Home Blog Page 190

Pay-up! Hackers Demand $7.5 Million to Free-up Telecom Argentina’s Systems

New Telecom Security Bill UK

An Argentine telecommunication services provider, Telecom Argentina, reportedly fell prey to a ransomware attack on July 18, 2020. The effects of the attack were first noticed when the Telecom’s employees started facing issues and lag in their systems while accessing the company’s VPN (virtual private network). The internal security systems instantly set-off the alarms but not before the ransomware was installed in over 18,000 workstations. According to reports and screenshots shared over Twitter, the ransomware gang demanded a ransom worth $7.5 million in Monero (XMR) cryptocurrency.

The Ransomware Attack as it Happened…

  • The attack was initiated in the early hours of July 18, 2020.
  • It affected more than 18,000 internal systems of Telecom Argentina.
  • The ransomware was reportedly targeted at the company’s customer relationship management (CRM) software Siebel, which contains client data.
  • Telecom’s internal systems and software including Office365, OneDrive, corporate VPN, Citrix, Genesys, the Customer and Field Service virtual machines were also affected.
  • Its users’ internet or telecommunication services were not affected.
  • Reports suggest that ReVIL, better known as Sodinokibi ransomware operators were behind this attack.
  • The operators demanded 109345.35 Monero coins (worth approximately US$7.53 million) as ransom in exchange for the decryption key.

Although there is no official statement given by Telecom Argentina about the source of compromise, the researchers indicate that it could have been caused by a careless employee who opened a malicious email file that triggered the entire event. However, Sodinokibi ransomware operators are popularly known to exploit network and code vulnerabilities like remote code execution for targeting their victims. Thus, if this holds true then the gang may also have acquired a phishing technique under its armory for infiltration.

Telecom Argentina also confirmed that none of its dependent services were affected and have asked its employees to look out for malicious email attachments and suspicious activities on its networks as remedial measures.

Cybersecurity Investment Estimated to Grow up to 6% in 2020

Cybersecurity Investment Estimated to Grow up to 6% in 2020

Security research firm Canalys reported that cybersecurity spending will remain as an essential expenditure for most organizations in 2020 as cyberthreats and vulnerabilities continue to affect the industry. In its analysis report “Global Cybersecurity 2020 Forecast,” Canalys revealed that cybersecurity spending across the globe is estimated to grow between 2.5% ($43.1 billion) and 5.6% ($41.9 billion) in 2020, depending on the economic impact . Organizations are investing to enhance their endpoint security, network security, web and email security; data security, vulnerability detection, and security analytics —  to boost their security defenses in the wake of present remote working conditions.

While network security remains the largest segment in cybersecurity spending at 36%, the research stated that the endpoint security segment will witness high growth rates due to remote working practices.

“Cybersecurity will remain a top priority for most organizations in 2020, as threats and vulnerabilities persist and compliance, regulations and ecosystem requirements strengthen. It underpinned the mass shift to remote working during the lockdown by securing newly provisioned endpoints, providing secure access to corporate resources, and extending perimeter defenses beyond physical corporate networks,” the report stated.

Image Source: Canalys

Matthew Ball, the Chief Analyst at Canalys, said, “The shift to subscriptions will shield cybersecurity from immediate IT spending cuts, but additional expenditure will be affected for the rest of the year as organizations begin the next stage in their response to the pandemic. The switch from free trials to paid-for subscriptions will be a factor in maintaining cybersecurity growth. But the mix of cost containment measures, workforce reduction and cashflow issues will result in greater scrutiny of existing projects and smaller deals. Delays and cancellations of new initiatives will increase, except those that enable cost reductions and secure high-priority digital transformation initiatives.”

Budgets will be reprioritized to defocus spending on traditional appliance-based perimeter defenses. Spending on key areas of security will help address new vulnerabilities through multi-layer prevention, detection and response.

