Home Blog Page 198

Philips Release Patches for Vulnerabilities Affecting its Medical Devices

Medical Devices

Electronics and health technology provider Philips has reported a vulnerability to the Cybersecurity and Infrastructure Agency (CISA) in its ultrasound medical devices, which allows threat actors to take control of the medical devices, remotely.

In an official statement, CISA stated that the vulnerability “CWE-288” was identified in Ultrasound ClearVue, Ultrasound CX, Ultrasound EPIQ/Affiniti, Ultrasound Sparq, and Ultrasound Xperius devices. “Successful exploitation of this vulnerability may allow a non-authenticated attacker to view or modify information. An attacker may use an alternate path or channel that does not require authentication of the alternate service login to view or modify information,” CISA said in a statement.

Mitigation

Philips corrected the flaws for Ultrasound EPIQ/Affiniti Version VM6.0 and is planning to release patches for Ultrasound ClearVue Version 3.3, Ultrasound CX Version 5.0.3, and Ultrasound Sparq Version 3.0.3 in Q4 2020.

To mitigate the risk of exploitation of the vulnerability, CISA recommends a few  preventative measures, these include:

  • Implement physical security measures to limit or control access to critical systems
  • Restrict system access to authorized personnel only and follow a least privilege approach
  • Apply defense-in-depth strategies
  • Disable unnecessary accounts and services
  • Where additional information is needed, refer to existing cybersecurity in medical device guidance issued by the FDA

Health Care Devices at Cyber Risk

A research from Atlas VPN revealed that majority of health care organizations in the U.S. are running their medical devices on outdated software and operating systems, leaving them vulnerable to cyberattacks. The research found nearly 83% of health care providers in the U.S. that are running on outdated software. More than 40% of health care providers stated that they were planning to enhance their cybersecurity measures this year. The research also revealed that 27% of medical devices are still running Windows XP or old versions of Linux OS. Nearly 16% of imaging systems are at 51% risk of getting hacked.

Due to the severity of the Coronavirus threat, the health care sector leaves several connected medical devices vulnerable to potential cyberthreats.

 

GDPR Data Breach Notifications Rise by 66% Across Europe

GDPR fines in 2020

A survey by multinational law firm Linklaters revealed that GDPR-related data breach notifications across European countries have increased by 66%, compared to the first year of the GDPR (from May 25, 2018 to May 24, 2019). However, the U.K. witnessed a decline in notifications, with a 17% drop compared to the notifications reported in the first year of the GDPR (11,499 notifications). The numbers doubled in France, with a total of 2,287 notifications (97% increase). Spain reported 1,608 data breach notifications, with a 58% increase. It is also found that Poland reported a high number of notifications when compared to other EU countries with 6,039 data breach notifications in 2019.

The analysis stated that the surge in data breach notifications in both France and Spain is because the companies were aware of their data security obligations. The reasons for  the decline in data breach notifications in the U.K. include:

  • Organizations over-reporting data breaches after the initial implementation of the GDPR
  • The U.K.’s Information Commissioner’s Office (ICO) issued a warning on the over-reporting of data breaches
  • The U.K. is having high breach notifications compared to other countries in the first year of the GDPR

Most of the data breach notifications stemmed from breach of confidential data or access by unauthorized third parties. The survey also highlighted that attackers mostly targeted on clients and employees to steal data with various hacking activities like malware attacks, phishing e-mails, and compromising victims’ unsecured devices.

In addition, the analysis also highlighted the number of fines ordered under the GDPR in the last year. It said that only one fine was reported in the U.K., while 112 fines were ordered by the Spanish DPA, 10 by the Italian DPA, 9 by the Belgian DPA, 6 by the CNIL in France, 13 in Germany, and 5 in Poland. The findings are based on the data analysis across seven European countries, namely Belgium, France, Germany, Italy, Poland, Spain, and the U.K.

Tanguy Van Overstraeten, Partner and Global Head of Linklaters’ Privacy and Data Protection Practice, said, “The harmonization of data protection rules across the EU has been largely successful under the GDPR; however, there are still significant differences among Member States – impacting uniformity of enforcement across the EU. Only harmonizing the approach towards the determination of sanctions will not be sufficient, the interpretation of the rules should also be common to all the Member States. Businesses need certainty and a more unified approach across the EU.”

Overstraeten added “There is also a danger of GDPR fatigue amongst businesses and the Covid-19 crisis is impacting budgets which could limit resources to ensure compliance going forward. The further simplification and harmonization of data protection rules across the EU will be key to ensure companies can sustain this effort.”

