Home Blog Page 188

121.4 Million Ransomware Attacks Recorded in the First Half of 2020

Ransomware attacks, LockBit Ransomware

A  survey from cybersecurity firm SonicWall revealed that the opportunistic use of COVID-19 pandemic by cybercriminals has resulted in the rise of ransomware and IoT malware attacks globally. The survey “2020 SonicWall Cyber Threat Report” found that ransomware continues to be the most concerning threat to enterprises and the preferred attack method, with 121.4 million attacks (20% increase) reported globally in the first half of 2020. The threat researchers recorded 79.9 million ransomware attacks (109% increase) in the U.S. and 5.9 million ransomware attacks (6% decline) in the U.K.

Decline in Malware Attacks

The survey also sheds light on the global malware attacks, which saw a declining trend since last year. During the first half of 2020, global malware attacks fell from 4.8 billion to 3.2 billion (-24%) over 2019’s mid-year total. The U.S. (-24%), the U.K. (-27%), Germany (-60%), and India (-64%) encountered reduced malware attack volume. However, ransomware has seen a corresponding jump over the same time period.

Image Source: SonicWall

Changing Attack Landscape

Cybercriminals utilized the global pandemic to launch social-engineered attacks, phishing, and other Coronavirus-related scams. SonicWall researchers detected a surge in scams and exploits specifically based around COVID-19 and noted a 7% increase in COVID-related phishing attempts during the first two quarters.

“COVID-19 phishing began rising in March, and saw its most significant peaks on March 24, April 3 and June 19, 2020. This contrasts with phishing as a whole, which started strong in January and was down slightly globally (-15%) by the time the pandemic phishing attempts began to pick up steam,” the survey stated.

The survey also found a 176% increase in new malware attacks disguised as trusted Microsoft Office file types and 11% of PDF files made up 33% of all newly identified malware in 2020. “Cybercriminals are too sophisticated to use known malware variants, so they’re re-imagining and re-writing malware to defeat security controls like traditional sandboxing techniques — and it’s working,” the survey added.

 IoT Continues to Attract Threat Actors

The researchers found a 50% increase in IoT malware attacks, a number that represents the number of additional smart devices that are connected online as employees and enterprises functioning remotely.

The survey findings are based on the threat intelligence data gathered from 1.1 million sensors in over 215 countries and territories.

Bill Conner, SonicWall President and CEO, said, “Cybercriminals can be resourceful, often setting traps to take advantage of people’s kindness during a natural disaster, panic throughout a crisis and trust in systems used in everyday life. This latest cyber threat data shows that cybercriminals continue to morph their tactics to sway the odds in their favor during uncertain times. With everyone more remote and mobile than ever before, businesses are highly exposed, and the cybercriminal industry is very aware of that. It’s imperative that organizations move away from makeshift or traditional security strategies and realize this new business normal is no longer new.” 

 

India’s First Virtual Awards Show Honoring Excellence in Cybersecurity

2nd edition ciso mag awards

Mumbai, India – July 27, 2020 – Following the huge success of CISO MAG Awards India 2019, EC Council’s CISO MAG is all set to virtually host the 2nd Edition of the CISO MAG Awards and Summit India on  July 30, 2020 from 9:55 AM to 15:00 PM IST. #HyperCyberSec

CISO MAG Awards 2019 was received excellently in the market with support from eminent partners namely SonicWall (Presenting Partner), SearchInform (Gold Partner), Sequretek (Cocktail Partner) and Ola (Mobility Partner) among others. It was graced by illustrious members, associations, and business circles in India.

CISO MAG plans to recreate the same magic, this year, virtually around the central theme ‘Cybersecurity in a Hyper Connected Ecosystem,’ staying true to what the changing times demand.

The2nd CISO MAG Summit & Awards 2020 – India has been specifically designed to create more awareness on the need for cybersecurity and its related implications across the nation with its major aim to:

  • Promote and highlight professionals and organizations who have demonstrated best practices in the information security arena.
  • Uphold the cybersecurity profession in India region by recognizing innovations and contributions by the professionals and organizations.
  • Ensure fair, transparent, and robust award selection and recognition.