Ketaki Borade, Canalys Research Analyst, said, “The emergence of COVID-19 in January saw a surge in targeted phishing campaigns and malicious domains established to lure end users searching for information. These fell once lockdown took effect. But hackers continue to target organizations and individuals by compromising unsecured and poorly trained remote workers via numerous vectors, including email, social engineering and RDP brute force attacks. Organizations will to have reassess changes to workflows, application use, customer engagement and training for cybersecurity awareness in a more virtual workplace.”

 

Football Site Fun Fantastico Suffers Data Breach; 150,000 Records Exposed

credential phishing campaigns

A security investigation from cybersecurity firm WizCase discovered a misconfigured Amazon S3 server that exposed data of Mexican football site, Fut Fantastico. The data breach exposed personally identifiable information (PII) of 150,000 active and inactive users, including the full names, email addresses,  birth dates, date of user registration, gender, notification settings, last login details, in-game statistics, and IP addresses registered between 2017 and 2019.

Owned by Televisa, Fut Fantastico allows football fans to create a virtual soccer team of their choice for gaming experience. The misconfigured bucket is now secured after WizCase reported the data leak to the site owner.

The researchers at WizCase stated that threat actors can use the leaked information to perform malicious activities. “The misconfigured bucket could allow scammers and criminals unrestricted access to various personal information. From the exposed data, an unauthorized person can find out, among other details, a user’s name, and location. This breach of privacy could pose big threats to everyone involved. With personal details readily available, hackers can use them for fraudulent activities or to make new identities. The latter can assist in creating new bank accounts, take over existing ones, purchase illegal items, or even acquire legit legal documents such as passports or driving licenses,” WizCase said.

Football Fans Continue to Suffer Data Breaches

Football fans across the globe continue to suffer data breaches. Recently, Australia’s AFL fan website fell victim to a security breach where private data of 70 million users was compromised. Researchers from SafetyDetectives stated that they found around 132GB of data from a leaky Elasticsearch database including private user data and technical information relating to the company’s website, BigFooty.com. SafetyDetectives notified the incident to the BigFooty authorities and also reported to the Australian Cybersecurity Centre. BigFooty.com is an Australian web and mobile application focused on Australian football rules. The site allows users to interact with each other on a range of topics with football being the prime focus for most users.

 

Security Analytics – Approaching Cybersecurity Proactively

Google Cloud

There are glaring holes in how enterprises currently tackle security analytics, and by redefining the approach, the analyst’s role can be transformed. Rani Hmayssi, Regional Manager Google Cloud Middle East explains how.

1. What are the top challenges organizations face to achieve effective threat detection and producing proactive security measures?

When it comes to proactive threat detection, the top challenges we see organizations face pertain to scale, cost, speed, and productivity.

Accurate threat detection takes place when security teams are able to collect and store as much security telemetry as possible. Full detection requires full visibility. The current solutions for threat detection make it cost-prohibitive to keep all the necessary security telemetry, which adds time to the security investigation process and can cause threats to go undetected.

At the end of the day, the security landscape has changed. Security systems are easily generating petabytes of data, so it’s important to have the right tools that can accommodate this volume and then help deliver accurate detection.

With all your security data on hand, security teams can also perform proactive threat hunting and take advantage of simpler, but more powerful analytics constructs like YARA-L, Chronicle’s new rules engine syntax. These techniques enable and empower tier 1 SOC analysts to increase their productivity and perform better incident response.

2. Amid the COVID-19 lockdown, there has been a surge in potential cyberattacks such as email phishing, VPN-based attacks, enterprise network attacks, and other threat vectors.  What should companies do to get ahead of the attack curve and how is security analytics changing the game?

Ransomware attack on Colonial Pipeline

We definitely emphasize with our customers when it comes to new security risks associated with COVID-19. There has been a surge of phishing attacks targeting employees and threat actors looking to compromise VPN systems.

Security analytics can help enterprises get ahead of this attack curve by making it easy to understand the scope of a phishing attack. Phishing campaigns, for example, use numerous variants such as malicious domains, URLs, and files that need to be quickly identified.