 

Data Breach Affects PII of 1 Mn OneClass App Users Across North America

School apps sharing students’ data

OneClass app, a Canada-based online learning platform, suffered a data breach after an unsecured Elasticsearch database exposed personal information of over 1 million students across North America. Security researchers at vpnMentor discovered the leaky database sized over 27GB that contained PII and educational data of the students. The researchers detected the data breach on May 20, 2020 and reported it to OneClass authorities. The database is now secured.

“By not securing its users’ data, OneClass has created a goldmine for criminal hackers, jeopardizing the privacy and security of over a million young people and their families,” the researchers said in a statement.

The exposed information included full names, schools and universities attended, email addresses, phone numbers, school and university course enrollment details and OneClass account details. It is estimated that around 8,972,251 student records may have been exposed in the data breach.

“OneClass users are very young – including minors – and will generally be unaware of most criminal schemes and frauds online. This makes them particularly vulnerable targets. It is also likely many of them use their parent’s credit cards to sign up, exposing their whole family to risk. It is also possible that some of the data belongs to minors, as OneClass includes resources for high school students and accepts users from 13 years old and above. Many records also included additional information on individual students and their courses, including faculty details and access to otherwise protected textbooks and question and answer exercises,” researchers added.

Cyberattacks on E-Learning Platforms

There has been a  surge in the usage of online learning platforms during the ongoing pandemic. Hackers targeted multiple e-learning portals to steal users’ personal information. In a  similar incident, India-based online learning platform Unacademy suffered a data breach that exposed details of 22 million users. Cybersecurity firm Cyble revealed that the unknown hackers kept 21,909,707 user records for sale at $2,000 on darknet forums. The compromised information included usernames, hashed passwords, date of joining, last login date, account status, email addresses, first and last names, and other account profile details. Earlier, a Spanish e-Learning platform 8Belts suffered a data breach that exposed personal data of over 100,000 e-learners across the globe. According to an investigation report, the 8Belts database was stored on a misconfigured Amazon Web Services (AWS) S3 bucket which resulted in the data leakage.

 

Democratizing Cybersecurity Protects Us All

cybersecurity, password, password management,

Cybersecurity is a sophisticated art. It can truly consume the time and resources of IT teams as they work to safeguard valuable data from the growing risk of cyberattacks and data breaches. The technical nature of it, along with the specific expertise it requires, has created a workforce gap that many fear is nearly impossible to bridge.

By Akshay Bhargava, Chief Product Officer at Malwarebytes

In fact, the cybersecurity workforce gap has been reported to be over four million globally, causing an alarming void of security experts who are fit to protect business and consumer data. This gap is particularly painful for small and midsize businesses (SMBs) where recruiting cybersecurity expertise may be particularly costly or challenging. Unfortunately, with the average cost of a breach weighing in at a hefty $3.92 million, cybersecurity is not something any business – no matter the size – can afford to get wrong. This is especially concerning for SMBs where estimates have found that as many as 60% are forced to shut their doors after a cyberattack.

But the damage caused by a successful attack can extend beyond the SMB itself.

Not only will the SMB suffer in the event of a cyberattack, but the larger enterprises it partners with are also put at risk. Take the 2019 Quest Diagnostics data breach as an example. Nearly 12 million patients were exposed after hackers took control of a payments page for one of Quest’s billing collection vendors, AMCA, exposing account data, social security numbers and health information. The same attack also impacted 7.7 million customers of LabCorp. AMCA has since filed bankruptcy.

It’s also been reported that it was an email attack on a vendor of Target Corp. that exposed the credit card and personal data of more than 110 million consumers in 2013. The Target breach has been traced back to network credentials stolen from an email malware attack on a heating, air conditioning and refrigeration firm used by Target.

In each instance, the exposure of a smaller organization put a much larger enterprise at risk. There is hope though, that if we can democratize cybersecurity, SMBs could realize the same protections enterprises require, and we’d all be much safer as a result.

So, what can be done? How can SMBs achieve a cybersecure environment like their enterprise competitors? The key lies in automation and empowering employees.