The intent of this event is to help drive innovation, excellence, and a positive change in the Indian security industry by recognizing best-in-class products, companies, and individuals.

This is your annual opportunity to build cross-sector security partnerships, benchmark your company’s digital resilience, and participate in the discussions shaping India’s cybersecurity landscape in 2020 and beyond.

The winners will have exciting reasons to celebrate:

  • Global Exposure – Winners will be featured in CISO MAG magazine under the exclusive India Awards section.
  • Online Promotion – Winners will be promoted on event website and social media.
  • Event Trophy – Winners will receive the coveted CISO MAG trophy
  • Certificate of Acknowledgement
  • Visibility in 20+ Countries

Milind MungaleExecutive Vice President & CISO, NSDL e-Governance Infrastructure Limited; Bharat AnandCIO & CTO, Ministry of Home Affairs, Government of India; and Durga Prasad DubeSenior VP and CISO, Reliance Industries Ltd., together form the esteemed Jury overseeing the Awards.

Associate partners for this event include Computer Society of India and Electronic Security Association of India.

Arvind GuptaInnovation Evangelist, Technology Entrepreneur and Policy Advisor, will open the event with his keynote address. He will share his insights on strategic approaches to accelerate transformation in Cybersecurity in times of COVID-19.

Dr. Pavan DuggalAdvocate, Supreme Court of India and Brijesh Singh, Inspector General, Maharashtra Police, will be addressing the gathering to help reimagine business and reshape the future of work as the world goes digital.

A Panel discussion involving Dr. Balsing RajputSuperintendent of Police, Maharashtra Cyber Cell, will be hosted on ‘Leveraging analytics to derive a proactive security framework and incident response mechanism to safeguard business continuity.’ 

The event will conclude with a discussion on ‘Fortifying the cybersecurity strategy through comprehensive risk assessments, information sharing and access management protocols.’

Mansi ThaparHead Information Security, Jaquar GroupJacxine FernandezVice President & Group Chief Information Security Officer, Adani Group; and Mohd. Shadab SiddiquiHead of Information Security, Privacy, Trust and Compliance, Hotstar will be a part of this engaging interaction.

You can now register for the event in one step.

Additional details on the CISO MAG Summit and Awards 2020 – India are available at https://events.cisomag.com/E-Events/CISO-MAG-Summit-Awards-2020.html

About CISO MAG

CISO MAG, an EC-Council initiative, is a cybersecurity magazine delivering cutting-edge updates about the latest happenings in the cybersecurity world. It is the handbook for CISOs, CXOs, and every responsible stakeholder of a secure Internet space. More information can be found at https://cisomag.com/

For more information, press only:

Name: Deepali Mistry

Email: [email protected]

Phone: +91-9833151933

 

Update Now! Researchers Find Multiple Bugs in ASUS Routers

MikroTik Devices, ASUS Routers

Security researchers from Trustwave revealed that certain models of ASUS routers are vulnerable to malicious attacks. The bugs in the routers are related to its firmware update process. In a security advisory, the researchers stated that they found security vulnerabilities in the ASUS RT-AC1900P router model of version 3.0.0.4.385_10000-gd8ccd3c. The two vulnerabilities, dubbed CVE-2020-15498 and CVE-2020-15499, in the routers’ firmware could have allowed attackers to perform malicious attacks.

Trustwave researchers said the vulnerability CVE-2020-15498 allows the router to accept forged server certificates for the firmware update. This enables  cybercriminals to launch a man-in-the-middle attack (MITM) using no-check-certificate option passed to the wget tool and later download firmware update files on the router by connecting the device to a malicious network. The vulnerability CVE-2020-15499 shows the firmware release notes dialog in the router management web interface, which is susceptible to cross-site scripting.

“Given that the device accepts forged certificates, an attacker can trick the router to display a message that a new firmware is available when the admin user opens the firmware upgrade page. Furthermore, an attacker can then craft a malicious file containing release notes for the new firmware that will contain arbitrary javascript. Due to cross-site scripting the malicious javascript will be executed when an unsuspecting admin user clicks the release notes link on the firmware upgrade page,” the researchers explained.

Trustwave recommended users to immediately upgrade the router’s firmware to version 3.0.0.4.385_20253 or the latest stable release to avoid any malicious intrusions.