Using a security analytics platform, you can see the enterprise-wide prevalence of any indicator of compromise in a suspected phishing email. For example, if an email contains a link, you can search Chronicle for that link to find any and all network connections to it. If the email contains an attachment, you can search Chronicle for all occurrences of that file. From there, you have the ability to rapidly or automatically delete known and confirmed phishing emails or reset account credentials for phished users.

3. What are your customers’ main objectives when it comes to security analytics and operations?

The main objectives for implementing a security analytics platform are SOC productivity, efficacy of threat detection, and economics. In the current climate, enterprises are looking to get more out of their security budget and the ability to do more with their technology. Security analytics allow business to cut costs associated with storing security data and give analysts the power to efficiently perform investigations by having all security information in one place. New and more powerful threat detection frameworks like YARA-L also enable detection of a broader range of threats in a more efficient manner.

In addition to cost savings, there is a growing need to cut down on caseloads and increase time to detection and time to remediation. With the correlation provided by security analytics, analysts have broader threat coverage across the enterprise, including the ability to detect threats that operate low and slow.

4. Technologies that monitor cyberattacks generate a high volume of alerts from different systems that can’t all be analyzed. Is there a way to prioritize the high-risk alerts?

IaaS

We definitely see security teams suffer from alert fatigue and determining whether an alert needs to be escalated or marked as a false positive can be a time-consuming task. Using security analytics, investigation teams can come to conclusions faster by providing the right context to help understand severity and determine action steps.

With a platform like Chronicle, you can perform retroactive threat intelligence scanning which looks at all incoming indicators of compromise and map it to your data automatically. As soon as a new domain, URL, IP or hash is reported by a threat intelligence feed, Chronicle searches through one year of historical logs to see if your organization is impacted and will also look for these indicators in the future.

Chronicle also provides context for an alert across three dimensions: the user, your enterprise assets, and the severity of the threat. By having all the context you can quickly answer questions like:

  • What other suspicious behavior has been seen on a particular device?
  • Are there any new unauthorized domains or connections present in the network?
  • Does activity tied to a specific user suggest anomalous behavior, such as compromised credentials?

5. The last couple of years have shown security professionals slowly shifting to cloud-based security analytics. What drives that change and what are your predictions for the next couple of years?

The big shift we’re seeing is that security analytics has become a big data problem. Today, even mid-sized organizations may generate petabytes of security telemetry. Security teams, however, aren’t in the business of managing big data and the underlying infrastructure required to keep up with these volumes. On top of this, budgets have largely shifted from capex to opex, which means budgets won’t be spent on more hardware to support security telemetry. CISOs want their staff to perform security operations, not infrastructure management, which is why it makes sense to invest in SaaS-based security analytics with unlimited data storage.

For the next couple of years, we predict that the use of cloud-based security technology is going to change the game. For example, the capacity of the cloud to help bring shared intelligence to enterprises is super powerful. We see the opportunity for sharing intelligence at both geographical and vertical levels. Imagine seeing increased attacks on organizations in a certain country in Europe, or a new phishing attack targeting banks and then being able to anonymize these threat signals to help ensure all our customers are protected.

Download your copy of Redefining Security Analytics to learn how to investigate and hunt at the speed of search here.
Follow us on Twitter: @GoogleCloud_ME

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

E-Learning Platforms Continue to Suffer Data Breaches; 1 Mn Records Exposed

School apps sharing students’ data

Security researchers from WizCase discovered unprotected databases belonging to multiple e-learning platforms that were exposed online without password protection. The unencrypted databases leaked personally identifiable information (PII ) such as  names, emails, passwords, ID numbers, contact numbers, addresses, birth dates, course details, and school information, of one million users.

The databases were hosted on misconfigured servers, which allowed anyone to access it without any authentication. WizCase stated that it found five breaches from separate online educational institutions across the globe.  The data was stored and managed on four Amazon S3 buckets and one ElasticSearch server.

