Home Blog Page 182

Unsecured Database Exposes 5.5 Mn Records of Multiple Organizations

Data breach in 100 U.S. cities

Inadvertent database exposure continues to be a major risk for organizations. Security professionals are concerned about their database security as employees are now working remotely. Security researchers Noam Rotem and Ran Locar from vpnMentor uncovered an unsecured AWS S3 bucket containing over 5.5 million files (around 343GB in size) exposed online.

Multiple Organizations’ Data at Risk

The researchers stated that the major data in the server belongs to a U.S.-based project management firm InMotionNow. The other organizations whose data was found in the unsecured S3 bucket include: Universities like Kent State in Ohio and Purdue in Indiana, cybersecurity firm ISC2.org, insurance company Brotherhood Mutual, Potawatomi Hotel & Casino in Milwaukee, public limited companies like Zagg & Myriad Genetics, and a non-profit organization Freedom Forum Institute.

Information Exposed

According to vpnMentor researchers, the exposed data included analytics reports, internal presentations like company strategy, annual revenue amounts, and current customer count; training materials, internal client requests like requester name, project name and details; marketing strategies and collateral, product labels; and business intelligence reports. In addition, the database also exposed email addresses and mailing lists with relevant personally identifiable information (PII) related to universities including full names, donation amounts, physical addresses, contact details, and the credentials of donors.

The leaky database was secured after vpnMentor notified all the organizations affected in the security incident.

How to Secure an Open S3 Bucket

vpnMentor researchers also recommended some basic security measures to protect the S3 bucket. These include:

  • Make the bucket private and add authentication protocols
  • Follow AWS access and authentication best practices
  • Add more layers of protection to the S3 bucket to further restrict who can access it from every point of entry

“It is important to note that open, publicly viewable S3 buckets are not a flaw of AWS. They’re usually the result of an error by the owner of the bucket,” the researchers said.

Misconfigurations Increase Data Leaks

A cloud security survey by cybersecurity firm Sophos revealed that 70% of organizations suffered at least one public cloud security breach in 2019, with misconfigurations exploited in 66% of reported attacks. The survey report titled “The State of Cloud Security 2020” stated that 50% of organizations that use multi-cloud environments are more likely to suffer a cloud security incident than those using a single cloud. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only 1 in 4 respondents stated lack of staff expertise as a top concern.

 

APAC Consumers Overlook Data Security in Favor of Seamless User Experiences

Experian API Flaw

A research from cybersecurity firm F5 revealed that 96% of users in the Asia Pacific would prefer to choose convenience or seamless application experiences over data security. The research report “Curve of Convenience 2020 Report: The Privacy-Convenience Paradox” stated that 43% of consumers expect businesses to protect their information, and 32% believe it is the government’s responsibility.

The report stressed that businesses should involve consumers in their security processes to curb cyberthreats. If users are provided with the right information, they will be more vigilant when sharing their sensitive information.

Research Highlights

  • Most Asia Pacific consumers assign security responsibilities to businesses and governments. Only 25% of respondents believe it is the users’ responsibility to protect their own data.
  • 69% of users, on average, are choosing to give up their privacy to gain better experiences. Respondents from China (82%), India (79%) and Indonesia (79%) are most willing to share their data, with respondents from Japan (43%), Australia (50%), and Singapore (58%) being the least likely to trade data for more seamless experiences.
  • Over a quarter of users are unaware of breaches. 27% of respondents indicated that they were not even aware of the breaches despite hacks that affected government bodies or high-use applications.
  • Today’s users frequently choose frictionless experiences over security, but they still expect the organizations to safeguard their data. Only 4 % of respondents stopped using an application as a result of a breach, however, their trust in an organization’s abilities to protect their data is waning across the board—with social media companies witnessing the steepest drop in trust by 19 percentage points.

Adam Judd, Senior Vice President, Asia Pacific, China, and Japan, at F5, said, “To truly integrate convenience and security, businesses should proactively involve consumers across the development of the applications, not only at the end. This is especially the case in an age where both application consumption and security vulnerabilities are multiplying by the day. Partnering with consumers means that the industry can thrive, and businesses, together with their digital partners, can create better solutions that deliver seamless yet secure experiences, any time, all the time. Ultimately, showing users what’s at stake will help them feel that they should be invested in their own protection.”

Online banking, entertainment, shopping, and food delivery applications have become primary means of accessing goods and services amid the pandemic and remote working.  It is a critical time for businesses to stay vigilant and secure their customer and organizational data.

