Home Blog Page 197

Europe Introduces 13 New IoT Cybersecurity Provisions

IoT attacks

To address the concern over the rising number of devices at home being connected to the Internet, the European Telecommunications Standards Institute (ETSI) launched a new cybersecurity standard (ETSI EN 303 645) to establish a security baseline. From large scale to prevalent attacks, this cybersecurity standard for Internet of Things (IoT) devices is an attempt to cover them all with 13 new provisions.

The Cybersecurity Standard for IoT Devices

Work from home has seen a major shift in the number of home devices connected to the internet. This has challenged the very fabric of traditional cybersecurity measures as they often do not cover the home periphery. To address these issues, ETSI  sought help from industry experts, academics and the government to define a standard that aims to restrict the ability of cybercriminals to control devices across the globe.

ETSI EN 303 645 includes the security of a wide range of IoT consumer devices and their associated services, including:

  • Connected children’s toys and baby monitors
  • Connected home safety products such as smoke detectors and window sensors
  • Smart cameras, TVs, and speakers
  • Wearable health trackers
  • Connected home automation and alarm systems
  • Connected appliances such as washing machines, and fridges
  • Smart home assistants

13 cybersecurity measures for consumer IoT devices listed under this standard:

  1. No universal default passwords
  2. Implement a means to manage reports of vulnerabilities
  3. Keep software updated
  4. Securely store sensitive security parameters
  5. Communicate securely
  6. Minimize exposed attack surfaces
  7. Ensure software integrity
  8. Ensure that personal data is secure
  9. Make systems resilient to outages
  10. Examine system telemetry data
  11. Make it easy for users to delete user data
  12. Make installation and maintenance of devices easy
  13. Validate input data

It is a known fact that many IoT devices store and process users’ personal data. IoT manufacturers are expected to provide security features to these devices for the protection of such personal user data. Apart from these 13 new cybersecurity measures and already defined GDPR compliance policies for data protection, the ETSI EN 303 645 standard provides five specific data protection provisions for consumer IoT devices.

IoT Devices to Dominate the Market

Earlier, research by Transforma Insights revealed that the number of active IoT devices globally is expected to grow from 7.6 billion in 2019 to 24.1 billion in 2030, thereby generating revenue of more than $1.5 trillion, at 11% CAGR. The findings also stated that North America, China, and Europe are expected to have a lion’s share in this growth of IoT devices with 26%, 24%, and 23% respectively of the total value.

PII of Thousands of Users Exposed in Multi-Stage Bitcoin Scam

multi-stage bitcoin scam, Google Ads crypto wallet scam

Threat intelligence firm Group-IB discovered personal records of thousands of users from the U.K., the U.S., South Africa, Spain, Australia, Singapore, Malaysia, and other countries exposed in a multi-stage bitcoin scam. It is found that the attackers used 248,926 sets of stolen personally identifiable information (PII) to pull people into a fake cryptocurrency investment scheme.

According to Group-IB’s investigation, a majority of the victims were from the U.K. with 147,610 records exposed, followed by Australia (82,263), the U.S. (4,147), South Africa (4,149), Singapore (3,499), Malaysia (2,491), and Spain (2,420). While the source of the data leak is still unknown, the researchers stated that the information has been provided to relevant authorities in the affected countries.

Image Source: Group-IB

“Victim’s phone numbers, which in most cases came with names and emails, were contained in personalized URLs used to redirect people to websites posing as local news outlets with fabricated comments of prominent local personalities about cryptocurrency investment platform that helped them build a fortune,” the researchers said.

Attack Vector

Group-IB identified all the stages of the attackers’ fraud scheme. Initially, hackers send a phishing message to the victim mimicking a popular media outlet. The message contains a malicious link that redirects the victim to another URL which is designed to trick users into entering their personal information like phone numbers, first and last names, and email addresses.

Image Source: Group-IB

The malicious URLs take users to fraudulent websites that host false interviews and comments attributed to local celebrities saying that they have made a fortune with this new cryptocurrency investment platform.  The researchers spotted six fake active domains showcasing the same bitcoin investment platform with different names like Crypto Cash, Bitcoin Rejoin, Bitcoin Supreme and Banking on Blockchain.