Image Source: WizCase

According to WizCase, the five e-learning platforms that suffered data breaches include:

  • Escola Digital, a Brazil-based online learning platform, suffered a data leak that exposed over 75,000 private records (15MB) of students and teachers.
  • South Africa-based online learning platform MyTopDog lost over 800,000 students’ personal records (40-50MB).
  • Okoo, a Kazakhstan-based online course portal, lost around 7,200 records (418MB) that held students’ personally identifiable information and administrative data.
  • The U.S.-based online education platform Square Panda lost around 15,000 personal records (1MB) of parents and teachers.
  • S.-based virtual learning platform Playground Sessions’ data leak exposed nearly 4,100 user records (1.2MB).

The vulnerable data poses myriad cyberthreats and can be used in several online crimes, since many of the affected users are children and young people. Threat actors can use the leaked data to launch various attacks like identity theft, stalking, blackmailing, and phishing scams.

Cyberattacks on E-Learning Platforms Rise

There has been a surge in the usage of online learning platforms during the ongoing pandemic. Hackers targeted multiple e-learning portals to steal users’ personal information. Recently, India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe.

 

U.K. Government Proposes IoT Security Rules, Non-compliance May Lead to Fine

IoT attacks

A proposal from the U.K. government stated that insecure IoT devices that are used in households and businesses could be banned from sale or removed from the market if they fail to meet the basic security standards. The new security regulations are intended to protect  the digital infrastructure from the evolving cyberattacks on connected devices.

The U.K.’s Department for Digital, Culture, Media, and Sport (DCMS) and the National Cyber Security Centre (NCSC) have chalked three security requirements that IoT manufacturers need to comply with if they want to sell their devices in the country. Initial non-compliance may lead to a fine or penalties using civil enforcement, however, continued non-compliance may lead to criminal action in accordance with the scale of the offence.

The proposed  security requirements include:

  • Ban universal default passwords in consumer smart products
  • Implement a means to manage vulnerability reports
  • Provide transparency on for how long, at a minimum, the product will receive security updates

However, the government is also seeking feedback and suggestions from IoT manufacturers on the proposed regulations to collectively enhance IoT security.

“Manufacturers do not embed even the most basic approaches to cybersecurity into their products, leaving consumers unnecessarily exposed to a range of harms. Most consumers overwhelmingly assume that products available in store and online are safe by default; the reality is that a number of insecure consumer smart products remain stocked on our shelves,” said, Matt Warman, Minister for Digital Infrastructure.

“The government’s intention is to design future-proofed legislation that will remain relevant amidst the rapid pace of technological change and innovation across the consumer smart product sector. The government will therefore seek to design this legislative framework so that it could be rapidly updated as necessitated by the evolution of the consumer smart product landscape, in consultation with relevant stakeholders,” Warman added.

IoT Devices to Dominate the Market

Earlier, a research by Transforma Insights revealed that the number of active IoT devices globally is expected to grow from 7.6 billion in 2019 to 24.1 billion in 2030, thereby generating revenue of more than $1.5 trillion, at 11% CAGR. The findings also stated that North America, China, and Europe are expected to have a lion’s share in this growth of IoT devices with 26%, 24%, and 23% respectively of the total value.

 

Human – The Weak Link in the Recent Twitter Hack

Twitter hack

Twitter was left red-faced last week with an account hacking incident that compromised nearly 130 accounts including Twitter handles of world celebrities, prominent figures, and Twitter employees. In view of the investigations conducted post the breach, Twitter found that it was the human-factor that led to the hack in the first place.

 The Weak Link

With all the advanced security measures and tools in place, we often feel that our business perimeter is secured. However, it is not the process or technology that proves to be the weak link; it is the human that is the weaker link in cybersecurity. As per a survey by Black Hat, 91% of social engineering attacks are launched with a phishing email. It says, “A single human mistake, can result in an attacker taking over all of the organization’s infrastructure, no matter what hardware, software, or endpoint security implementation has been done from the defensive team,” and this is exactly what resulted in the Twitter hack.