Automation Unlocks Cybersecurity Democratization

Adopting security automation is an effective way to achieve cyber resilience without adding staff or cost burden. It’s the core of cybersecurity democratization. In fact, companies that fully deploy security automation realize an average $1.55 million in incremental savings when handling a data breach. Not only will automation relieve the pressure from continued staff and skills resource constraints, it’s also dynamically scalable, always on, and enables a more proactive security approach that makes the business exponentially more secure. When applying automation, consider each of these three critical security process areas:

1. Threat detection and prevention. Technologies including advanced analytics, artificial intelligence and machine learning give SMBs the ability to apply adaptive threat detection and prevention capabilities so that they can stay one step ahead of cybercriminals without added staff. By automating threat detection, powered by strong threat intelligence, SMBs can detect new, emerging threats while also increasing the detection and prevention of known threats that may have previously slipped past corporate defenses. Furthermore, they can reduce the noise from incident alerts and false positives from detection systems, improving overall threat detection and prevention success rates.

2. Incident response. If a successful cyberattack does break through, it can move throughout an environment like wildfire. Incident response time is critical to mitigating the severity of the damage, and for those SMBs impacted by the security skills shortage, having the response team needed to react fast is likely a problem. By automating incident response, organizations can greatly improve their cyber resilience. Adopt solutions that will automatically isolate, remediate and recover from a cyberattack:

  •  Isolate. By automating endpoint isolation SMBs are able to rapidly contain an infection while also minimizing disruption to the user. Effective isolation includes the automated containment of network, device and process levels. Advanced solutions will also impede malware from “phoning home” which will restrict further damage to the environment.
  • Remediate. Automating remediation will quickly and effectively restore systems without requiring staff resource time or expertise. It will also allow CISOs to remediate endpoints at scale to significantly reduce the company’s mean-time-to-response.
  • Recover. Finally, incident response should also provide automated restore capabilities to return endpoints to their pre-infected, trusted state. During this recovery process it’s also wise to enable automated detection and removal of artifacts that may have been left behind during the incident. This is essential to preventing malware from re-infecting the network.

3. Security task orchestration. To further relieve security staff while ensuring cyber resiliency, low-level tasks should be automated, including the orchestration between complex, distributed security ecosystems and services. This will ensure a more nimble and responsive environment in the event a cyberattack is successful. Cloud-based management of endpoints can help, specifically if it provides deep visibility with remediation maps. This allows CISOs to better coordinate response efforts and track the impact if a successful incident occurs.

Enterprise-grade security protection should be available for every company, not just those that have the large staff and resources to fund and apply it. Instead, cybersecurity technology needs to be easier to use and more affordable so that companies, regardless of their size or resources, can defend themselves from a growing influx of cyberthreats. By democratizing security through automation, we will all benefit from a safer, more secure world.

About the Author

Akshay BhargavaAkshay Bhargava is the Chief Product Officer at Malwarebytes, a leading provider of advanced endpoint protection and remediation solutions. He is focused on building organizations with culture of innovation and data-driven decisions to enable impactful business outcomes.

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Fxmsp: The Russian Underground Seller Who Made a Fortune

Nobelium

With a target reach of 44 countries, affecting nearly 135 companies and net earnings of more than $1.5 million, meet Fxmsp, the ‘Richie Rich’ of the underground market who made a fortune by selling corporate network access. This famed cybercriminal, who is a ghost in the underground forum, has been in operation for merely three years, however, has quickly learned the traits of the trade to climb up the ladder.

Fxmsp threat geography
Image Credit: Group-iB

The Birth of Fxmsp

According to a Group-IB report, Fxmsp took to cybercrime world in September 2016 when he registered on a Russian underground forum, fuckav[.]ru. The mistakes made in his early posts indicate how naïve he was to this world and how he did not know to monetize the access and maintain persistence within the networks he had compromised. He often sought help from other users of the underground community.

The Rise and Fall

However, once he picked up the answer to “How”, he never looked back. By October 2017 he registered on multiple underground forums such as exploit[.]in and began targeting the corporate networks of the financial and hospitality sectors in Africa. This gave him the fame, but like many others, this fame got to him and thus he forgot the famous rule of the Russian underground market – “You do not go against your own country”. He tried to sell access to an ATM and to the website of two customs offices located in Russian cities. This move made his fellow members ban him from across all forums.

The Climb to the Top

Fxmsp learnt his lesson and took off all the posts related to that sell and started fresh in January 2018. With new sales seeing an exponential increase, Fxmsp collaborated with another notorious underground user known by the name of Lampeduza. Together, these two took their clientele ahead and earned $1,100,800 in exchange for the network access of companies ranging from food and hospitality to government and retail industry.