Image Source: Group-IB

“If a victim decides to click any link in the article, they are taken to a bitcoin investment platform website, where their data, contained in the URL, would already be pre-filled in the registration form without a user’s consent. Later a victim would be asked to add to their account balance in BTC,”  the researchers added.

Ilya SachkovIlya Sachkov, CEO and founder at Group-IB, said, “The bitcoin investment scams have been around for quite a while and we regularly detect new instances of crypto fraud. This time however the scheme was significantly upgraded, and a tremendous amount of personal information was leaked. The bad guys got smarter in a bid to increase the success rate of their fraudulent operations. Using personal data allows them to carry out targeted attacks and make a victim’s journey easier and smoother, which levels up the overall effectiveness of the scheme.”  

Stolen Data From 945 Websites Exposed on Darknet Forums: Report

SEO poisoning

Researchers from cybersecurity firm Lucy Security discovered a collection of two SQL databases exposed on darknet forums. It was found that the databases contain stolen information from 945 websites, hacked by different attackers from across the world. The databases host around 150GB SQL files which were released on June 1  and June 10 2020, respectively. The exposed information included usernames, phone numbers, full names, hashed and non-hashed passwords, IP, email addresses, and physical addresses.

Among the 945 compromised sites, the researchers identified 14 government sites belonging to Ukraine, Israel, the U.K., Pakistan, Russia, Lebanon, Belarus, Rwanda, and Kyrgyzstan. Over 14 million users are said to be affected in the incident.

“As if this was not alarming enough, this might be only the beginning. The entity who collected and shared the databases on the dark web claims to have gathered these so-called private databases without having committed any hacking by themselves, yet they also claim to possess even more databases, which they are planning to share or sell to the highest bidder,” the researchers said in a statement.

Connection to Collection #1 Breach

The researchers at Lucy Security clarified that the new data leak does not relate to Collection #1, a massive data leak that exposed 773 million records from different sources on dark web last year. “This is an entirely new threat, none of the databases were known to the public before,” the researchers said.

Darknet Flooded with Leaked Databases

Researchers from security firm Cyble stated that a hacking group “Shiny Hunters” is selling Wishbone.io database on darknet forums. The leaked database contained over 40 million records of Wishbone users–a social platform that allows users to compare social content via voting poll. It is found that the Shiny Hunters group was responsible for numerous data breaches including the breach of 73.2 million user records from over 11 companies. The hackers are also behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

 

3 Signs That Your Company Has A Security First Mindset

cloud, cloud security

As organizations consider moving to the cloud or architecting their applications in the cloud, security is top of mind. In the June 2020 cloud security survey, 68% of respondents stated that security, privacy, and compliance should be built in as foundational principles when migrating to the cloud. This finding is consistent with the rise of DevSecOps over the past couple of years and the “shift security left” mindset.

By AJ Yawn, Cloud Security Expert

This finding from the survey may sound a lot like DevSecOps, a concept in the security industry that is gaining more and more traction as teams embed security into the software development lifecycle. DevSecOps is Security + DevOps (Development + Operations) running together as a single, cohesive unit. The underlying principle of DevSecOps is to unite security teams and application developers, creating a collaborative environment where security is a shared responsibility in the continuous integration/continuous deployment (CI/CD) pipeline. DevSecOps is often focused on adding new security tools to integrate security in the software development lifecycle. The DevSecOps mentality does not have to be restricted to just the development teams, this mentality shows itself through three cultural security shifts in organizations.

Integrating Security Early

As security practitioners, we should aim to add security as a cohesive component of every part of the organization. The results of this survey show that technologists understand the benefits of integrating security and privacy at the beginning of the cloud migration process. Early inclusion of security and privacy will ensure infrastructure choices, availability planning, and compliance risks are examined before any business decisions are made.

It can be argued that cloud migration should not be the trigger to integrate security as an integral part of all organizational processes. Adopting a security-first culture allows organizations to implement the DevSecOps culture whether they are migrating to the cloud or not. There are a couple of actions that organizations can implement to ensure that security, privacy, and compliance are embedded in all organizational processes.