According to Twitter, the attackers first targeted its employees through a social engineering attack to which a few of them fell prey to. The compromise meant that the attackers now possessed the login credentials of Twitter employees required to gain access into Twitter’s internal systems and tools. The sophistication of the attackers can be gauged from the fact that they even circumvented its two-factor authentication (2FA), which was in place to avoid such a security incident. Once in, they specifically targeted 130 Twitter accounts of which 45 were used to send tweets after the attackers reset their passwords.

Things We Know So Far About the Twitter Hack…

  • Attackers used a “social engineering attack” to target Twitter employees.
  • Nearly 130 Twitter accounts were hacked once the attackers gained access to Twitter’s internal system and tools using compromised employee credentials.
  • They also bypassed the two-factor authentication (2FA) of these accounts.
  • Attackers were able to initiate a password reset, account login, and Tweet sending for 45 accounts.
  • Personal information including email addresses and phone numbers of certain users may have been viewed by the attackers along with some additional info.
  • However, the attackers could not view previous account passwords, as these are encrypted and cannot be accessed using the tools used in the attack.

Twitter’s Way Forward

Taking remedial measures, Twitter restricted the affected accounts from tweeting or resetting the password. With the investigation still going on, the work is cut-out for Twitter going forward. Its core objective to prevent future hacks include:

  • Restoring account access of all affected users who may still be locked out because of their remediation measures.
  • Continue further investigation and co-operate with law enforcement authorities in their combined efforts.
  • Increase security measures of its systems to prevent a relapse.
  • Provide and implement company-wide cybersecurity training against social engineering tactics like phishing emails and SMSs, and keep their employees updated with ongoing phishing campaigns throughout the year.

How to Secure Your Home Wi-Fi Network

KCodes NetUSB, FragAttacks on Wi-Fi connected devices

The Wi-Fi router has become the most important gadget in every household as most employees are currently working from home. Remote workers require endpoint devices such as a laptop/desktop, tablet, and smartphone that need an internet connection. Several experts warned that the proliferation of connected devices and unpatched vulnerabilities in them might create a security blind spot for cybercriminals to compromise other devices like smart security webcams, smart TV,  or a smart home, that are linked to the same Wi-Fi network.

By Rudra Srinivas, Feature Writer, CISO MAG

Securing your home Wi-Fi network is essential when it comes to protecting your data against cyberattacks. Here are some ways to secure your home network:

1. Use VPN

A VPN (Virtual Private Network) helps improve data privacy and security on the internet. VPNs provide a secure connection for users when joining another network online. It also changes your IP address and location, making your browsing activity safe and private from threat actors. With a VPN connection, remote employees can connect to their corporate networks securely with end-to-end encryption enabled. Even if hackers penetrate your network, they still cannot access your data in transit or compromise your Wi-Fi router with when a VPN is used.

2. Use an Arbitrary Password

According to a  study, three-quarters of millennials in America use the same password on more than ten devices, apps, and other social media accounts. It also stated that most of them were using the same password in over 50 different places.

Every router comes with a default username and password for installation purposes. If you continue to use the wireless network without changing its default credentials, it will be easy for attackers to guess your login details, if they know the router manufacturer. Make sure you have a strong and complex Wi-Fi password which is difficult to guess. It is also recommended to change the Wi-Fi password on a regular basis. Using a passphrase rather than a password will give you maximum security for your network, however, make sure the passphrase you choose is easy-to-remember and complex as well.

3. Stay Updated

Wi-Fi routers run on low-level software called firmware that controls the router operations. Like any other software, a router’s firmware might contain vulnerabilities and could be exploited. Updating your router’s software regularly will help apply security patches and protect against known vulnerabilities. Some modern routers update their software automatically, and some routers don’t —  but irrespective of the model, it is always recommended to update the firmware to secure home networks.

