Home Blog Page 200

80,000 Printers Exposed Online Through IPP Port: Report

HP multi-function printers, Unpatched vulnerabilities

Security researchers have warned that hackers could take advantage of unsecured connected devices to take control of corporate networks. A recent report from Shadowserver Foundation, revealed that internet-connected printers at corporate enterprises expose sensitive information like device names, locations, device model, firmware versions, organization names, IPP (internet printing protocol) port, and WiFi SSIDs.

Researchers at Shadowserver scanned around four billion routable IPv4 addresses to find connected printers that are exposing their IPP port. They found around 80,000 printers exposing themselves online via the IPP port per day.

“We scan by sending an IPP Get-Printer-Attributes request to TCP port 631. We started regular scanning of all 4 billion routable IPv4 addresses on June 5, 2020, and added Open IPP reporting as part of our daily public benefit remediation network reports on June 8, 2020,” the researchers said.

According to researchers, South Korea (36.3k) is the most affected country due to unsecured IPP ports, followed by the U.S. (7.9k), Taiwan (6.7k), and France (2.8k).

Image Source: ShadowServer

How IPP Works?

IPP is a protocol that allows users to manage their internet-connected printers and send print jobs to printers hosted online. The difference between IPP and other printer management protocols is that IPP allows a secure protocol for accessing control lists, encrypted communications, and authentication.

Issues with Unsecured IPP Ports

Unsecured IPP ports are vulnerable to several kinds of attacks. It is found that a quarter of the total number of printers with IPP capability (over 20,000 devices) have exposed information about their brand and model.

“Out of the roughly 80,000 exposed services, a large percentage returned additional printer information attributes, such as printer names, locations, models, firmware versions, organizational units and even printer wifi ssids,”  the researchers added.

“Exposing printer devices with anonymous, publicly queryable vendor names, models and firmware versions obviously makes it much easier for attackers to locate and target populations of devices vulnerable to specific vulnerabilities,” the researchers added.

60% of Enterprises Suffer Printer Security Breaches

A similar research from Quocirca revealed the risks of unsecured printers. It stated that 60% of businesses in the U.K., U.S., France, and Germany suffered a print-related data breach last year, which resulted in a data loss that cost companies an average of more than $400,000. In addition to financial loss, data breach victims also suffer damage to productivity, consumer confidence, and brand value, the report said.

 

iOS 14 and macOS Big Sur Get a Host of New Security and Privacy Features

Apple Notarization

Apple Inc., for the first time in its history, organized a virtual version of its annual Worldwide Developer Conference (WWDC). In the WWDC 2020 held on June 22, 2020, apple announced the  upcoming versions of its operating systems — iOS 14 for iPhones, iPadOS 14 for iPads, watchOS 7 for Apple Watches, and macOS Big Sur for MacBooks — with new features and enhancements.

This year, among other features, Apple particularly took note of the amount of data being stored and shared across its devices and thus gave its new privacy features a much-needed center stage.

Latest Security and Privacy Features of iOS14 and macOS

  • iOS will now enable users to share an approximate location with apps instead of your precise geolocation while granting any app location access.
  • Apple’s new privacy controls let you decide what photos and videos you share. You can choose to select specific items or allow access to all photos and videos.
  • iOS will also display a camera and microphone recording indicator in the status bar. The recording indicator will be placed in the notification bar at the top and will be displayed only when your front or rear camera is in use, or if a microphone is active.
  • The biggest takeaway and a behavioral change comes from the fact that Apple has now made it mandatory for app developers to get user consent before tracking them across the entire online eco system.
  • Additionally, the developers are now required to give a summary of their privacy practices on the App Store so that users can review and decide to download or not.
  • The Safari browser also got a security upgrade as one of its new feature makes the user aware if they are using any compromised password for their online accounts. Its other feature, known as the Intelligent Tracking Prevention, identifies and prevents trackers from profiling or following users across the web.

The beta version is already out in the market for users to test the new features, however, the final roll-out to all end users will take place in the coming months.

Microsoft Acquires CyberX To Boost its IoT Capabilities

FireEye Acquires Respond Software

Microsoft recently acquired Israel-based IoT security vendor CyberX in an undisclosed amount. The tech giant is planning to integrate CyberX’s technologies with its existing Azure IoT security to deliver end-to-end security across managed and unmanaged IoT devices.