Fxmsp victims by industry
Image Credit: Group-iB

However, Fxmsp’s activity came to the fore in April 2019. According to media reports, Fxmsp had managed to compromise networks belonging to three high-profile antivirus software vendors. Fearing a hunt and backlash of his involvement, Lampeduza broke ties with Fxmsp and stated no involvement in those hacks. The duo went completely inactive post that and in late December 2019, Lampeduza, in a post on the underground forum, confirmed Fxmsp’s retirement from the cybercriminal world.

Fxmsp is one of the most prolific sellers of access to corporate networks in the history of Russian-speaking cybercriminal underground who publicly advertised the access to 135 companies in 44 countries, including in the U.S., Russia, Singapore, the U.K., and elsewhere, which brought him more than $1.5 million in profits.

 

 Dmitry Volkov, CTO of Group-IB 

Currently, it is uncertain whether his operations are truly frozen or he is still trying to penetrate the corporate network accesses, thus, researchers have advised keeping a close vigil on open RDP ports as the default RDP port 3389 can be edited by changing it to any other and hence compromise the network security of the company.

California University Paid $1.14 Mn Ransom for Decryption Key

California University Data Breach

The University of California, San Francisco (UCSF) recently admitted that it paid $1.14 million to cybercriminals after suffering a ransomware attack. In an official statement, UCSF stated that attackers injected malware that encrypted databases inside the School of Medicine, where the COVID-19 related antibody testing work is going on. While no patients’ data or COVID-19 work was affected,  the officials at UCSF stated that hackers obtained certain data as a proof of their act and to demand ransom.

“We quarantined several IT systems within the School of Medicine as a safety measure, and we successfully isolated the incident from the core UCSF network. Importantly, this incident did not affect our patient care delivery operations, overall campus network, or COVID-19 work,” UCSF said.

The security incident was detected on June 1, 2020, and halted immediately by the UCSF security team. The university said it received the decryption key to restore access to the database and recover the stolen documents. “The data that was encrypted is important to some of the academic work we pursue as a university serving the public good. We therefore made the difficult decision to pay some portion of the ransom, approximately $1.14 million, to the individuals behind the malware attack in exchange for a tool to unlock the encrypted data and the return of the data they obtained,”  UCSF added.

Ransom Demand Soars

According to the Coveware Ransomware Marketplace Research report, the average enterprise ransom payments increased 33% ($111,605) in Q1 of 2020 from Q4 of 2019. The research revealed that ransomware operators succeeded in targeting large organizations and forcing ransom payments. It was found that Sodinokibi (used in 26.7% of attacks), Ryuk (19.6%), and Phobos and Dharma (7.8%) were the top three most used ransomware variants in Q1 of 2020. Coveware stated that Maze, Dopplepaymer, and Sodinokibi operators are using content before encrypting the data, and holding it hostage to threaten to post it unless the target agrees to pay.

 

Infamous Magecart Attack Hits Government Websites of 8 U.S. Cities

e-skimming attacks , Chinese e-commerce scammers

Security researchers from Trend Micro revealed that threat actors compromised government websites of eight U.S. cities across three states through Magecart card skimming attack. The attack occurs when users make a payment on the compromised Click2Gov website.

“These sites all appear to have been built using Click2Gov, a web-based platform meant for use by local governments. It is used to provide services such as community engagement, issues reporting, and online payment for local governments. Residents can use the platform to pay for city services, such as utilities. Breaches in these sites, however, are not new, in 2018 and 2019, the websites of several towns and cities using Click2Gov were compromised,” researchers said in a statement.

Image Source: Trend Micro

“Unlike other skimmers which grab data on various types of payment forms, the skimmer used here is rather simple and only works on a Click2Gov payment form. No obfuscation or anti-debugging techniques were used. The skimmer hooks the submit event of the payment form; when a victim clicks the button to send the payment information, the skimmer will grab the information from the selected columns inside the payment form and immediately send the collected information to remote server via a HTTP POST request,” the researchers added.

The attackers obtained users’ personal information like names, phone numbers, addresses, along with financial data like credit card numbers, expiration dates, and CVV details.

How Magecart Attack Works

Magecart attack, also known as web skimming or e-skimming, is a form of cybercrime where attackers plant malicious JavaScript code on online stores. In Magecart attacks, hackers gain access to a company’s website by compromising and hiding malicious code in it. The malicious code then collects the payment card information from users while making purchases on the infected site. Hackers either sell the stolen card data on the darknet or use it to make fraudulent purchases.