4. Hide Your SSID

An SSID (Service Set Identifier) is a series of characters that uniquely names your network. It allows the users to connect to the desired network from multiple networks available in a particular area.

If attackers know the type of router you have, they may try to exploit the known vulnerabilities to break into your network. So it’s a bad idea to have your router brand included in the SSID. Changing your Wi-Fi network’s default name makes it difficult for threat actors to find out the name of the router manufacturer, and determine the default password. Including your name in the your Wi-Fi network as in “Mike’s Wi-Fi” is not recommended, as you do not want hackers to know your name. Disclosing your personal information on a network name may expose you to identity theft or brute force attacks.

5. Enable Firewall

Most Wi-Fi routers come with built-in firewalls that secure your Wi-Fi connection from network attacks. However, they are often disabled by the manufacturer while shipping. So, make sure your router’s firewall is enabled to add an extra layer of protection against malicious actors. Install a good firewall, if your router does not have one. Regularly crosscheck which devices are linked to your home network to make sure they too have a protection tool installed.

Wrap-Up

Cybercriminals are using advanced hacking tools and techniques to break into users’ networks/devices to steal sensitive information. It is our responsibility to secure our personal devices, endpoint devices and networks, in turn securing corporate networks from online intruders.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

Endpoint Security: No More a Blind Spot for Remote Work

endpoint security

The COVID-19 pandemic has forced businesses to operate remotely. While working from home is becoming the new normal, the drastic change in the SOPs of businesses has paved a way for the inception of additional cyberthreats. And the need for endpoint security has never been more important.

By Pooja Tikekar, Feature Writer at CISO MAG

Endpoints or end-user devices such as desktops, laptops, smartphones, tablets, and Internet of Things (IoT) devices (like smart home appliances) are playing a significant role in communicating back and forth during the current work from home (WFH) scenario. But how secure are these devices?

Myriad Security Challenges Posed by Endpoint Devices

1. Unsecured Wireless Access Point (WAP)

Before the outbreak of the COVID-19 pandemic, employees working out of public co-working spaces such as cafes, hotel lobbies, railway stations, and malls used “public Wi-Fi” connections. The word “public” encourages a stampede of cyberthreats as Wi-Fi is free and lacks encryption of data. However, today, home private networks are just as vulnerable due to the increased adoption of Bring Your Own Devices (BYOD) and WFH infrastructure. According to a survey conducted by access management solutions provider CyberArk, 77% of remote workers have been using unmanaged, insecure endpoint devices to access corporate systems.

2. Data Breach

Remote employees may risk-sensitive corporate data by uploading it on public cloud or unsecured home networks. This is an open invitation to opportunist hackers to easily access, steal, or misconfigure the data left open or visible without strict in-network cybersecurity. A study conducted by global intelligence firm IDC revealed that nearly 80% of the companies surveyed experienced at least one cloud data breach in the past 18 months, and nearly half (43%) reported 10 or more breaches.

3. IoT Incursions

Internet of Things (IoT) has leveraged how we operate and optimize operations in real-time, however it also opened new avenues for security incursions through hardware, software, cloud, and enterprise networks. Gartner’s 2019 research forecast a 21% increase in the enterprise and automotive Internet of Things (IoT) market in 2020 (totaling to 5.8 billion endpoints). Considering the number, IoT endpoints are potential targets if they are deployed outside standard IT security perimeters.

4. Malware and Phishing

Hackers are using social engineering tools to formulate phishing emails in the name of the World Health Organization (WHO) and other regulatory bodies to lure end-users into opening documents with embedded links that result in malware and ransomware attacks. According to Beazley Breach Response (BBR) Services, Q1 2020 witnessed a 25% surge in ransomware attacks, compared to Q4 2019.