Target on Home Routers

Recently, cybersecurity solutions provider Trend Micro warned users about a new wave of attacks targeting home routers. In its research report “Worm War: The Botnet Battle for IoT Territory,” Trend Micro revealed that cybercriminals are using home routers to build botnets. The research found a surge in cyberattacks by exploiting routers, particularly in Q4 2019. Attackers made brute force log-in attempts against routers by using automated software to try common password combinations. The number of attacks increased from around 23 million in September to nearly 249 million attacks in December 2019. In March 2020, around 194 million brute force login attacks were reported.

 

Continuous Tests in Cybersecurity Controls and Process

third-party risk

Much is said about the importance of security testing, regardless of what we call them, be it Pentest, Ethical Hacking, Red Team or whatever. This is a process that all security teams must have and perform regularly, if not continuously. Its benefit for companies is proven because it brings visibility of possible vulnerabilities and risk situations that are in our environments and need to be somehow mitigated.

By Glauco Sampaio, CISO, Cielo

We usually use this type of test with a focus on systems or new technologies, but how do we ensure that our legacy, what is already in production continues to work as planned and implemented? This is a question that must torment our minds and be the object of our efforts. It’s utopia to think that once implemented, the controls will be 100% functional with all the changes that the company makes in its environment, as a result of new initiatives or necessary adjustments. We cannot have the illusion that we will be able to have the complete and preventive visibility that allows us to know all the impacts and side effects of these changes.

Thinking about how to ensure the continuous operation of controls and processes is important, to ensure the security of our environments. It also helps us to avoid unpleasant situations such as an audit note on a situation that had already been mitigated.

The use of tools classified as Breach and Attack Simulation (BAS) has been widespread in the market is very interesting and mainly adds to this testing process a greater capacity to perform the validations. However, we must expand our testing horizons, also validate the associated processes that support the security operation, in addition to the particularities of our environments, which is not the main focus of these solutions.

Test an end-to-end process:

  • It is possible to run without being blocked
  • The log generated is correct and sent to the monitoring system
  • The monitoring system generates the alert as it should, within the defined SLA
  • If you have an automated response, it would be carried out as it should
  • The incident response team handles the case within the defined SLA and as described in the playbook for that particular event

This is just an example of a possible “complete” test script, this can and will vary according to the level of security maturity and the characteristics of each company. What we should keep in mind is that the life cycle of that scenario is the test objective, to ensure that all steps are being carried out as planned and agreed as the result.

The visibility generated by this type of test also helps in the management of operational teams, regarding the fulfillment of defined SLAs. In the incident response process, time is precious, and handling an alert within the expected timeframe can be vital to containing an incident, and prevent it from taking on greater proportions.

Often, stages of the incident response process are performed outside the security team or by service providers. Measuring the effectiveness of these actions has always been a challenge. The approach of continuous and complete tests is a tool for us to have inputs and be able to charge these third parties the level of effectiveness, defined through SLAs. Showing practical cases, helps us in the discussions or even in possible contractual penalties for outsourced services.

The results of these tests must be shared with all those in charge, or involved, in the incident response processes, as well as with the company’s executives. It can also be a security indicator that shows the effectiveness of the existing controls or where we need to reinvest money and efforts.

It seems utopian to think that we will be able to test 100% of the security controls continuously. For this issue, the automation tools or even the use of internally developed scripts can help us giving scale. Even so, planning is necessary so that we do not cause overwhelm in our response team by the test alerts. The classification and prioritization of the tests must be made based on the importance of the target control. Critical controls must be tested with greater frequency against those of less importance.

It’s important to have a Chinese Wall so that those responsible for the tests have the freedom to run them freely. It’s also important for security managers to have the maturity to understand that the purpose of these tests is to be preventive and help us to not be caught off guard by an incident.

In summary, continuous tests give visibility to our controls and guarantees against faults already identified and mitigated previously. We can start small by testing the most basic and simple controls, not necessarily with an end-to-end vision. But we have to start and define an objective within a feasible horizon to achieve this maturity. I guarantee that the most basic tests will give results and help us a lot!