CyberX provides IoT/OT-aware behavioral analytics platform for enterprises to reduce IoT/OT risks. Microsoft stated that CyberX’s technology will be an added advantage to other Microsoft Azure IoT services like Azure Sentinel, Azure IoT stack, and Azure Security Center for IoT, helping organizations to detect and respond to evolving threats.

“CyberX is further integrated with Microsoft’s broad portfolio of IoT security offerings in threat protection that span users, endpoints, applications, data and more.  For example, in conjunction with Azure Sentinel, Microsoft’s cloud-native, next-generation security information and event management (SIEM)/security orchestration, automation and response (SOAR) with built-in IoT security workload, SecOps personnel will be able to identify threats that span Operational Technology- and IT-converged networks that were previously challenging to detect,” Microsoft said in a statement.

Microsoft’s Bug Bounty Program

Recently, Microsoft announced its bug bounty program “The Azure Sphere Research Challenge,” which offered security researchers up to $100,000 bounty to break into its Azure Sphere Linux IoT OS platform and discover vulnerabilities. Linux IoT OS is a custom made and compact version of Linux built by the technology giant last year for its Azure Sphere OS. It was designed to run on specialized chips for IoT devices. The Azure Sphere Research Challenge is an extension of Azure Security Lab, which was announced at Black Hat USA in August 2019, with a reward of $40,000.

 

Online Fraudsters Steal Over $21 Mn Amid COVID-19 Pandemic

Ask Yourself These 4 Questions Before Shopping Online

Action Fraud, the U.K.’s National Fraud and Cybercrime Reporting Center,  reported that consumers have lost more than £17 million (US$21 million) to online frauds during the COVID-19 lockdown. It received multiple reports of online shopping frauds since March 2020, affecting over 16,352 online shoppers. It was found that young shoppers aged between 18 to 26 are the most affected (24%).

According to Action Fraud, most of the fraudulent sellers were found on eBay (18%), Gumtree (10%), Facebook (18%), and Depop (6%). Shoppers complained that purchased items including electronics (10%), mobile phones (19%), vehicles (22%), and footwear (4%), were never delivered. Attackers used phishing scams on online shoppers residing London, Leeds, Birmingham, Bristol, Manchester, Sheffield, Liverpool, and Nottingham.

Pauline Smith, the Head of Action Fraud, said, “The global outbreak of coronavirus has seen all our lives turn upside down. With the lockdown being introduced, so many more people are now online shopping, including those who have never done so before. It is therefore unsurprising that there has therefore been an increase in fraud being committed. However, we are still seeing young people in their 20’s falling victim the most. This has been the case for the last 18 months which implies this is not just a trend brought about because of coronavirus. We would make a plea to this group to take extra care when shopping online.”

Action fraud recommended certain security measures to protect against online shopping frauds, these include:

  • If you are purchasing from a company or seller you do not know and trust, carry out some research first and ask a friend or family member for advice before completing the purchase.
  • Use a strong, separate password for your email account. Criminals can use your email to access other online accounts, such as those you use for online shopping.
  • Some of the emails or texts you receive about amazing offers may contain links to fake websites. Not all links are bad, but, if you are unsure, do not use the link and type the website directly into your browser instead.
  • If you decide to go ahead with the purchase, use a credit card if you have one. Other payment providers may not provide the same protection.

“It’s important to shop on sites you know and trust. If you’re using a site you’ve not used before, do your research and check reviews before making a purchase. Always be wary of emails, texts and social media posts that offer products for considerably less than their normal price – this is a common tactic used by criminals. Where possible, use a credit card to make online purchases as this will offer you more protection if anything goes wrong,” Smith added.

 

Over 230K Indonesian COVID-19 Patients’ Records Exposed on Darknet

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Security researchers from threat intelligence firm Cyble  discovered more than 230,000 Indonesian COVID-19 patients’ records on the dark web during their regular deep web and dark web monitoring activity. Cyble claimed that its researchers found a threat actor selling the database of COVID-19 patients on various dark net forums.  The exposed data dump includes names, phone numbers, address, present address, citizenship, test results, diagnosis date, result date, and other sensitive information.

The researchers also analyzed the leaked data and confirmed its authenticity. “Cyble has acquired, validated and, indexed the leak on their data breach monitoring and notification platform, AmiBreached.com – people who’re concerned about their information exposure can register on the platform to ascertain the risks,” the company said in a post.