Some of the rampant ransomware that bypass endpoint security in the name of COVID-19 include:

  • CovidLock
  • Dharma (CrySIS)
  • Emotet
  • Maze
  • REvil
  • NetWalker

In light of the current pandemic, the enterprise network perimeter is replaced with endpoint networks to conduct business using mobile devices. Although traditional antivirus software is central to endpoint security, it is not always enough. Every entry point needs additional protection to authorize control over access points and prevent attack vectors.

Endpoint Risk Mitigation Measures

Since endpoint threats are fileless, organizations need to strategize adequate and effective security solutions. Some of the key measures of endpoint management include:

1. Endpoint Visibility

It is advisable that businesses allow only those devices that are approved to connect to their networks. Endpoint detection gives an upper hand over advanced or unknown threats, analyze vulnerability, and come up with patching solutions. Corporates must audit their endpoints (perimeter) and ensure that they have complete visibility of all endpoints on their network. Revoke access to unauthorized endpoints and back this with a clear security policy.

2. Scrap Unnecessary Data

Scrapping or deleting unnecessary data and uninstalling Potentially Unwanted Applications (PUAs) from endpoints will free up excessive memory and prevent security risks. PUAs installed on endpoint devices may collect information without the user’s consent and display excessive advertisement popups interrupting the smooth functioning of the device.

3. Routine Patch Management

Businesses need to set up routine patches to address issues concerning operating systems and out-of-date certifications and licenses. Having a structured and proactive patch management program lessens system outages. IT governance should include patch management and OS or Windows updates on endpoint devices.

4. Device Control

Blocking or disabling USB ports, DVDs, or access to any other form of external media helps protect endpoint devices against malware. Device control must be a mandatory administrative policy for a company’s cybersecure environment.

5. Virtual Private Networks (VPNs)

Having a VPN technology in place offers end users safe remote access to corporate networks and data safety can be ensured through multi-factor authentication (MFA). Enabling MFA or 2FA for all internal applications and corporate virtual private networks (VPNs) prevents identity theft because an employee’s device is a treasure chest for threat actors.

6. Virtual Desktop Infrastructure (VDI)

Another solution is to switch from standalone desktops and laptops to virtual desktops. VDIs live within virtual machines (VMs) on a centralized server and are accessed over a network with an endpoint device or “thin” client such as a tablet or Chromebook. Since VDI computing takes place on a secure host server, endpoint devices are less likely at risk.

Conclusion

Building a secure endpoint ecosystem is the need of the hour. Hackers want to compromise any and every device because cybercrime is a booming business to siphon billions. As wireless endpoint devices inch closer to acting as corporate infrastructure in the current remote work scenario, debunking the myth that wireless hijacking cannot be done across remote geographic locations becomes more critical.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

Why You Should Avoid Social Logins and SSO

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

The Twitter accounts of top celebrities were recently hacked. You could be the next victim, only to be locked out of your Twitter account. And social logins could be the reason. When consumers register for online services they are usually presented with options and can use their existing Facebook, Google, Microsoft, Apple, or Amazon IDs to login to that service. These are called social logins. Some services also offer options to use LinkedIn and Twitter accounts for login. And in others, you could use your mobile number. This concept is also known as single sign-on or SSO. But using social logins on third-party websites can result in credential or identity theft and hacked social media accounts. In fact, Digital Shadows found threat actors trading more than 15 billion usernames and passwords, including over 5 billion unique credentials on various hacking forums on the dark web. Many of those credentials include stolen social logins. Here’s how social logins get stolen and what you can do to prevent it.

By Brian Pereira, Principal Editor, CISO MAG

SSO was originally developed for IT administrators who found it cumbersome to remember IDs and passwords for hundreds of IT services, servers, and enterprise applications. SSO enables them to use a single password and user ID to use multiple services on the corporate network. Well, in recent years, SSO also came to the web for consumers. For instance, if you log into Gmail, you can open other Google services (in separate browser tabs) without logging in repeatedly. The same Gmail credentials can be used for Google Drive, Google Maps, Google Photos, etc. So, SSO systems are very practical and spare the end-user the need to remember multiple passwords.