Making Security Everyone’s Responsibility

One of the reasons organizations implement DevSecOps is to prevent a security incident or event from occurring. DevSecOps is a cultural shift, not just a series of tasks or checkboxes to complete as you move through your CI/CD pipeline. This requires organizations to adopt the mind of a security practitioner which means everyone in the organization acknowledges that it is not a matter of if a vulnerability or flaw will be identified, but a matter of when. Assuming you will be breached or hacked changes the conversation internally and influences decision making on tools, technologies, and migration strategies. This shift in thinking will encourage security-conscious individuals outside of the security team to look forward to finding flaws and reporting them to the security team.

The development and growth of security-conscious employees in every department is an indicator of a strong security culture.

A security-first culture eliminates the blame game from cybersecurity-related issues and encourages a culture of fact-finding, issue-spotting, and investigation. We are no longer asking “who wrote this code?” when a vulnerability is discovered. This cultural shift means we are now asking:

  1. How do we fix this?
  2. How do we stop this vulnerability from occurring in the future?
  3. Can we automate the fix?

Those questions are application security specific however it is important to reiterate this is much more than just securing your application and integrating security tools into your CI/CD pipeline. A cultural shift involves all employees and departments considering the security implications of their processes and actions. For example, in a mature cybersecurity environment, the human resources (HR) team is educated on the implications of onboarding processes and procedures on your cybersecurity compliance assessments. This understanding facilitates an open line of communication between HR reps and security team members. This open line of communication facilitates collaboration on potential solutions that can alleviate the manual aspect of HR teams monitoring and proving compliance with cybersecurity regulations and frameworks. With the end goal of an automated security and compliance monitoring process that ensures new hires are onboarded according to your applicable compliance standards (i.e. background checks performed, access request created, security awareness training completed, etc.).

Automating Everything

Security automation has become increasingly important due to the thousands of threats facing organizations daily. It is virtually impossible to manually identify, protect, detect, respond, and recover to security events or incidents.

Automation will not work without a deep understanding of the business processes and risks security professionals are trying to automate. For this reason, the cultural shift described above is imperative to begin before implementing automation strategies. Automation makes security easy and reduces the burden on understaffed and under-resourced security teams.

When considering automation strategies, security practitioners must adapt security to the business processes and not expect business units to adapt to security. Security must remain an enabling function not a blocking function for automation to work. Security in the cloud requires and encourages automation of key security controls.

As organizations undergo annual compliance assessments, they should aim to make security controls programmable and automated wherever possible. Multifactor authentication (MFA) flaws and public storage services (specifically AWS S3 buckets) are two common risks facing organizations that would best be addressed through automation. For example, on AWS a simple, automated Force MFA and S3 Bucket Security configuration would significantly reduce two key security risks facing the organization without requiring the security team’s manual intervention.

An “automate everything” mentality encourages your organization and security professionals to consistently identify simpler and better ways to perform key functions.

Making Security Easy

Implementing security, privacy, and compliance earlier in the process for all projects, including cloud migrations, makes security easier for everyone involved. It makes sense that over two-thirds of survey respondents believe this is a top security concern when migrating to the cloud. It also makes sense to begin taking the initial steps to integrate security within your overall organizational culture encouraging a relentless focus on automating security.

About the Author

AJ Yawn, Cloud securityAJ Yawn is a cloud security subject matter expert that possesses over nine years of senior information security experience and has extensive experience managing a wide range of compliance assessments (SOC, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers. He has earned several industry-recognized certifications, including the CISSP, AWS Certified Security Specialty, AWS Certified Solutions Architect-Associate, and PMP. AJ is involved with the AWS training and certification department, volunteering with the AWS Certification Examination subject matter expert program.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

50% of Users Online Fall Victim to Cyberattacks: Report

cyberattacks on U.S. and U.K., Barnes & Noble cyberattack, zero trust

Threat actors are using sophisticated hacking methods to target users online. It’s not just about taking advantage of Coronavirus-related anxieties, but attackers are using every single opportunity to steal personal and financial information from users online. According to a NordLocker cybersecurity survey report, 50% of computer users admitted that they have fallen victim to cybercrimes, with virus attacks, phishing scams, and stolen passwords reported as the most common security incidents. The report revealed that 55% of Britishers and 67% of Americans have fallen prey to malicious cyber activities while using their connected devices.