About the Author

Glauco Sampaio is a Chief Information Security Officer (CISO) at Cielo, where he is in charge of the security strategy for the largest Brazilian credit and debit card operator. Sampaio has been working for 20 years as information security professional in Brazil in media companies such as iG and Editora Abril, and also in financial institutions such as Santander Bank, Votorantim Bank and Original Bank.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article

The Human Component in the Security Operations Center

soc

As cybersecurity challenges become more complex, the tendency is for organizations to focus on what piece of security technology they can acquire next. But that usually means the human component of the security operations center (SOC) isn’t getting enough attention. The SOC must have its security tools, but it cannot rely solely on machines to protect the organization. People are a fundamental to the very core of SOC operations. To understand how SOCs can be improved to support the humans who make security possible, it’s important to start with an overview of the status quo.

By Gil Shulman, Vice President of Products, Illusive Networks

Inside today’s SOCs

The SOC is almost like a living organism built out of a symbiotic relationship between the different tiers of engineering and analysis. Most SOCs are saturated with security technologies to help analysts do their jobs. They generate piles of alerts by detecting malware signatures, rule violations and threshold exceptions, or suspicious patterns, sequences and anomalies — signs that something bad may be happening.

These alerts then require an examination or validation process so SOC analysts can know what’s worth escalating. SOC teams must filter alerts, separating millions of benign alerts to find and prioritize meaningful alerts that warrant further investigation. For verified incidents, they then collect data from multiple tools to piece together a picture of what actually happened, which can take weeks or months. In the event of a true attack, the attacker may already have been well entrenched in the network — or may already have exfiltrated data.

The toll on analysts

Though incident responders invest intensive time and effort, they continue to fret over what important alerts they may have missed.  As one survey after another shows, the process suffers from a shortage of skilled security personnel, lack of real-time forensic data and inability to accurately assess business risk.

Without knowing which incident poses the biggest threat to an organization’s crown jewels, teams can spend valuable time on non-critical incidents instead of using scarce expertise where it’s needed most. Consequently, the humans who work in the SOC – the analysts – are burning out. They repeatedly expend a tremendous amount of concentrated brain power and precious time on alerts that are largely false positives.

Burnout is endemic. A stunning 60% of SOC team members are thinking of leaving their jobs or changing careers altogether due to stress, according to the second annual Devo SOC Performance Report, based on a survey conducted by Ponemon Institute. Since SOC analysts are already hard to come by and replacing them is no easy task, this is a problem of significant proportions.

That’s because the human component of security analysis remains critical to success. AI and automation are being used to great effect within the SOC; they absolutely lighten the load in a world of increasing alerts and scarce cybersecurity talent. But algorithms lack a human touch. A survey conducted at RSA Conference 2020 found that the majority of industry professional respondents agreed that human analysts possess qualities that machines cannot match. These qualities include intuition, creativity, previous experience, and frame of reference.

In short, the SOC will always need humans, working in conjunction with helpful tools like automation and AI. Since that’s true, organizations need to find ways to ease the stress burden on their analysts if they hope to maintain the staff required to keep their networks safe.

How to improve the status quo

IDC has observed that “traditional cybersecurity leads with a ‘block and tackle’ strategy.” They note, though, that as the complexity and sophistication of threats increases, SOCs “require a better understanding of how threats beyond the perimeter interact with their network.” Incident response teams waste valuable hours sifting through multiple tools and systems, looking for the contextual data needed to validate escalation. Essentially, SOC analysts need decision-making context and broader correlation to be optimally effective at their job.

This is where automation shines. A wealth of forensic data collected automatically and directly from where the attacker is operating provides knowledge of where in the network the attacker is lurking and how far they are from privileged credentials. SOC teams can reclaim a vast chunk of the expensive time and effort lost to manual activities typical in the processes of triage, ticket enrichment, investigation, and validation — while becoming more proactive and efficient in incident response. Less stress and greater efficiency equate to higher job satisfaction – more benefits of automation.

Upskilling and reskilling are needed, as well. In the SOCs that the Devo report classify as “high-performing,” 67% have skills development and training in place. By implementing a training program, Tier 1 analysts can learn the more sophisticated skills they need to move up to Tier 2, and the same goes for Tier 2 analysts as they advance toward Tier 3. Additionally, as automation, AI and SIEM technologies become increasingly important, staff will need training in these areas.