Third-party web services take SSO a step further by connecting with social media sites through plug-ins, widgets, and APIs. SSO for consumer websites uses the OAuth industry standard for authorization. That enables consumers to sign into third-party websites/online services using their social media accounts. This is designed to simplify logins for end users as well as provide more reliable demographic information to web developers. Users struggle to remember multiple login IDs and passwords. So why not use something they already know? That sounds very convenient until one’s social media account gets hacked and taken over.

In 2018, the University of Illinois, Chicago, conducted a study on the top 1 million websites according to Alexa. The study found that 6.30% of websites support SSO. That was two years ago, and this number is much higher today. This highlights the scale of the threat, as attackers can gain access to a massive number of web services just by getting one’s social media credentials.

How Social Logins work

According to AuthO, Social Login is a simple process, with the following steps.

  • The end-user visits the third-party website (relying party or RP) and selects the desired social network provider (Identity Provider) for login.
  • A login request is sent to the concerned identity provider (IdP).
  • Once the IdP confirms the user’s identity, it sends an access token or authorization code to the RP, allowing the end-user to login to the RP’s website or service.
  • For the first login, a user will be registered as a new user and then logged into the application or service.

SSO tech is not perfect

SSO systems are far from perfect and have several potential problems. Wired Magazine UK quoted a research paper where five University of Illinois, Chicago, researchers said SSO tech can “pose a massive security risk”. The researchers created a proof-of-concept attack against Facebook, where they could completely take over an account. “Using a hijacked Facebook account an attacker could indirectly compromise an additional 226 [other services],” the researchers wrote. The research paper is titled: “O Single Sign-Off, Where Art Thou? An Empirical Analysis of Single Sign-On Account Hijacking and Session Management on the Web” and it was published in August 2018.

To quote from the research paper: “Due to the proliferation of SSO, user accounts in identity providers are now keys to the kingdom and pose a massive security risk. If such an account is compromised, attackers can gain control of the user’s accounts in numerous other web services.”

Following the release of this paper, Facebook CEO Mark Zuckerberg revealed that hackers had compromised the social network and accessed around 50 million access tokens. The tokens are generated once a user logs into Facebook and avoid users having to re-login every time they return to the website. Facebook tokens are reusable on other websites like Tinder, Spotify, and Airbnb. These sites also share user data with Facebook, thereby breaching user privacy. And this happens without the user’s knowledge.

How access tokens get stolen

There are multiple attack vectors that bad attackers use to steal access tokens or authorization codes. The technical details of these attack methods are beyond the scope of this article but you can find all the details in the aforementioned research paper. Some of the methods quoted in the paper are:

  • Phishing
  • Cookie hijacking (Sniff Wifi)

How to secure your accounts

  • Use two-factor authentication
  • Use an authenticator app like Google Authenticator
  • Do not re-use passwords across sites or services
  • Use a sentence or a string of random words as a password
  • Consider using a trusted password manager (like Norton Password Manager or LastPass) for all your accounts
  • Change the default passwords on gadgets you own
  • Change the passwords in your social media accounts every few months
  • Use apps on your phone for the same email and social media accounts you access through a desktop browser
  • Regularly check where account activity originates
  • Go through the security settings in your Google account and “revoke” access to apps you no longer use
  • Check the security settings in your social media accounts and review which third-party services have been linked to these accounts
  • Set up email notifications for suspicious logins
  • Link a few trusted devices to your Google account

Summary

In closing, we advise you to be very alert and aware while using social logins and SSO on websites. Check your account login activity regularly. Set up email notifications for suspicious logins. For instance, you can do this on accounts.google.com or in the security and privacy settings of your social media accounts. Check which third-party apps are linked to your Google, Facebook, and Twitter accounts and revoke access for apps or services you no longer use. If you set up alerts and notifications, the social media or email service will send you security alerts via email or SMS if it detects a suspicious login from a user in another country or from an unregistered device.