According to the survey, 33% of respondents in the U.K. suffered malware attacks compared to 46% of respondents in the U.S. Nearly, 20% of respondents in the U.K admitted that they fell victim to email scams, while 32% respondents  in the U.S. admitted the same. 14% of the respondents in the U.K., compared to 23% of U.S. respondents, claim to have had their passwords stolen.

“In the U.S., less than half (45%) of computer users don’t share their personal computers. In comparison, the number is slightly higher (49%) in the U.K. However, 52% of users in the U.S. and 50% in the U.K. do use a computer that’s also used by someone else. This is usually a spouse (around 40% in both countries), children (around 20%), parents (6%), and coworkers (3%). Only 3% of respondents said they used a public computer,” the report stated.

“The two countries are quite different when it comes to tax records. The American tax filing system requires individuals to store their tax information, causing 33% of users in the U.S. to store this information on their personal computers. In comparison, it’s only 17% in the U.K. The users in the U.S. also store more medical records (23%), compared to the U.K.’s 15%,” the report added.

U.S. and U.K. Jointly Fight Cyberthreats

Cybersecurity officials in the U.K. National Cyber Security Centre (NCSC), the U.S. Department of Homeland Security (DHS), and the Cybersecurity and Infrastructure Agency (CISA) stated that cybercriminals and advanced persistent threat (APT) groups are targeting individuals and organizations with a variety of ransomware and malware attacks, thereby exploiting the COVID-19 outbreak for their personal gain. The security agencies have released a joint advisory describing the growing number of attackers and other malicious groups in the U.K. and the U.S.

 

An Organization’s Ability to Contain a Cyberattack has declined by 13% Over 5 years: IBM Study

median dwell time, Supercharged AI Cyberattacks are Unavoidable

IBM Security today announced the results of a global report examining businesses’ effectiveness in preparing for and responding to cyberattacks. While the organizations surveyed have slowly improved in their ability to plan for, detect and respond to cyberattacks over the past five years, their ability to contain a cyberattack has declined by 13% during this same period. The global survey conducted by Ponemon Institute and sponsored by IBM Security found that respondents’ security response efforts were hindered due to the use of too many security tools, as well as a lack of specific playbooks for common attack types.

While security response planning is slowly improving, the vast majority of organizations surveyed (74%) are still reporting that their plans are either ad-hoc, applied inconsistently, or that they have no plans at all. This lack of planning can impact the cost of security incidents, as companies that have incident response teams and extensively test their incident response plans spend an average of $1.2 million less on data breaches than those who have both of these cost-saving factors in place. IBM Security and Ponemon Institute: 2019 Cost of a Data Breach Report

The key findings of those surveyed from the fifth annual “Cyber Resilient Organization Report” include:

Slowly Improving:  More surveyed organizations have adopted formal, enterprise-wide security response plans over the past 5 years of the study; growing from 18% of respondents in 2015, to 26% in this year’s report (a 44% improvement).

Playbooks Needed: Even amongst those with a formal security response plan, only one third (representing 17% of total respondents) had also developed specific playbooks for common attack types — and plans for emerging attack methods like ransomware lagged even further behind.

Complexity Hinders Response: The amount of security tools that an organization was using had a negative impact across multiple categories of the threat lifecycle amongst those surveyed. Organizations using 50+ security tools ranked themselves 8% lower in their ability to detect, and 7% lower in their ability to respond to an attack, than those respondents with less tools.

Better Planning, Less Disruption: Companies with formal security response plans applied across the business were less likely to experience significant disruption as the result of a cyberattack. Over the past two years, only 39% of these companies experienced a disruptive security incident, compared to 62% of those with less formal or consistent plans.

“While more organizations are taking incident response planning seriously, preparing for cyberattacks isn’t a one and done activity,” said Wendi Whitmore, Vice President of IBM X-Force Threat Intelligence. “Organizations must also focus on testing, practicing, and reassessing their response plans regularly. Leveraging interoperable technologies and automation can also help overcome complexity challenges and speed the time it takes to contain an incident.”