Change is coming

Technology is democratic in that its evolution is available to all – the good and bad alike. SOC staff are already so overwhelmed that unless something significant changes, it’s only a matter of time before they are overrun by clever new attack types as well as the current deluge of alerts. For the health and retention of SOC teams and for the security of your organization, changes must be made. They include adopting automation and upskilling analysts for what’s ahead. The human component of the SOC must not be overlooked but instead nurtured in order to create a truly secure network environment.

About the author

Gil Shulman is the Vice President of products for Illusive Networks and has over 20 years of experience in the technology industry focusing on cyber defense. Before joining Illusive Networks, Shulman worked with a wide variety of market-leading companies, from Check Point Software, where he led the high-end products team; to Radware and Verint Systems, where he managed the product organization for national cyber defense. In recent years, he has focused on virtualization and cloud technologies, traffic and application management, and network appliances and platforms, creating new product categories and design strategies. Shulman served at the technological unit of the Israel Defence Forces Unit 8200.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Strategic Alliance Between AttackIQ and Ackcent to Provide BAS Services Across Europe

NCSC and Microsoft Cyber Accelerator program

Cybersecurity solutions provider AttackIQ announced a strategic partnership with managed detection and response services firm Ackcent to provide breach and attack simulation (BAS) and continuous security validation (CSV) to customers across Europe. Industry experts opined that the partnership allows both the companies to meet the growing cybersecurity market demand in Europe and enhance customers’ security capabilities against evolving cyberthreats.

The alliance also enables customers to understand how to thwart the tactics, techniques, and procedures (TTPs) used by cybercriminals.

AttackIQ offers cloud-based software-as-a-service (SaaS) platform allowing managed security service providers (MSSPs) to provide additional BAS services to its customers.  Its wide range of managed detection and response (MDR) services help organizations in threat monitoring, detection, and response capabilities.

Lluis Vera, CEO at Ackcent said, “The industry has hit an inflection point where spending money on technology, people and processes internally is failing them. Lacking real information and in the face of increasing budgetary pressures, organizations are forced to make assumptions and potentially bad decisions about their security. Customers need a solution to identify how systems, people and processes are configured and if they are able to defend against the latest known threats. AttackIQ’s open platform will allow Ackcent to develop its own BAS use-cases and enable new and existing customers to have a threat-informed assessment of their security solutions’ effectiveness.”

Ross Brewer, strategic advisor of Europe, Middle East and Africa at AttackIQ, said, “Despite spending $100 billion per year on cybersecurity, most CISOs still experience damaging data breaches, due to controls failing silently. So, security control failures become visible and can be corrected, closing the gap to adversaries and making the world safe for compute.”

Europe’s Cyber Readiness

According to a research report, cyberattacks across several verticals in Europe have seen a sharp surge, whereas the cyber readiness of the organizations has come to a halt. The report highlighted that 61% of the firms experienced a cyber incident in the past year, up from 45% in 2018. Financial losses that accounted for $1,67,000 have risen five times to nearly $7,20,000.  Despite these alarming numbers, the cyber readiness of the firms seems to be moving at a snail’s pace, as only 10% of the surveyed companies achieved expert status and 74% were tagged as unprepared novices. The survey included nearly 5,400 private and public sector organizations from the U.S., UK, Belgium, France, Germany, Spain, and the Netherlands.

 

Ransomware Alert for Garmin’s Watch?

Garmin ransomware attack

IoT devices like wearables and smartwatches have often been touted as the next big thing as the IoT industry is expected to grow from 7.6 billion in 2019 to 24.1 billion in 2030, thereby drawing a huge revenue of more than $1.5 trillion, at 11% CAGR. These numbers are truly humongous and seem to catch the eyes of cybercriminals like it probably happened in the case of Garmin.

Garmin Hit by a Ransomware Attack?

Garmin, a known GPS and wearable smartwatch device manufacturer, is suspected of being attacked by a ransomware that led to a two-day complete service outage (on July 24 & 25) of its website and other services including customer support. According to the information provided by iThome, a Taiwanese tech news source, Garmin’s internal employees were told that the IT server was attacked by a computer virus and the entire production line was down as a result.