 

Cutting the Vulnerability Noise with Context

cybersecurity

Chasing Patches

Why does 20% of hacking activity focus on vulnerabilities? Here’s why and it’s no surprise. The cycle of scanning and patching continues as it ever does. The discussion of which patches get deployed in what order ranges from friendly conversation to heated argument. There are never enough cycles to patch them all. And some systems cannot be patched because of deprecated code or critical functionality.

By Brandon Hoffman, CISO at Netenrich

Certainly, we could shift the heavy lifting of ordering and priority left, and have machines do the work. The idea of having the machines learn and crunch enough data to make decisions for us is appealing. Many smart people and vendors have worked hard on this problem for decades, yet the need for a human analyst remains too deeply embedded.

So, an organization builds a risk model and aligns it to their business. The machines are spinning away on the risk model and the data input. Yet somehow it feels that something is missing because while we all accept that there is no 100%, the damage is still not being controlled. Setting aside the technology difficulty and dependence on future improvements, there remains an opportunity to dissect the inputs to the risk model and make course corrections.

Risk Model Elements

Every organization has, or should have, a risk model that is aligned with the specifics of an organization’s business and exposure areas. Some elements of this risk model are generic or more widely applicable. These elements are commonly adopted by technology providers and include all the usual suspects such as CVSS scoring, patch availability, and assessments related to the function of the system impacted.

Furthermore is a core component of risk valuation – contextualization. Context is fundamental for any intelligence driven model, and that’s what we are really chasing……context. Some variables of context are more easily identified and remain relatively constant. Examples that are present in the vulnerability risk model include the operational area of the system, uptime requirements of the system, and the user(s) of the system.

More difficult components that require constant re-assessment include the downstream impact and accessibility of the system in question. How exposed is this system to somebody targeting it and if exploited, where can you pivot from that system? Technology providers have done a reasonably good job of creating systems that can generate this type of analysis. Technology that assesses risk exposure from the outside in and systems that calculate network paths and potential access through the network.

The final piece needed for context comes down to adversary capability, intent, and opportunity. These contextualized data points are critical inputs to any risk model, especially when considering risk to business systems and data. To evaluate capability, intent, and opportunity, you need to assess the “who”, and this analysis is what bolsters the model to create further efficiency and gains in risk reduction.

Bolstering the Model by Adding Context

The majority of attacks on business systems are driven by cybercriminals. Their motivation is the potential financial gain from selling access, data, or tools that empower other criminals. From the adversary’s perspective, they carefully consider which tools to equip themselves with for targeting specific high-value victims, but also look at it from the other angle at tools and exploits being developed against vulnerable systems that can be attacked opportunistically.

They too are considering risk against a similar model – Is there a patch, how many of these systems exist (availability and exposure of targets), what data may be present on these systems, and where are these systems generally positioned in the organization. Depending on the capability of the adversary, they may also consider if there is available exploit code, is it weaponized, and is it easy to use or re-purpose. The starting point for this perspective is from outside-in. The initial attack vector will most likely be an externally facing company asset, which provides a unique challenge and opportunity at the same time.

Analysis of the adversary perspective can be a daunting and complex task. Understanding of the attack surface available to the adversary is just the beginning. It is compounded by the difficulty to obtain the prerequisite information for interpretation of motive and intent. Creating a statistical analysis of how frequently a specific exploit is mentioned or discussed doesn’t really provide enough contextual data to satisfy this component of the risk model. The observables necessary to analyze this would cover credibility of an adversary over time (have they been successful at this), where an adversary is sharing information about an exploit (is it with the world or exclusively with other credible criminals), and most importantly the technical status/maturity of the exploit being discussed and shared. These contextual data points are the critical inputs to the risk model that can have a significant and effective impact on scoring and prioritization.

Consider a situation where there is a vulnerability on a system of low value, rated as low criticality. Understanding where that system exists and downstream access from that system is important, yes. However, if there is no observed targeting or meaningful discussion of that vulnerability by the community of adversaries who normally have the capability, intent, and opportunity to attack the system, or possibly there is only rudimentary code available to leverage that vulnerability, the criticality would remain low.

Conversely, if the people who typically perpetrate these attacks on a regular basis are having meaningful conversations and executing technology advancements to make leveraging this vulnerability more accessible, that low priority vulnerability becomes critical.

Context remains the key input to risk modeling and that context comes from a reasonably challenging combination of closed-source access, data collection and triage, and human-driven intelligence analysis.