Updating Playbooks for Emerging Threats

The survey found that even amongst organizations with a formal cybersecurity incident response plan (CSIRP), only 33% had playbooks in place for specific types of attacks. Since different breeds of attack require unique response techniques, having pre-defined playbooks provides organizations with consistent and repeatable action plans for the most common attacks they are likely to face.

Amongst the minority of responding organizations who do have attack-specific playbooks, the most common playbooks are for DDoS attacks (64%) and malware (57%). While these methods have historically been top issues for the enterprise, additional attack methods such as ransomware are on the rise. While ransomware attacks have spiked nearly 70% in recent years, IBM Security, 2020 X-Force Threat Intelligence Index, (2020), p. 15 only 45% of those in the survey using playbooks had designated plans for ransomware attacks.

Additionally, more than half (52%) of those with security response plans said they have never reviewed or have no set time period for reviewing or testing those plans. With business operations changing rapidly due to an increasingly remote workforce, and new attack techniques constantly being introduced, this data suggests that surveyed businesses may be relying on outdated response plans which don’t reflect the current threat and business landscape.

More Tools Led to Worse Response Capabilities

The report also found that complexity is negatively impacting incident response capabilities. Those surveyed estimated their organization was using more than 45 different security tools on average, and that each incident they responded to required coordination across around 19 tools on average. However, the study also found that an over-abundance of tools may hinder organizations ability to handle attacks. In the survey, those using more than 50 tools ranked themselves 8% lower in their ability to detect an attack (5.83/10 vs. 6.66/10), and around 7% lower when it comes to responding to an attack (5.95/10 vs. 6.72/10).

These findings suggest that adopting more tools didn’t necessarily improve security response efforts — in fact, it may have done the opposite. The use of open, interoperable platforms as well as automation technologies can help reduce the complexity of responding across disconnected tools. Amongst high-performing organizations in the report, 63% said the use of interoperable tools helped them improve their response to cyberattacks.

Better Planning Pays Off

This year’s report suggests that surveyed organizations who invested in formal planning were more successful in responding to incidents. Amongst respondents with a CSIRP applied consistently across the business, only 39% experienced an incident that resulted in a significant disruption to the organization within the past two years compared to 62% of those who didn’t have a formal plan in place.

Looking at specific reasons that these organizations cited for their ability to respond to attacks, security workforce skills were found to be a top factor. 61% of those surveyed attributed hiring skilled employees as a top reason for becoming more resilient; amongst those who said their resiliency did not improve, 41% cited the lack of skilled employees as the top reason.


RELATED STORY

Rushing to the Cloud to Support Remote Workers Poses New Security Risks: IBM Study


Technology was another differentiator that helped organizations in the report to become more cyber resilient, especially when it comes to tools that helped them resolve complexity. Looking at organizations with higher levels of cyber resilience, the top two factors cited for improving their level of cyber resilience were visibility into applications and data (57% selecting) and automation tools (55% selecting). Overall, the data suggests that surveyed organizations that were more mature in their response preparedness relied more heavily on technology innovations to become more resilient.

About the Study- Conducted by the Ponemon Institute and sponsored by IBM Security, the 2020 Cyber Resilient Organization Report is the fifth installment covering organizations’ ability to properly prepare for and handle cyberattacks. The survey features insight from more than 3,400 security and IT professionals from around the world, including the United States, India, Germany, United Kingdom, Brazil, Japan, Australia, France, Canada, ASEAN, and the Middle East.

Review the full report here: https://www.ibm.com/account/reg/us-en/signup?formid=urx-45839

California Consumer Privacy Act Puts Additional Pressure on Financial Organizations

California Consumer Privacy Act, Hanna Andersson to Pay $400K to Settle CCPA-related Class-Action Lawsuit

A survey from cybersecurity firm Netwrix revealed that the execution of the California Consumer Privacy Act (CCPA) will put additional pressure on IT resources and expenses, and especially on financial organizations. The survey “2020 Data Risk & Security Report” stated that 32% of financial organizations witnessed an increase in data subject access rights requests (DSARs) since the CCPA came into effect, which was on January 1, 2020.

According to the survey, nearly 73% of financial organizations are already under pressure to satisfy data subject rights requests, and 27% of them reported these requests have increased their expenses. It takes more than two weeks for organizations to fulfill a single data subject request and costs an average of $1,400, if done manually. This brings many financial organizations to put additional workforce and budget to ensure compliance with the CCPA.