However, Garmin has not yet officially confirmed the ransomware attack. Instead, its official website stated, “We are currently experiencing an outage that affects Garmin.com and Garmin Connect. This outage also affects our call centers, and we are currently unable to receive any calls, emails, or online chats. We are working to resolve this issue as quickly as possible and apologize for this inconvenience.”

Since the smartwatch maker records personal, sensitive, physiological information and exercise data across its broad range of wearable devices, users are also concerned about the extent of disruption and data compromise that could happen if the allegations are upheld to be true. In the meanwhile, many users reported that their Garmin smartwatch data was not getting synced and, in some cases, certain historical and physiological data appeared to be lost.

The Rise of IoT Draws New Security Concerns

Earlier, research named, “The Internet of Things: Consumer, Industrial & Public Services 2020-2024,” from Juniper Networks found that with the number and purpose of connected devices increasing rapidly, the concerns over security threats also increase. The research stressed that IoT networks must implement steps to maximize security in all layers of the IoT ecosystem, including devices and connectivity. The research advised enterprises to implement the necessary security measures to defend against cyberattacks. It suggested two key areas of focus — the use of network segmentation to mitigate cyber risks and to ensure that the lifecycle management of network assets is properly maintained.

Cyber Risk Looming Over U.K. Sports Sector; Ransomware and BEC Attacks Common

Hackers Target Sports Sector with Ransomware, BEC Attacks

The U.K.’s National Cyber Security Centre (NCSC) warned about the increasing cyber risks like phishing, ransomware attacks, and Business Email Compromise (BEC) schemes targeting football clubs, teams, and sports authorities. In its report “The Cyber Threat to Sports Organizations” NCSC revealed that around 70% of sports organizations suffered a breach or a security incident and 30%  reported over 5 incidents in the last 12 months that caused a financial damage of £10,000 (US$ 12,700), with the biggest single loss of over £4 million (US$ 5,100,000).

BEC Fraud on Sports Club

The report highlighted two BEC fraud attempts that targeted a Premier League football club and a U.K. sporting body through spoofed Office 365 accounts.

  • The Managing Director of the football club fell victim to a spear-phishing attack that compromised his email login credentials. “During a transfer negotiation with an overseas football team the email address of the managing director of a Premier League club was hacked by cybercriminals. Only a late intervention from the bank prevented the club from losing almost £1 million (US$ 1.27 million),” NCSC explained.
  • In the case of the sporting body, threat actors compromised employees’ email accounts and set up auto-forwarding rules to external email accounts and re-routed almost 10,000 emails that contained sensitive data of more than 100 individuals.

Ransomware Attack

The report also highlighted that 40% of cyberattacks on sports organizations involved malware infection and 25% of them involved ransomware. According to NCSC, threat actors compromised corporate systems of an English Football League (EFL) club in a ransomware attack and asked to pay a 400-bitcoin ransom (approximately US$ 3,800,000). “The attack encrypted almost all the club’s end user devices, resulting in the loss of locally stored data. Several servers were also affected, leaving the club unable to use their corporate email. The stadium CCTV and turnstiles were non-operational, which almost resulted in a fixture cancellation,” the report said.

Paul Chichester, Director of Operations at the NCSC, said, “While cybersecurity might not be an obvious consideration for the sports sector as it thinks about its return, our findings show the impact of cybercriminals cashing in on this industry is very real. I would urge sporting bodies to use this time to look at where they can improve their cybersecurity – doing so now will help protect them and millions of fans from the consequences of cybercrimes.”

 

BadPower Attack: How Hackers Damage Smartphones Using Fast Charging Feature

How Attackers Invade a Fast Charger to Breakdown Your Device

Fast chargers let users charge their smartphone batteries faster than normal by increasing the voltage. However, some fast chargers can destroy the devices and compromise the built-in firmware if they fall into hackers’ hands, according to a research from Xuanwu Labs, Tencent Security.