Not the First Time

Multiple security incidents have been reported on Magecart hackers. In its earlier security report, Trend Micro stated that Magecart attackers used a malicious code designed to steal the data  from around 201 online campus stores that were catering to 176 colleges and universities in the U.S. and 21 in Canada.  Hackers used a skimming script to compromise users’ card and personal details entered on the payment page.

Magecart Hackers Arrest

In a recent development, Indonesian Police and Interpol arrested three men who belong to Magecart hacking group for their involvement in Magecart attacks. The police officials stated that it is the first arrest of Magecart gang members. The suspects, identified by initials ANF (27 years), K (35 years), and N (23 years), were accused of injecting JavaScript sniffers into websites to capture information entered by the site visitors. It is said that the suspects allegedly used the stolen payment card data to purchase electronic and luxury goods.

 

Lucifer Malware Exploits Windows Vulnerabilities to Launch DDoS Attacks

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Security experts from Palo Alto Networks discovered a new malware dubbed “Lucifer” targeting Windows systems with cryptojacking and distributed denial-of-service (DDoS) attacks. The researchers stated that Lucifer is a new kind of self-propagating malware that tries to exploit unpatched vulnerabilities.

“Lucifer is a new hybrid of cryptojacking and DDoS malware variant that leverages old vulnerabilities to spread and perform malicious activities on Windows platforms,” the researchers said in a statement.

The new malware campaign was first spotted on June 10, 2020. The attackers later resumed their campaign on June 11 with an upgraded version of the malware, which included the addition of anti-sandbox capability and new checks for device drivers. According to the researchers, the vulnerabilities targeted by Lucifer malware include Rejetto HTTP File Server (CVE-2014-6287), ThinkPHP RCE (CVE-2018-20062), Apache Struts (CVE-2017-9791), Oracle Weblogic (CVE-2017-10271), Laravel framework  CVE-2019-9081), and Microsoft Windows (CVE-2017-0144, CVE-2017-0145, and CVE-2017-8464).

If an attacker exploits the flaws successfully, the malware installs itself and connects to the command-and-control (C2) server and executes arbitrary commands on the vulnerable device. Researchers also stated that Lucifer contains three resource sections – the X86 resource section that contains a UPX-packed x86 version of XMRig 5.5.0; the X64 resource section that contains a UPX-packed x64 version of XMRig 5.5.0; and the SMB section that contains a binary, which includes exploits like EternalBlue, EternalRomance, and DoublePulsar backdoor implant.

“Lucifer is quite powerful in its capabilities. Not only is it capable of dropping XMRig for cryptojacking Monero, it is also capable of C2 operation, and self-propagation through the exploitation of multiple vulnerabilities and credential brute-forcing. Lucifer also checks for the presence of the following device drivers, DLLs, and virtual devices. If any of these objects are detected, the malware enters an infinite loop, stopping its execution from going further. Applying the updates and patches to the affected software are strongly advised,” the researchers concluded.

 

Privileged Access Management is an Essential Component of an Organization’s IT Security Strategy

Privilage management

CISO MAG recently hosted a Virtual Roundtable with Ajay Kumar, Director, Solutions Engineering of BeyondTrust, and Sean Gunasekera, ASEAN Cyber Security Lead, EY. The roundtable, which was moderated by Brian Pereira, Principal Editor, CISO MAG, was on the subject “Strengthening Operational Resilience Through a Universal Approach to Privilege Management.” A slew of cybersecurity experts comprising of CEOs, CISOs. CIOs, Vice Presidents, and executives from countries like the U.K, Singapore, Spain, Lebanon, Australia, India and even regions like Antigua and Barbuda attended the virtual roundtable.

The Panel

Gunasekera is a Partner and currently leads EY’s APAC Financial Services Cyber practice. He has spent the past 16 years in consulting, focusing on cyber security and cyber risk. His areas of expertise are in security strategy and operations.

Ajay Kumar has over 15 years of experience in cybersecurity, and seven specializing in privileged access and identity access management. Prior to becoming the Director of Solutions Engineering – APJ at BeyondTrust, he was the Regional Technical Sales Leader for over seven years at IBM. He is a trusted cybersecurity advisor to enterprise customers, his experience spans across several industries such as banking, insurance, energy, and utilities, in addition to state and federal government.