“Organizations are investing more than ever in cybersecurity, yet data breaches and other security incidents are continuing to increase in both number and size. First, while security professionals successfully mitigate security issues at some of the six stages of the data lifecycle, they often overlook other stages, leaving their organization’s content vulnerable. In addition, security professionals generally know very little about what data they have, how sensitive it is, where it is stored, and who has access to it,” the report said.

Other findings from the research include:

  • 33% of financial organizations discovered sensitive or regulated customer data outside of designated secure locations.
  • 40% of respondents admitted their IT teams granted direct access to sensitive data based solely on a user’s request in the past 12 months.
  • 75% of financial organizations that classify data can detect data misuse in minutes, while those who don’t usually need days (43%) or months (29%).
  • 61% of organizations that are subject to the GDPR collect more customer data than the law permits.
  • 54% of organizations ignore the security best practice of reviewing access rights to data on a regular basis.
  • 70% of incidents of unauthorized data sharing within this vertical led to data compromise.
  • 44% of CISOs and CIOs don’t have or don’t know whether they have KPIs for IT security and risk.

Steve Dickson, CEO of Netwrix, said, “While organizations are unlikely to be flooded with data subject access requests on July 2, they do need to be prepared to process requests accurately and promptly. One missed deadline or incompletely fulfilled request could result in a thorough audit from the authorities and sizable fines. To ensure compliance while controlling costs and relieving the burden on IT, financial organizations need to automate the DSAR process.”

 

U.K.’s Computer Misuse Act Turns 30; Security Professionals Call For Reform

Computer Misuse Act

A coalition of cybersecurity businesses and professionals in the U.K.  wrote a letter to the Prime Minister Boris Johnson urging him to reform the Computer Misuse Act 1990 (CMA). The coalition includes major cybersecurity firms like NCC Group, F-secure, McAfee, and Trend Micro, international accreditation body CREST, and several leading lawyers in the field came together to urge the Prime Minister for cybersecurity law reforms.

What is the Computer Misuse Act?

The Computer Misuse Act (CMA) 1990 came into effect 30 years ago to prevent computer hacking before the emergence of the internet and the concept of cybersecurity. Industry experts stated that Section 1 of the CMA prevents unauthorized access to computers and unintentionally criminalizes cybersecurity researchers and their investigations.

Letter to Prime Minister

The letter published by CyberUp,  a campaign working towards cybersecurity reforms in the U.K., stated that the outdated CMA prevents security researchers from finding out malicious activities.

“In 1990, when the CMA became law, only 0.5% of the U.K. population used the internet, and the concept of cybersecurity and threat intelligence research did not yet exist. Now, 30 years on, the CMA is the central regime governing cybercrime in the U.K. despite being originally designed to protect telephone exchanges. This means that the CMA inadvertently criminalizes a large proportion of modern cyber defense practices. In particular, Section 1 of the Act prohibits the unauthorized access to any program or data held in any computer and has not kept pace with advances in technology,” the letter stated.

“With the advent of modern threat intelligence research, defensive cyber activities often involve the scanning and interrogation of compromised victims’ and criminals’ systems to lessen the impact of attacks and prevent future incidents. In these cases, criminals are obviously very unlikely to explicitly authorize such access,” the letter added.

Earlier, a joint research by Criminal Law Reform Now Network (CLRNN), scholars from Birmingham and Cambridge universities stated that the U.K.’s CMA needs an update, as it has jeopardized the country’s cybersecurity. The research report, Reforming the Computer Misuse Act revealed how the CMA is preventing security professionals from performing threat intelligence researches. It also stated that the Act restricts journalists and scholars from researching potential cyberthreats.

 

Cyber Warfare: The Battle Tact of the Digital Age

cyber warfare, cyber warfare whitepaper

Border disputes between countries are common these days. But these very countries engage in another kind of warfare, where there are no “boots on the ground” planes in the air or warships in the sea. Instead, it’s a war that involves different kinds of soldiers and spies – all highly adept in computer and cybersecurity skills. This “cyber army” has a mission to “attack” the information assets of the “enemy” – to take down servers belonging to governments and private organizations and destabilize the economy. They look for state secrets stored in digitized form. And they are trained to launch cyberattacks with a different type of weaponry – hacking tools and technologies.  The threat actors and the attack surfaces have evolved, expanded, and now replace traditional combat warfare with a new tack – the age of  Cyber Warfare.