About the Author

Brandon Hoffman is the Chief Information Security Officer (CISO) at Netenrich. He is a veteran CTO and security executive well-known for driving sales growth and IT transformation. Hoffman is responsible for Netenrich’s technical sales and security strategy for both the company and its customers. Most recently, he oversaw Intel 471’s dark web threat intelligence business. As former CTO at Lumeta Corporation and RedSeal Networks, Hoffman led technical and field development in network security, vulnerability, and risk management. He’s also held key practitioner roles in security architecture, penetration testing, networking, and data center operations. Hoffman holds a MS Degree from Northwestern University and a BS Degree from University of Illinois at Chicago.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

India Ranks Second in Drive-by Download Attacks and Cryptomining Encounter: Microsoft

Vulnerabilities in Zimbra

The drive-by download attack volume has been witnessing a steep surge since 2018, with India being the second highest in terms of volume of attacks in the Asia Pacific region. The number is nearly three times higher than the regional and global average. In fact, India, together with Hong Kong and Singapore, continued to face high drive-by download attack volume, according to findings from the latest edition of Microsoft’s “Security Endpoint Threat Report 2019.” The country moved from 11th to second highest attack volume YoY across the region. The report also asserted that cybercriminals remain focused on stealing financial information or intellectual property.

India also recorded the second highest in cryptocurrency mining encounter rate in the Asia Pacific. Even though there has been a considerable decline in the cryptocurrency mining encounter rate compared to 2018, India was still 4.6 times higher than the regional and global average. During these attacks, victims’ computers were infected with cryptocurrency mining malware, allowing criminals to leverage the computing power of their computers without their knowledge.

 Ransomware Hogs the Limelight 

With respect to ransomware attacks, the report also highlighted that the Asia Pacific continued to experience a higher-than-average encounter rate for malware and ransomware attacks – 1.6 and 1.7 times higher than the rest of the world with India continuing to rank the third-highest for ransomware attacks. This was despite a 35% and 29% decrease in malware and ransomware encounters respectively over the past year.

Drive-by download


Talking to CISO MAG about this alarming trend around ransomware, Keshav Dhakad, Group Head & Assistant General Counsel – Corporate, External & Legal Affairs, Microsoft India, said, “With the modes of attacks, cybercriminals are shifting their efforts to customized campaigns targeting specific to geographical areas, industries, and businesses.”

Drive-by-download


Countries with lowest encounter rate were Japan, New Zealand, and Australia.

In an ensuing statement, he added, “While overall cyber hygiene in India has improved, we believe there is more to be done. Typically, high malware encounters are a result of excessive usage of unlicensed and/or pirated software, and the proliferation of sites that illegitimately offer free software or content, such as video streaming. Consumer education is important – users should regularly patch and update programs and devices and be able to identify unsafe websites and illegitimate software.”

 Cybersecurity in Times of Pandemic 

COVID-19 has changed the cybersecurity landscape and remains the top-of-mind concern for individuals, organizations, and governments around the world. Ever since the onset of the pandemic, every country in the world has seen at least one COVID-19-themed attack with a continuous increase in the volume of successful attacks.

Among phishing messages seen globally each day, over 60,000 include COVID-19-related malicious attachments or malicious URLs with attackers impersonating establishments like the World Health Organization (WHO), Centers for Disease Control and Prevention (CDC), and the Department of Health.

Dhakad further explained, “Attacks have affected aid organizations, medical billing companies, manufacturing transport, government institutions, and educational software providers.”

He stated, “According to our data, we found that COVID-19 themed threats are mostly retreads of existing attacks that have been slightly altered to tie to the pandemic. This means that attackers have been pivoting their existing infrastructure, like ransomware, phishing, and other malware delivery tools, to include COVID-19 keywords, to capitalize on people’s fear. Once users click on these malicious links, attackers can infiltrate networks, steal information, and monetize their attacks.”

When asked, with COVID-19 seeing mass layoffs in several companies across the world and many of these may have been employees with privileged access. Doesn’t it pose a bigger insider threat challenge?  Dhakad responded to this question: “Zero trust has been principal for organizations. It is important that all the accesses are verified. Fortunately, technology is well advanced to easily spot the anomalies. To stress again, zero trust policy must be mandatory for every organization during these times.”