To reduce the impact of COVID-19, organizations had relocated their workforce to a remote operating model. The discussion began with the subject of COVID-19 impacting cybersecurity operations in the APAC region. Gunasekera took the lead on it and said, “Organizations have had to adjust on multiple fronts, business processes have had to change, and even sensitive business transactions had to be remotely.” He also suggested that technology operations also had to change to accommodate the shift in dynamics, like how a vendor who would have traditionally been onsite to do work on an air gapped system would have to be more relied on home working now. He stressed on how when business make concessions and allow for sensitive transactions to be done offsite cyber controls must be implemented to secure these transactions.

Gunasekera continued, “From an attack surface perspective, as organizations adapted their external perimeter controls to allow for remote access, we also saw an influx of attacks targeting this. Whether it was phishing attacks targeting people’s remote access credentials or country specific campaigns like the malware associated with fake contact tracing apps in Singapore.”

Kumar added, “Another one of the biggest challenges was to add VPN capacity across all breadth, as well as the emergence of shadow IT— applications and infrastructure that are managed and utilized without the knowledge of the enterprise’s IT department. Many a times companies did not know the volume of shadow IT within an organization.”

The virtual roundtable also addressed several other key topics like adoption of new technologies, and compromise of privileged accounts. Talking about the common mistakes made by IT and system admins while managing privileged accounts, Kumar said, “It begins from not changing the password often. Apart from that there is also a trend of account sharing amongst multiple administrators. Another common mistake is multiple accounts for multiple environments like Unix and Windows, which in turn increases the number of accounts and therefore the attack surface. And lastly, as organizations move into DevOps – it is essential that the API keys are appropriately secured.

The three key takeaways from the roundtable were:

  • The adoption of new technologies has resulted in a proliferation of privileged credentials and the expansion of the privilege “universe”. This has compelled CISOs to adopt a new model for privileged access management. Password Management alone is no longer enough to secure the enterprise “privilege universe”.
  • COVID-19 has forced CISOs to reconsider their cybersecurity models to improve operational resilience and security scalability/flexibility, that must now support and protect an increased remote workforce.
  • Recommended by leading analyst and consultancy firms, Privileged Access Management is an essential component of an organization’s IT security strategy and their journey to meet compliance mandates such as MAS TRM, RMiT, PCI DSS and others.

Attendees of the roundtable also took part in a snap poll. Here are the results:

poll-01

poll-02

poll-03You can watch the entire recording of the Virtual Roundtable at: https://attendee.gotowebinar.com/recording/1726333718968954370

Through the Virtual Roundtable and Fireside Chat series, CISO MAG will be partnering with industry experts and solution providers from across the world to host similar webinars to discuss some of the pressing issues and trends in the cybersecurity. Stay tuned.

About BeyondTrust

BeyondTrust is the worldwide leader in Privileged Access Management (PAM), empowering organizations to secure and manage their entire universe of privileges. Our integrated products and platform offer the industry’s most advanced PAM solution, enabling organizations to quickly shrink their attack surface across traditional, cloud and hybrid environments.

The BeyondTrust Universal Privilege Management approach secures and protects privileges across passwords, endpoints, and access, giving organizations the visibility and control they need to reduce risk, achieve compliance, and boost operational performance. We are trusted by 20,000 customers, including 70 percent of the Fortune 500, and a global partner network. Learn more at www.beyondtrust.com.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. Learn more at https://www.eccouncil.org.

Rushing to the Cloud to Support Remote Workers Poses New Security Risks: IBM Study

Cloud Security

The pandemic and subsequent remote working resulted in businesses making sudden and intermittent changes to infrastructure. This is a risky proposition since security policies were often bypassed, and tools and technologies used by remote workers (shadow IT) are not yet audited and checked for compliance. This has resulted in new security threats that impact cloud security and enterprise network security. Research from IBM Security reveals new data examining the top challenges and threats impacting cloud security, indicating that the ease and speed at which new cloud tools can be deployed can also make it harder for security teams to control their usage.

According to IBM survey data and case-study analysis, basic security oversight issues, including governance, vulnerabilities, and misconfigurations, remain the top risk factors organizations should address to help secure increasingly cloud-based operations. The case-study analysis of security incidents over the past year also sheds light on how cybercriminals are targeting cloud environments with customized malware, ransomware, and more.