Risk Mitigation

Cyble also recommended certain mitigation measures to defend against data breaches, these include:

  • Never share personal information, including financial information over the phone, email, or SMS
  • Use strong passwords and enforce multi-factor authentication where possible
  • Regularly monitor your financial transaction, if you notice any suspicious transaction, contact your bank immediately
  • Turn-on automatic software update feature on your computer, mobile and other connected devices where possible and pragmatic
  • Use a reputed anti-virus and internet security software package on your connected devices including PC, Laptop, and Mobile

Data Breaches on Indonesia

Recently, Indonesian e-commerce giant Tokopedia suffered a massive data breach after hackers leaked over 15 million user records. It was also discovered that threat actors kept the details of 91 million users up for sale on the darknet for $5,000. According to Under the Breach, the leaked records contained names, emails, password hashes, and other personal information. Tokopedia’s spokesperson, Nuraini Razak, also confirmed the breach and claimed that the company had ensured the security of its users’ information. While Tokopedia is investigating the incident, Razak clarified that users’ financial details like credit/debit card numbers and e-wallet information were not affected. She also advised the users to change their passwords to prevent further damage.

 

Remote Working: Are You Really Secure?

remote work, Remote workforce security

As cities across the globe begin to ease their COVID-19 restrictions, this year’s transition back to the office could take place in stages — or not at all. Prior to the pandemic, data had already shown a steady increase of remote work employees — growing by 173% over the last 15 years, with nearly 5 million telecommuters in the U.S. alone.

By Andrew Milne, CRO at Field Effect

Research now shows nearly 40% of global companies expect work-from-home policies to be permanent.  Supporting this data, a study last month shows 65% of UK workers believe remote working could become more common after COVID-19. In Canada, 66% of Canadians who shifted to remote work earlier this year, reported a high success rate.

While businesses and organizations consider their next steps, what impact will this have on your cybersecurity strategies?

Working Safely, Securely, and Remotely

Whether you are transitioning back to the office or working remotely long-term, cybersecurity best practices remain as important as ever — and it is equally critical that employees stay vigilant about new COVID-19 scams, and web and email threats.

You can also bet that cybercriminals are tracking these next steps. One look at this year’s cybercrime numbers, provides a good reminder.

Consider these recent risks, in just the first quarter of the year:

  • Over 25,000 malicious COVID-19 websites were created on March 19 — a record for the first quarter.
  • In March, phishing and counterfeit websites increased to 8,342 — from just 3,142 in January.
  • More than 80% of remote work employees surveyed recently claimed awareness of COVID-19 phishing scams, yet 24% clicked on a link from an unknown sender before determining their legitimacy and only 12% reported the email.
  • An estimated 36% of these employees are using one or more personal devices to access company files and 29% also share that device with other members of their household.
  • The reality is, as lockdown restrictions change, you should not change the attention placed on cybersecurity and remote work risks.

Secure your teams working from any location 

As companies consider their transition options, ensuring employees can work from any location, productively and securely — without compromising the security of networks, devices, and users — remains a critical challenge.

That is why our team at Field Effect recently introduced Covalence for Remote Work.

Based on the technologies and capabilities of our flagship Covalence threat detection and monitoring platform, Covalence for Remote Work provides a complete solution in one platform for monitoring and detecting cyberthreats to email and cloud services, devices that support remote work, vulnerabilities in cloud networks, and more.

Here is a quick look:

  • Personalized cloud security monitoring: Gain the insights to detect malicious or suspicious activity to your endpoint devices, email, and cloud services. Covalence uses data, logs, and APIs from your cloud service providers to monitor and identify threats to your services, administrative components, user accounts, and more.
  • Advanced monitoring and analytics: Benefit from machine learning and cloud analytic capabilities that provide continuous analysis of user and service data to identify threats. The result is real-time visibility to detect, monitor, measure, manage, and reduce attackable points.
  • Simple, affordable, powerful: Priced affordably, Covalence integrates easily with all existing systems. Set it up in just a few clicks and it does the heavy lifting to protect you as quickly as possible.

Visibility to the threats and risks facing your remote, distributed workforce will help businesses and organizations build safe IT environments for any stage of the pandemic, as well as into the future.

Get the visibility, protection, and confidence to secure your work from home employees.

Find more information about Covalence for Remote Work here or contact us to get started!