Microsoft has also issued guidance for businesses and individuals:

 Guidance for Businesses 

  • Safeguard employees with strong tools and infrastructure.
  • Turn on two-factor authentication (2FA) or multi-factor authentication (MFA) as employees work from home.
  • Include end-to-end encryption on trusted applications for audio/video calling and filesharing.
  • Guide employees on how to identify phishing attempts and distinguish between official communications and suspicious messages.

 Guidance for Individuals 

  • Update all devices with the latest security updates and ensure that an antivirus service is included.
  • Watch out for malicious or compromised websites and avoid pirated content.
  • Recognize and report suspected attack attempts.
  • Verify all links and attachments before opening them.

“You can’t quantify business risk with RAG color coded scores”

quantify business risk, Adam Palmer, Chief Cybersecurity Strategist, Tenable

A recent study by Forrester Research shows that 97% of Indian organizations experienced at least one business-impacting cyberattack in the past 12 months. Yet, only four in 10 security leaders in India have a clear picture of how much at risk, or how secure their organizations are. In a chat with CISO MAG, Adam Palmer, Chief Cybersecurity Strategist at Tenable, tells us how security leaders should quantify business risk and assess the attack surface, using accurate and more insightful metrics like the cyber exposure score.

Palmer has over 20 years of cybersecurity experience.  That includes executive positions at large cybersecurity vendors, leading the U.N. Global Program against cybercrime.  Before joining Tenable, Palmer held the position of Global Director, cybersecurity Risk & Controls for Banco Santander – the largest bank in the EU and Latin America.

Palmer began his career as a U.S. military officer focused on cybercrime cases.  After the military, he worked in a senior operational role by creating the [.]ORG top-level Internet domain cybersecurity program.

Edited excerpts of the interview:

By Brian Pereira, Principal Editor, CISO MAG

Your research shows that only 4 in 10 security leaders know how secure or at risk they are. How does an organization quantify business risk due to these business-impacting cyber attacks? Are there any frameworks or tools to do this?

I worked on this idea for two years and my prior job at the bank (Banco Santander) was trying to quantify risk — moving from qualitative to quantifiable analysis. Many security leaders use the heat matrices, the red, amber, green (RAG) scores to try to describe risk to the business leaders. This is really IT talk. Every organization I worked at did this. It doesn’t say anything to really quantify the risk or help people understand the reduction in risk. How can a business leader make a decision based on a color in RAG scores? There is a gap in communication between how IT people speak (technical or ambiguous), and the expectations of business leaders — quantitative understanding of risk.

A cyber exposure score, which is what Tenable creates, is a powerful tool because it gives you a quantifiable number.

Why haven’t security leaders been able to do accurate risk assessments for business-impacting cyberattacks?

The heart of it is really the lack of partnership between the security and the business leaders. There’s not enough alignment of metrics and objectives with business strategic priorities. I see that organizations report risk in a very qualitative language. This is not the language of business leaders. They have to consider industry benchmarking frameworks and accurately report it to the business, especially in times like today.

Organizations with security and business leaders who are aligned in measuring and managing cybersecurity as a strategic business risk deliver demonstrable results. What would be your recommendations to security leaders to do this security-business alignment? How do they weave cybersecurity into the fabric of business discussions?

The keys are a few things: linking the security program to business performance.  Making sure you have visibility across the entire attack surface. The attack surface has expanded with cloud and even operational technology. You can’t protect what you can’t see. And you have to apply a business context to your tactical decisions and express that in a quantifiable matrix that business leaders understand.

Looking at the global threat landscape, which countries are being targeted the most? And what could be the reasons?

We saw that all the markets had a high percentage of business-impacting events over the last 12 months. 97% of businesses in India reported a cyberattack within the last 12 months. And 74% expect an increase in cyberattacks. Today, we are in a very dynamic business environment, with business and technology closely woven together. The effective business-aligned CISO just can’t focus on technical issues or one part of that threat landscape. They really have to be aligned with the business and elevate themselves as a business-aligned security expert — and be aware of the entire expanded threat landscape.

Specific to India, what does your research show, with respect to the types of businesses being increasingly targeted?

We saw medium and large businesses being attacked. We know that these businesses make India a dynamic and exciting economy, with Digital India, and all the technology being used throughout India – in business and in government. Cybercriminals know where the money is, and they target technology and intellectual property. Given the monetary value and the damage that can be caused by a successful attack, across industries, telecom, health care, finance, all these industries are major targets. And what we found in this study is that all of these are equal opportunity targets for cybercriminals to attack a business.