With businesses rapidly moving to the cloud to accommodate remote workforce demands, understanding the unique security challenges posed by this transition is essential for managing risk. While the cloud enables many critical business and technology capabilities, ad-hoc adoption and management of cloud resources can also create complexity for IT and cybersecurity teams. According to IDC, more than a third of companies purchased 30+ types of cloud services from 16 different vendors in 2019 alone. According to IDC CloudPulse Summary Q119, this distributed landscape can lead to unclear ownership of security in the cloud, policy “blind spots” and potential for shadow IT to introduce vulnerabilities and misconfiguration.

In order to get a better picture of the new security reality as companies quickly adapt to hybrid, multi-cloud environments, IBM Institute for Business Value (IBV) and IBM X-Force Incident Response and Intelligence Services (IRIS) examined the unique challenges impacting security operations in the cloud, as well as top threats targeting cloud environments.

The IBM Institute for Business Value and Oxford Economics conducted a global survey, interviewing 930 senior executives across 17 industries and 20 countries including India, Australia and South Korea across Asia Pacific. The other countries are Brazil, Mexico, USA, Canada, UK, Germany, France, Spain, Nordics, Middle East, South Africa, China and Japan. The respondents interviewed are a mix of COOs, CISOs, CIOs, CTOs, CEOs — all occupying leadership roles across Security, Technology, Operation and Business Strategy.

They were interviewed to understand success factors and market trends related to cloud security strategy, deployment and operations, answering two key questions:

1. How are security operations being modernized for cloud-native scale, speed and interoperability?

2. How are security leaders enabling security awareness and collaboration across the ecosystem?

Top findings include:

Complex Ownership: 66% of respondents in the IBM Institute for Business Value Survey of 930 senior business and IT professionals say they rely on cloud providers for baseline security, yet the perception of security ownership by respondents varied greatly across specific cloud platforms and applications.2

Cloud Applications Opening the Door: The most common path for cybercriminals to compromise cloud environments was via cloud-based applications, representing 45% of incidents in IBM X-Force IRIS cloud-related case studies. IBM X-Force IRIS “Cloud Security Landscape Report” says, in these cases, cybercriminals took advantage of configuration errors as well as vulnerabilities within the applications, which often remained undetected due to employees using new cloud apps on their own, outside of approved channels.

Amplifying Attacks: While data theft was the top impact of the cloud attacks studied, hackers also targeted the cloud for crypto mining and ransomware – using cloud resources to amplify the effect of these attacks.

“The cloud holds enormous potential for business efficiency and innovation, but also can create a ‘wild west’ of broader and more distributed environments for organizations to manage and secure,” said Abhijit Chakravorty, Cloud Security Competency Leader, IBM Security Services. “When done right, the cloud can make security scalable and more adaptable – but first, organizations need to let go of legacy assumptions and pivot to new security approaches designed specifically for this new frontier of technology, leveraging automation wherever possible. This starts with a clear picture of regulatory obligations and compliance mandate, as well as the unique technical and policy-driven security challenges and external threats targeting the cloud.”

Prashant Bhatkal, Security Software Leader, IBM India/South Asia, said, “While companies have been slowly moving to the cloud for years, the global pandemic has served as a forcing function for businesses to drastically accelerate their cloud adoption. The pandemic has created a premium on agility, which the cloud and associated services can provide. Businesses need the ability to adapt quickly and access tools and systems remotely, making cloud the inevitable solution for the new normal.” 

He continues, “While agility is essential, rapid technology shifts lead to new opportunities for cybercriminals. In the case of the cloud, we are moving to a very flexible and dispersed IT landscape that is easy to deploy and scale, but more complex to manage and control. As the rapid move to the cloud has likely exacerbated these challenges, companies must quickly re-evaluate their security policies for the new normal. Customers in India before the pandemic focused around on-prem deployments of critical applications and data. As they started moving to SaaS-based offerings in the last couple of months to allow availability and access to data anywhere, they realized the need to re-imagine their security posture. We are working with clients to help migrate their mission-critical workloads to Cloud by ensuring security is baked in at every level. We are partnering with customers on how they can shift their security approaches to protect increasingly dispersed, hybrid-cloud environments. Cloud today is a key enabler in providing a secure environment to applications and data across various platforms.”

Who owns Security in the Cloud? 

A survey from IBM Institute for Business Value found that responding organizations that relied heavily on cloud providers to own security in the cloud, despite the fact that configuration issues – which are typically users’ responsibility – were most often to blame for data breaches (accounting for more than 85% of all breached records in 2019 for surveyed organizations). Reference: IBM X-Force Threat Intelligence Index, 2020.