About the Author

Andrew MilneAndrew Milne is the Chief Revenue Officer (CRO) at global cyber security firm Field Effect. His career in Sales & Marketing spans over more than two decades. Milne is a much sought-after speaker on marketing, digital transformation, audience engagement, and how these topics will shape the future of business. He is also an active blogger and the host of “The Brief”, a video series focused on conversations with key players in business of digital transformation today.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Authomize Raises $6Mn to Come out of Stealth Mode

Startup funding

Tel Aviv has been a launchpad for many cybersecurity startups in recent years. Continuing this trend, Authomize, an Identity and Access Management (IAM) solutions provider, has come out of stealth mode by raising raised a seed funding of $6 million. The funding round was led by Blumberg Capital, M12, and Entrée Capital.

This is a special time, with special requirements. When the workforce is spread out, organizations take on a lot of cloud services and run a risk of losing control.

What does Authomize Offer?

Authomize stands for Authority + Automation. It provides a non-intrusive path to turn authorization management chaos to operational efficiency. It provides a singular platform to view and manage authorization and permission sprawls of all scattered applications across all environments. The artificial intelligence (AI) based platform monitors and generates prescriptive security and operational recommendations.

How it Works?

The platform consists of a prescriptive analytics engine called SmartGroups. This engine continuously monitors the data from all apps that the user accesses. It learns the network architecture between resources, identities, entitlements, and their usage. The AI component of the engine then applies these observations and recommends user to take grant only necessary authorizations.

Additionally, the Authomize platform offers compliance templates, automated (re)certification campaigns, alerts on violations and generates audit and compliance reports to help the already overwhelmed IT teams.

Dotan Bar-Noy, Co-Founder of Authomize said,  “This is a special time, with special requirements. When the workforce is spread out, organizations take on a lot of cloud services and run a risk of losing control. The current Identity Governance and Administration (IGA) tools lack the ability to provide the intelligence and automation needed to make informed and efficient decisions. With Authomize, IT and Security teams can make highly informed decisions or choose to automate processes, removing the need to compromise between IT efficiency and impeccable security hygiene.”

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

A recent survey from the security management provider Exabeam revealed that 82% of security operations centers (SOCs) are confident to detect potential cyberthreats. According to the survey “2020 State of the SOC Report,” 40% of organizations still struggle with  SOC staff. Only 22% of frontline staff tracking mean time to detection (MTTD), which helps to determine attackers’ dwell time. It is also found that the dwell time, the time between when a breach first occurs and when it is first detected, has increased exponentially.

The survey also highlighted that there is a disparity between SOC leaders and frontline analysts on the most common cyberthreats on organizations. It is found that SOC leaders believe phishing and supply chain vulnerabilities are critical issues, while analysts see DDoS attacks and ransomware as major threats.

Other research findings include:

  • Small- and medium-sized teams are especially more concerned with downtime or business outage (50%) over threat hunting as an operational metric, yet threat hunting stands out as a must-have hard skill (61%)
  • SOC outsourcing in the U.S. has declined year over year (36% to 28%)
  • K.’s outsourcing had a year over year increase (36% to 47%)
  • Australian SOCs struggle in most categories and need improvement in technology updates, monitoring events and responding to incidents
  • More than 50% of SOCs were found to log at least 40% of events in a SIEM
  • The U.K. utilizes logging the most, compared with other geographic counterparts
  • Most SOCs expect to see security orchestration, automation and response (SOAR) tools take precedence over other technologies in upcoming years
  • The U.S. and the U.K. SOCs have shown year over year improvements in recruiting costs and identifying candidates with the right expertise. Workplace benefits, high wages and a positive culture were this year’s top drivers for retention in nearly 60% of SOCs
  • 23% of SOC personnel across the U.S. and 35% across Canada report being understaffed by more than 10 employees
  • 64% of frontline employees in the SOC reported a lack of career path as a reason for leaving jobs
  • Less effective SOCs reported feeling they lacked the necessary investment in technology, training and staffing to do their jobs well

The survey findings were based on the responses from security decision-makers across the U.S., the U.K., Canada, Germany, and Australia. The survey is aimed to determine how analysts and SOC management view key aspects of their operations, hiring and staffing, retention, technologies, training, and funding.

Steve Moore, the chief security strategist at Exabeam, said, “We see great progress in the SOC with attention paid to employee well-being, measures for better communication and more. However, disparate perceptions of the SOCs’ effectiveness could be dangerously interpreted by the C-suite as assurances that the company is well-protected and secure, when it’s not.”