Your research shows that 67% of security leaders in India say these attacks also involved an operational technology (OT) system. What kind of industries are being targeted within India? Does this also include critical infrastructures like nuclear plants and electricity grids?

This is really an issue of convergence. Automation is now common in the industrial environment. And that environment is converging with the IT environment. It is in critical infrastructure and manufacturing. But it can be in lots of different types of businesses. Think about automated access controls, with all kinds of smart connected devices, HVAC — some of these use smart connected industrial controllers. And we are finding that cybercriminals are attacking these devices and often, security teams aren’t monitoring these satisfactorily. They are using legacy approaches for vulnerability risk management, and they are not detecting these devices. And the criminals are attacking them.

A heavy manufacturing plant that uses OT devices, was targeted last year in Europe. And it cost Euro 40 million in the first week.  It disabled their operations. So it is critical that the security teams secure these critical operations and make sure they are using the same amount of analysis and care that they apply to other amounts of threats and that they are applying that as well to this new threat vector, which is OT.

I want to talk about the COVID-19 response strategies, and you have another data point in your report about this: 75% of the respondents say their COVID-19 strategies are somewhat aligned to the business. What is the reason for the surge in COVID-19 related phishing attacks on businesses?

Cybersecurity threats really thrive amidst a climate of uncertainty. We’ve seen attacks increase with attackers taking advantage of the current pandemic environment. This highlights the fact that cybersecurity should be a board-level concern. In times of crisis, it’s more important that you have clarity and alignment with the business. Cybersecurity teams need to evolve to align themselves to a business strategy that understands this, connects with this, and manage cyber risk, in relation to the world around them, which is now an unusual world due to COVID-19.

Cybersecurity Strain: 161% Increase in Visits to High-Risk Apps

Mobile Apps Security, mobile apps

Research experts from Netskope Cloud warned security teams about the surge in the use of risky apps and websites by the remote workforce, globally. In its report “Cloud and Threat Report – August 2020” Netskope Cloud stated that the number of remote employees has more than doubled and changes in user behavior has been dramatic in the Q1 of 2020, with 161% increase in visits to high-risk apps and sites by a 64% remote workforce.

Research Highlights

  • 80% increase in the use of collaboration apps as remote workers sought to remain connected with their colleagues, and a 2% increase in the total number of cloud apps being used in the average enterprise.
  • 600% increase in visits to adult content.
  • 97% increase for personal use of managed devices.
  • Cloud-based malware delivery (vs web) increased to 63%.
  • Personal use of devices increased by 97% and use of risky apps and websites increased by 161%.
  • 7% of all users uploaded regulated data, source code, company confidential data, and other sensitive data to personal instances, exposing the data to potential misuse and theft.
    Image Source: Netskope Cloud

The research also revealed that Cloud Storage, Webmail, and Social apps were among the most popular apps used for phishing, with 63% of malware delivered over cloud applications like Microsoft Office 365 OneDrive for Business, SharePoint, Google Drive, and Amazon S3. While, Microsoft Office 365 OneDrive for Business, Microsoft Live Outlook, Blogger, AOL Mail, and Facebook are the most popular apps used for phishing attacks.

“The percentage of phishing attempts being delivered through cloud applications held steady at 15% with a variety of apps being used to deliver the bait, including cloud storage, webmail, web hosting, and social media apps. This statistic, combined with those reported by the Anti-Phishing Working Group, indicates that phishers are both using the cloud to phish and phishing for cloud credentials,” the report said.

“Device sharing at home is validated by the traffic to websites and apps categorized as Education and Kids, where managed devices are used for remote education efforts within families. Even with an increase in personal use of managed devices and high-risk websites, the most popular apps remain the leading delivery method of cloud-enabled threats and malware. And finally, as expected, the use of collaboration apps increased greatly as remote teams aim to stay connected,” the report added.

Protective Measures

Netskope Cloud also recommended certain security measures to protect sensitive data from adversaries. These include:

  • Use strong authentication and access controls like 2FA, MFA, etc.
  • Adaptive access controls based on the user, app, device, location, data, and destination to selectively grant access to specific activities.
  • Zero-trust network access to private apps in data centers and public cloud services to reduce exposure of apps and limit network lateral movement.
  • Continuous security assessment of public cloud services to detect misconfigurations and publicly exposed data.
  • Cloud inline analysis of managed and unmanaged cloud apps for data context to enable data and threat protection defenses.
  • Selective and safe enablement of cloud applications based on a third-party risk assessment of applications with the ability to recommend safer alternatives.
  • Granular policy controls for data movement to and from apps, instances, users, websites,devices, and locations.
  • Cloud data protection (DLP) for sensitive data from internal and external threats
  • Behavior analysis for anomalies, plus confidence index scores for users with event correlation timelines to visualize changes in behavior.
  • Real-time coaching to users on activity and data movement with justification collection, proceed/cancel, or warning alerts to change user behavior.