The BadPower

Xuanwu Labs researchers stated that the fast charger technology includes both power transmission and data transmission functions. They found that some manufacturers have designed interfaces with protocols that can read and write built-in firmware in the data channel, however they lack effective security verification of the read and write behavior of the technology. The fast charger protocol has a memory corruption issue which could be misused by an attacker to rewrite the firmware of the fast charging device and control the power supply behavior.

The researchers explained two possible attack scenarios dubbed as “BadPower” in which an attacker can invade a charger and other devices supporting fast charger technology. The researchers tested 35 out of the 234 fast charging devices, and found 18 devices with BadPower problems, and 11 devices that can be attacked through digital terminals.

Scenario 1: BadPower Attack Procedure Using Special Hardware

  • The attacker uses a special device disguised as a mobile phone to connect to the charger’s charging port to invade the charger’s internal firmware.
  • If one uses the hacked charger to charge other devices, the charger will perform a power overload attack on the powered device.

Scenario 2: BadPower Attack Procedure via a Common Terminal

  • The attacker invades the user’s mobile phone, notebook computer and other terminal devices in some way, and implants malicious programs with BadPower attack capabilities in them, making the terminal device an attack agent of BadPower.
  • When the user connects the terminal device to the charger, the malicious program in the terminal device invades the internal firmware of the charger.
  • When the user uses the hacked charger to charge the device again, the charger will carry out a power overload attack on the powered device.

“Using BadPower, an attacker can hack into devices such as chargers that support fast charging technology, causing the intruded device to output an excessively high voltage when powering externally, resulting in breakdown and burning of the components of the powered device, and causes further damage to the powered device. The physical environment where the equipment is located creates a safety hazard,” the researchers explained.

Cyber Risks with Chargers

In a similar research, cybersecurity experts stated that using someone else charging cable might bring threats to mobile devices. Attackers could exploit charging cables/cords to access sensitive information from the victim’s mobile. They could implant malware into charging cords or cables to hack mobile devices. The USB chargers can be turned into potential hacking devices by inserting a malicious chip that allegedly allows attackers to access a mobile’s data over open Wi-Fi networks. The surprising part here is that the person who is lending the charger might not be aware that his/her charger is infected.

 

Stressed, Distracted Employees Exposing Organizations to Cybersecurity Risks: Study

Employee habits

A research from email security firm Tessian found that stressed and distracted employees are exposing organizations to cybersecurity risks. In its report “The Psychology of Human Error,” Tessian revealed that 43% of employees have made mistakes that led to security incidents, in turn jeopardizing the organization’s cybersecurity. 52% of employees admitted that they make more mistakes when they are stressed, whereas 43% of them said they are more error-prone when tired. Around 58% of employees have sent an email to the wrong person at work, and 1 in 5 companies lost customers due to misdirected emails sent to unknown person outside the organization.

Risks from Distraction

The research also highlighted that 33% of employees never think about cybersecurity while working. Nearly 45% of respondents cited distraction as the primary reason for falling for a phishing scam. And 57% of employees admitted that they are more distracted when working from home. Other reasons for employees falling for phishing attempts are: the perceived legitimacy of the email (43%) and the fact that it appeared to have come from either a senior executive (41%) or a well-known brand (40%).

Phishing Attempts

Phishing is one of the major security risks for an organization, as attackers try to target the entire network system. It is found that 1 in 4 employees (25%) said they have clicked on a phishing email at work. Men were twice as likely as women to fall for phishing scams, with 34% of male respondents saying they have clicked on a link in a phishing email versus just 17% of women. The research also stated that older employees were the least susceptible to phishing scams, with just 8% of them admitting they clicked on a phishing link.

“The older generation has, in many ways, the potential tools and mindsets needed for detecting phishing attacks. They have more life experience, and they tend to have strong, close networks which means they are good at detecting when something does not feel quite right. But if you are less experienced with these kinds of attacks, they are going to be harder for you to spot,” said Stanford University Professor Jeff Hancock.

“Understanding how stress impacts behavior is critical to improving cybersecurity. When people are stressed and distracted, they tend to make mistakes or decisions they later regret. Working in unusual environments can be stressful and distracting. The events of 2020 mean our personal and professional spaces have blurred, and we’ve had to quickly learn new ways of operating and this has its challenges,” Hancock added.