in a data breach suit filed by one of its customers, Timothy Smith. The suit claims class action status and alleges Morgan Stanley of improper handling of historical customer data dating as early as 2016. According to Smith, Morgan Stanley failed to thoroughly dispose its data, which led to the potential exposure of his and other customers’ personally identifiable information (PII).

How it Happened

Morgan Stanley reported to the Attorney General and notified its affected customers about two separate data exposure incidents. The first took place in 2016 when Morgan Stanley shut down two of its data centers and correspondingly decommissioned the computer equipment at both locations. As per their standard operating procedure (SOP), a contracted vendor was assigned to delete and dispose all the data from these devices. However, it was later learned that some of these devices still contained historical data of some customers in an unencrypted format.

In the second incident that took place in 2019, Morgan Stanley disconnected and replaced a computer server in a local branch office. This server contained information in encrypted disks that may have had personal information. During a recent inventory check, the company authorities were unable to locate this decommissioned server. Additionally, the server manufacturer subsequently informed Morgan Stanley of a software flaw that could potentially result in small amounts of previously deleted data remaining on the disks in an unencrypted form.

What is at Risk

The IT authority at Morgan Stanley in its self-assessment found that data pertaining to customer account(s) including PII  like account names and numbers (at Morgan Stanley and any linked bank accounts), Social Security number (SSN), passport number (if mentioned), contact information, date of birth, asset value and holdings data were exposed. However, this data did not include online passwords of Morgan Stanley accounts.

What Next for Morgan Stanley

Morgan Stanley is closely monitoring the compromised accounts for any suspicious activity but has not yet detected any misuse of the exposed data. They are also providing the affected customers with a 24-months free credit and identity monitoring service, in case there is a misuse of their identity.

However, the lawsuit alleges, “PII was compromised due to Morgan Stanley’s negligent and/or careless acts and omissions and the failure to protect customers’ data. In addition to Morgan Stanley’s failure to prevent the data breach, the defendant failed to detect the data breach for years, and when they did discover the data breach, it took them over a year, possibly longer, to report it to the affected individuals and the states’ attorneys general.”

Smith also pointed out in the lawsuit that Morgan Stanley did not use reasonable security procedures and practices. They could have prevented the data breach by encrypting the data. This case does not involve a direct breach of a computer system by a third party, but rather an unauthorized disclosure of the PII. Thus, it would be interesting to see the lawmakers’ verdict on this data breach class action suit.