 

CYFIRMA’s DeCYFIR Platform Can Predict Hacker Motives Before an Attack!

Cyfirma's DeCyfir, Cyfirma launches DeCyfir

Have you seen the Tom Cruise flick Minority Report? One of its themes is precrime or the ability to predict a crime before it happens. Well, CYFIRMA, a Singapore-based threat discovery and cyber-intelligence analytics company, seems to have come up with something similar for cybercrimes. It has introduced a cloud-based, AI-powered cybersecurity platform – DeCYFIR. The platform is designed to empower businesses with an ability to discover threats from the trenches of cyberspace and decode them into useful insights. DeCYFIR segregates important threat signals from all the noisy data out there. This enables businesses to not only take remedial actions against cybercriminals, but also helps in detecting their motives much before an actual attack occurs.

DeCYFIR Brings the Power of 3

The DeCYFIR platform has three tenets: Predictive, Contextual, and Comprehensive.

Predictive: The DeCYFIR platform, identifies potential threats at an early planning stage of a cyberattack. It picks up threat indicators from the deep/dark web, hackers’ forums, and other closed communities including its own repository of indicators of compromise (IoCs) and predicts upcoming attacks based on a set of probability mathematical models and analytical engines.

Contextual: DeCYFIR provides a quality intelligence solution to businesses by giving them industry, geography, and technology-specific threat information. The platform has a unique capability to join the dots between hackers, exploit campaigns, motivations, methods, and attack readiness. Thus, it offers businesses a combined and complete contextual visibility of their threat landscape.

Comprehensive: DeCYFIR redefines quality cyberthreat intelligence by providing all three layers of insights (strategic, management and tactical). These insights enable business leaders to take informed and accurate decisions for mitigating risks according to threat severity.

With DECYFIR, cyberthreats and signals are automatically discovered and decoded. These insights are provided in real-time so that security teams are always kept a step head of their cyber adversaries.

Click here to know more about CYFIRMA and its efforts to bring Cyberthreat Intelligence to the fore

Key Features of DeCYFIR

DeCYFIR consists of several modules, each designed to help businesses strengthen their cybersecurity postures and be better equipped to handle the risks of digitalization. However, the three features that stand-out are:

  • Threat Visibility and Intelligence (TVI) – Answers the WHO, WHY, WHAT, WHEN and HOW of the looming cyberthreats, and provides recommendations for remedial actions.
  • Cyber Situational Awareness (CSA) – Provides real-time cyberthreat insights, trends, news related to technology, regulatory & law, policy changes, emerging cyberattacks, vulnerabilities, exploits and much more.
  • Cyber Incident Analytics (CIA) – Enables businesses to comprehensively respond to security incidents with not only tactical information but also strategic-level insights by mapping associated campaign, hacker’s affiliation, motive, and mechanism.

Additionally, the latest version of DeCYFIR includes the following key features:

  • Risk Dossier – A threat playbook that provides complete contextual and correlated details of threats discovered by DeCYFIR.
  • Threat Search Engine – A dedicated search engine that enables businesses to search the dark, deep and surface web, P2P channels, bin sites and other data sources to retrieve information related to specific cyber events, attacks, incidents, malware, vulnerabilities, campaign, and threat actors.
  • Complete Threat Landscape View – A single pane view that offers business leaders and security teams a unified vision into their businesses’ external threat landscape and overall cyber posture.
  • Risk and Hackability Score – Risk and Hackability Score are calculated using proprietary algorithms and mathematical models. With Risk Score, businesses gain a vantage view of their external threat landscape and their preparedness as compared to their industry peers. Hackability Score however serves as an indicator of how hackable businesses are, and their level of attractiveness as a potential target.

DeCYFIR-ing the Threats in a COVID-19 World

The COVID-19 pandemic has increased the world’s digital dependency, and correspondingly increased businesses’ vulnerability to cyberattacks. According to the Global Risks Report 2019 published by the World Economic Forum, massive data fraud, theft, and cyberattacks have been ranked amongst the top five risks globally for the next 10 years in terms of likelihood. In such uncertain times, which includes a global pandemic, trade wars, and geopolitical tensions, cyberthreats and cybersecurity have become an inevitable aspect of businesses across various verticals.