SPONSORED CONTENT

The ethics of cyberweapons used in warfare has always been a debatable question. People have often downplayed them as benign weapons that do not really have the potential to cause major collateral damage. However, since the turn of the century, a wide range of state actors including the United States, Russia, China, North Korea, Iran, and Vietnam have outgrown their offensive and defensive cybersecurity operations and capabilities. Actors often leverage these cyberthreats to indirectly support more traditional means of warfare like espionage, sabotage, propaganda, etc.

Cyber Warfare, Cyber Warfare WhitepaperA new whitepaper produced by CISO MAG titled “Cyber Warfare: Decoding Threats for Nations and Businesses”, sheds more light on this latest form of warfare and the techniques used. The paper includes the latest case studies relative to the subject and answers FAQs about Cyber Warfare.

Download your copy now to know the underbelly of Cyber Warfare! 

This highly engrossing and informative whitepaper is a collaborative work of industry experts from CYFIRMA and cybersecurity editors at CISO MAG. Their combined effort in bringing out a fact-based and data-backed whitepaper unravels some amazing facts; although there is a country vs country angle to Cyber Warfare, yet enterprises and businesses in these countries are caught in the crosshairs of their respective governments and decision-makers.

CISO MAG editors closely analyze and dissect the latest incidents in the Cyber Warfare space and how threat actors leverage other countries geographical, political, and health emergencies like an epidemic or pandemic to their advantage. Lastly, we introspect the future of Cyber Warfare and how having a cyber threat intelligence helps in not only identifying the threats and respective threat actors but also in gaining an outside-in perspective to your organization’s cyber posture.

Cyber Warfare, Cyber Warfare WhitepaperRead about “Cyber Warfare” and CYFIRMA’s pledge towards protecting your businesses, enterprises, and governments from such attacks.

Australia Fortifies Cyber Defense by Investing in AUSHIELD

Cryptocurrency scams in Australia

Few weeks back, the Australian Prime Minister Scott Morrison briefed the nation about sustained cyberattacks carried out by a sophisticated state-sponsored actor. To fortify the cyberspace, the Australian Cyber Security Centre (ACSC) has been ever since taking counter measures and giving advisories to businesses around the country to defend themselves form cyberattacks. In continuation, Australia has now decided to add yet another defensive shield in the cyberspace–the AUSHIELD.

Cybermerc, the cybersecurity company who developed the Aushield Defend cyberthreat intelligence platform, has secured a $1.22 million funding from AustCyber. Cybermerc plans to use this investment in further developing and implement the Aushield platform in protecting Australian industry, researchers, and academia from cyberattacks. It also plans to partly use these funds towards a TAFE cybersecurity education project, which is a University of Adelaide project to provide schools with cyber resources, and a cyber security job platform.

What is Aushield Defend Platform?

Aushield Defend is a threat sharing platform developed by Cybermerc partnered by the Australian National University, Anomali, Vault Cloud and startups SecureStack and CounterSight. AustCyber, a non-profit organization established by the Australian Government, has recognized its importance in these critical times and under its $15 million quota as Projects Fund, it has further sponsored this threat sharing platform to enable Australian businesses to defend each other.

Aushield Detect and Protect

Aushield has two separate modules – Detect and Protect. Detect is a community of threat professionals and researchers who detect rulesets (STIX/TAXII) and reports concerning specific Malicious Cyber Actors and campaigns. When private businesses subscribe to a STIX/TAXII feed from Aushield Detect, the alerts can be directly integrated with their Intrusion Prevention and Detection Systems. Each industry is encouraged to upload their own STIX/TAXII rulesets for the benefit of the AUSHIELD community.

In the Aushield Protect module, there is a repository that collects data of various cyberattacks and malwares carried out on the worldwide network. This data can then be used by the community subscribers to train their artificial intelligence (AI) engines for future attacks and use machine learning (ML) to test the algorithms and implement them against latest attacks on Australian networks.