Additionally, perceptions of security ownership in the cloud for surveyed organizations varied widely across various platforms and applications. For example, the majority of respondents (73%) believed public cloud providers were the main party responsible for securing software-as-a-service (SaaS), while only 42% believed providers were primarily responsible for securing cloud infrastructure-as-a-service(IaaS). 

While this type of shared responsibility model is necessary for the hybrid, multi-cloud era, it can also lead to variable security policies and a lack of visibility across cloud environments. Organizations that can streamline cloud and security operations can help reduce this risk, through clearly defined policies that apply across their entire IT environment.

Top Threats in the Cloud: Data Theft, Cryptomining, and Ransomware

To get a better picture of how attackers are targeting cloud environments, X-Force IRIS incident response experts conducted an in-depth analysis of cloud-related cases the team responded to over the past year. IBM X-Force IRIS “Cloud Landscape Report,” based on client incident response cases taking place between June 2018 and March 2020.

The analysis found:

Cybercriminals Leading the Charge: Financially motivated cyber criminals were the most observed threat group category targeting cloud environments in IBM X-Force incident response cases, though nation-state actors are also a persistent risk.

Exploiting Cloud Apps: The most common entry point for attackers was via cloud applications, including tactics such as brute-forcing, exploitation of vulnerabilities and misconfigurations. Vulnerabilities often remained undetected due to “shadow IT,” when an employee goes outside approved channels and stands up a vulnerable cloud app. Managing vulnerabilities in the cloud can be challenging since vulnerabilities in cloud products remained outside the scope of traditional CVEs until 2020.

Ransomware in the Cloud: Ransomware was deployed 3x more than any other type of malware in cloud environments in IBM incident response cases, followed by cryptominers and botnet malware.

Data Theft: Outside of malware deployment, data theft was the most common threat activity IBM observed in breached cloud environments over the last year, ranging from personally identifying information (PII) to client-related emails.

Exponential Returns: Threat actors used cloud resources to amplify the effect of attacks like cryptomining and DDoS. Additionally, threat groups used the cloud to host their malicious infrastructure and operations, adding scale and an additional layer of obfuscation to remain undetected.

“Based on the trends in our incident response cases, it’s likely that malware cases targeting cloud will continue to expand and evolve as cloud adoption increases,” said Charles DeBeck, IBM X-Force IRIS. “Our team has observed that malware developers have already begun making malware that disables common cloud security products and designing malware that takes advantage of the scale and agility offered by the cloud.” 

Maturing CloudSec Can Lead to Faster Security Response 

While the cloud revolution is posing new challenges for security teams, organizations who can pivot to a more mature and streamlined governance model for cloud security can help their security agility and response capabilities.

The survey from IBM Institute for Business Value found that responding organizations who ranked high maturity in both Cloud and Security evolution were able to identify and contain data breaches faster than colleagues who were still in early phases of their cloud adoption journey. In terms of data breach response time, the most mature organizations surveyed were able to identify and contain data breaches twice as fast as the least mature organizations (average threat lifecycle of 125 days vs. 250 days).

As the cloud becomes essential for business operations and an increasingly remote workforce, IBM Security recommends that organizations focus on the following elements to help improve cybersecurity for hybrid, multi-cloud environments:

Establish collaborative governance and culture: Adopt a unified strategy that combines cloud and security operations – across application developers, IT Operations and Security. Designate clear policies and responsibilities for existing cloud resources as well as for the acquisition of new cloud resources.

Take a risk-based view: Assess the kinds of workload and data you plan to move to the cloud and define appropriate security policies. Start with a risk-based assessment for visibility across your environment and create a roadmap for phasing cloud adoption.

Apply strong access management: Leverage access management policies and tools for access to cloud resources, including multi-factor authentication, to prevent infiltration using stolen credentials. Restrict privileged accounts and set all user groups to least-required privileges to minimize damage from account compromise (zero trust model).

Have the right tools: Ensure tools for security monitoring, visibility, and response are effective across all cloud and on-premise resources. Consider shifting to open technologies and standards which allow for greater interoperability between tools.

Automate security processes: Implementing effective security automation in your system can help improve your detection and response capabilities, rather than relying on manual reaction to events. 

Use proactive simulations: Rehearse for various attack scenarios; this can help identify where blind spots may exist, and address any potential forensic issues that may arise during attack investigation. 

References

[2] [3] [4] To view the X-Force IRIS Cloud Security Landscape Report, download the full report here.