Kumar Ritesh, Founder and CEO of CYFIRMA, said, “Accelerated digitalization has brought about a rise in intensity and sophistication of cyberthreats. Adding to that, remote working has introduced new attack vectors. Integration of business applications with third-party systems can create new vulnerabilities, and employees unaccustomed and untrained in cybersecurity practices can heighten the digital risk. Our enhanced threat discovery and cyber-intelligence platform, DeCYFIR, will help businesses across all verticals as we know cyber-intelligence is the new currency that will power growth and allow businesses to thrive in the post-pandemic digital economy.”

As the digital landscape expands and cybercriminals and state-sponsored groups extend their cyber warfare into businesses and homes, reining in cyberthreats and risks require a mindset shift towards an intelligence-based predictive approach. The DeCYFIR platform could just be the solution that businesses require to decode threats and uncover hidden signals in this hyper-connected world.

And it’s not even 2054, the year in which the film Minority Report is set!

Cyber Warfare, Cyber Warfare WhitepaperAlso, download this whitepaper now and read about “Cyber Warfare” and CYFIRMA’s pledge towards protecting your businesses, enterprises, and governments from such attacks.

 

 

Qualcomm’s Flaws Led to “Achilles’ Heel” in 40% of Android Phones

vulnerabilities in DSP Chip, vulnerabilities in Qualcomm MSM Chip

Check Point, in its research dubbed “Achilles,” discovered multiple vulnerabilities in Qualcomm’s Snapdragon Digital Signal Processor (DSP) chips, exposing over 40% of all smartphones globally to cyberattacks. If exploited successfully, the vulnerabilities allow threat actors to take control of mobile devices without the user’s knowledge.

What’s a DSP Chip?

A Digital Signal Processor is like a computer on a chip that has both hardware and software designed to optimize and enable each area of use on the device itself, including charging abilities, multimedia experiences, and advanced AR abilities. Most modern smartphones, including high-end smartphones from Google, Samsung, LG, Xiaomi, OnePlus and others, have at least one of these chips.

Flaws in DSP Chip

Check Point researchers stated that the vulnerabilities in the DSP chip allows an attacker to turn the devices into spying tools without the user’s knowledge, render the mobile phone constantly unresponsive, and inject un-removable malware with evading detection capabilities. By using a fuzzing technique against smartphones with the vulnerable DSP chip, the researchers were able to identify 400 discrete attacks.

After Check Point disclosed its findings, Qualcomm acknowledged the vulnerabilities and assigned six of the flaws with CVE listings: CVE-2020-11201, CVE-2020-11202, CVE-2020-11206, CVE-2020-11207, CVE-2020-11208, and CVE-2020-11209. Even though Qualcomm fixed the six flaws affecting its Snapdragon DSP chip, the smartphone makers still has to deliver fixes to their users’ devices, which means that many smartphones are still vulnerable to potential threats.

Check Point recommended organizations to use proper mobile security solutions to protect their corporate data on mobile devices.

“While DSP chips provide a relatively economical solution that allows mobile phones to provide end users with more functionality and enable innovative features– they do come with a cost. These chips introduce a new attack surface and weak points to these mobile devices. DSP chips are much more vulnerable to risks as they are being managed as ‘Black Boxes’ since it can be very complex for anyone other than their manufacturer to review their design, functionality, or code,” Check Point said.

“Due to the ‘Black Box’ nature of the DSP chips it is very challenging for the mobile vendors to fix these issues, as they need to be first addressed by the chip manufacturer. Using our research methodologies and state-of-the-art fuzz testing technologies, we were able to overcome these issues – gaining us with a rare insight into the internals of the tested DSP chip. This allowed us to effectively review the chip’s security controls and identify its weak points,” Check Point added.

 

Tanium and Google Cloud Partnership Marks the Beginning of a New “Chronicle”

Cloud Security

Tanium, a unified endpoint security provider, has partnered with Google Cloud to collectively fight against advanced persistent threats (APTs) to the distributed business operations keeping in mind the ongoing and post COVID-19 era. This handshake brings together Tanium’s Threat Response platform and Google Cloud’s security analytics platform, Chronicle, whose acquisition was completed by Google Cloud in October 2019.