 

Australia Lost Over $630 Mn to Phishing Scams: Report

Cryptocurrency scams in Australia

A recent survey from the Australian Competition and Consumer Commission (ACCC) revealed that Australians lost over $634 million to scams in 2019, which is a 30% increase compared to $489 million in 2018. The survey “Targeting Scams 2019 Report” stated that Australians reported around 167,797 reports to Scamwatch.gov.au, a primary government website used to report scams, in 2019. It was found that 33% of people or enterprises who had lost money to scams in the last five years did not report to any agency about it.

Losses by Scams

It suggested that Australians lost $132 million to business email compromise (BEC) scams, $126 million to investment scams, identity theft scams reported $4.3 million losses, $83 million lost to dating and romance scams, and losses for cryptocurrency scams exceeded $21.6 million. It was found that phishing was the most common method used by attackers for scamming people, with 25,168 phishing scams reported in 2019.

Image Source: www.accc.gov.au

Only 11.8% of scam reports included a financial loss, according to the data obtained from four popular banks in Australia- the Australia and New Zealand Banking Group (ANZ), Commonwealth Bank of Australia (Commonwealth Bank), National Australia Bank (NAB), and Westpac Banking Corporation (Westpac).

“Scammers continue to adapt their strategies and technology use. In the past scams have relied on persuading a victim to hand over money or personal information. While this is still the norm, many scams, including phone porting scams, now operate with limited contact or none at all, making it difficult for targets to recognize and avoid them. Scammers have moved to unexpected platforms to target victims. In 2019, we saw dating and romance scammers targeting unsuspecting victims through gaming apps such as Words With Friends, and investment scammers targeting Facebook and Instagram users with get rich quick cryptocurrency investment scams,” the report said.

Hackers Target Australians Amid COVID-19

A new threat report from the Australian Cyber Security Centre (ACSC) revealed that Australia has seen a sudden surge in cyberattacks amid the pandemic. It highlighted how cybercriminals are exploiting the situation for their own gain through phishing schemes and malicious activities. The report is intended to raise awareness of increasing COVID-19-related malicious cyberthreats and provide cybersecurity advice in real-time that organizations and individuals can follow to reduce cyber risks.

 

SMEs Likely to Invest More on Cyber Insurance: Report

cyber insurance in SMEs

A recent survey by Cowbell Cyber revealed that 65% of SMEs are likely to spend more on cyber insurance in the next two years, compared to 58% of large enterprises. The survey report “The Economic Impact of Cyber Insurance” also found that 70% of SMEs have cyber insurance coverages with limits lesser than $1 million. The cyber insurance coverage limits varied from one sector to another. According to the report, life sciences, retail, health care, hospitality, and telecom sectors are severely under-covered with gaps in insurance limit and lose coverage.

Image Source: Cowbell Cyber

Other notable findings include:

  • 45% of SMEs and large enterprises converge on the likelihood of their business experiencing a breach in the next one year.
  • 62% of SMEs in the early stages of cybersecurity maturity believe that cyber insurance is well worth the protection. Only 13% felt otherwise.
  • 35% of SMEs buy cyber insurance because it is a customer requirement.
  • 30% of SMEs buy insurance because of regulations requiring restitution to individuals / third-parties.
  • 6 in 10 organizations plan to spend more on cybersecurity insurance over the next two years and more than half believe the cost of insurance is well worth the protection.
  • On average, organizations opt for cybersecurity insurance coverage limits of about 0.14% of revenue.
  • Cyberattacks using password and credential reuse cause the greatest losses today and the greatest risk over the next two years.
  • Multi-Factor Authentication (MFA) is significantly under-deployed in SMEs (18%) compared to very large enterprises (43%).
  • 55% of SMEs point to employee-owned end-user devices as the highest risk in two years.

“Cyber breaches are no longer an if scenario but rather a when scenario. Cyber insurance is becoming increasingly popular for SME organizations that want to protect their assets and accelerate the response and recovery process in the aftermath of a cyber incident. Cyber insurance is now a necessity and not a luxury for organizations,” said, Isabelle Dumont, VP of Market Engagement at Cowbell Cyber.

The survey findings are based on the responses from security professionals at 1,009 organizations across 13 different industries from November 2019 to January 2020. The survey helps understand the cyber insurance buying intentions, limits, and discrepancies between SMEs and large organizations in the U.S.