With Tanium and Google Cloud, customers don’t have to make difficult tradeoffs between the quality, breadth, timeliness or storage cost of their security telemetry.

What the Tanium and Google Cloud Partnership Means

Customers of both the platforms are excited about this partnership as it will help enterprises detect, investigate, and scope advanced, long-lived attacks (APTs) in a more diligent manner. It will additionally give them the following enhanced capabilities:

  • Proactive Threat Hunting: SecOps teams can now swiftly hunt threats both live and by comparing logs compiled over a year of endpoint activity. The high-fidelity and real-time security telemetry comes from Tanium, which then combines with the analytics and cloud-scale data capacity of Chronicle delivering high-speed search and cyber forensics capability to its customers.
  • Accelerated Incident Response: Both platforms together are now highly capable of providing historical data required to investigate, scope, and further remediate advanced persistent threats. With Chronicle, customers can correlate up to one year of data gathered from the Tanium platform’s sophisticated endpoint telemetry and network activity. This enables incident response teams to take comprehensive remediation actions against long-prevailing APTs.
  • Reduces Overhead Costs: This coalition also increases the efficiency of security analyst(s) and reduces costs associated with storage and point tool sprawl. Tanium reduces or nearly eliminates the need for a separate endpoint security and management solution. With a single agent architecture that provides detailed telemetry across endpoints, coupled with Chronicle’s cost-effective storage for that endpoint telemetry with zero data volume charges and a simpler user interface, this is soon going to be a hot favorite among security analysts.

Sunil Potti, General Manager and Vice President of Cloud Security at Google Cloud, said, “With Tanium and Google Cloud, customers don’t have to make difficult tradeoffs between the quality, breadth, timeliness or storage cost of their security telemetry. APTs require a sophisticated approach to detection and response. This starts at the endpoint, where most compromise activities begin. With telemetry sourced from Tanium’s comprehensive endpoint security approach, customers have the data they need to detect and investigate post-compromise activity to accelerate remediation and prevent future intrusion.”

The Other Collaboration

Tanium and Google Cloud are also extending their zero trust initiatives with another partnership between Tanium and Google’s BeyondCorp. Through this integration, Tanium will support the ability to use endpoint identity, state, and compliance data for BeyondCorp Remote Access.

Later this year, the two companies also plan to collaborate on improving the methodologies of managing and securing client endpoints like thin-client devices, cloud endpoints, and mobile operating systems.

Researchers Discover 30 Vulnerabilities in 20 CMS Products, including Microsoft SharePoint

CISA vulnerabilities, Microsoft Vulnerabilities, HP Device Manager Susceptible to Dictionary Attacks

Security researchers Alvaro Munoz of GitHub and Oleksandr Mirosh of Micro Focus Fortify discovered over 30 security vulnerabilities in 20 content management systems (CMS), including Microsoft SharePoint, Alfresco, and Atlassian Confluence. Munoz and Mirosh presented their findings at the Black Hat cybersecurity conference and demonstrated how a threat actor can escape template sandboxes and get access to the Remote Code Execution (RCE).  They also analyzed security controls executed by several CMS frameworks and techniques to bypass them.

A CMS is a software application used to manage the creation and modification of online content,  mostly used for enterprise content management (ECM) and web content management (WCM). According to the researchers, content in the CMS platform is stored in a database and displayed to users based on a set of templates.  These templates support a subset of programming language capabilities and are sandboxed to prevent users from any intrusions.

Using a Microsoft SharePoint server as a main CMS attack surface, the researchers found six unique RCE vulnerabilities by combining flaws in its implementation and design.  They also reviewed certain popular Java Template engines like Apache Velocity, Apache FreeMarker, Pebble, and JinJava and discovered multiple ways to escape template sandboxes and achieve RCE in many products including, Atlassian Confluence, dotCMS, Alfresco, Liferay, Crafter CMS, XWiki, and Apache OfBiz.

“In the most simple attack scenario, the attacker has access to the target CMS applications such as regular Sharepoint users being able to create their own sites and therefore being able to provide their own templates. In some cases, we were able to get trial accounts on cloud-based CMS platforms and perform the attacks from our own trial admin account. These were the most interesting cases since we were able to compromise the underlying infrastructure which could have allowed us to initiate attacks against other tenants. No matter what the vector used, though, the impact is always critical since once the mitigations are bypassed, template engines can be used to evaluate arbitrary code leading to Remote Code Execution (RCE),” the researchers said.