Home Blog Page 212

Nitro Pro PDF Reader Plagued with Multiple Vulnerabilities

actively exploited vulnerabilities, Vulnerabilities, risk-based vulnerability management

Researchers Aleksandar Nikolic and Cory Duplantis from Cisco Talos discovered multiple vulnerabilities including two code execution flaws and one information disclosure flaw in Nitro Pro PDF reader. Cisco Talos reported the said vulnerabilities in accordance with their disclosure policy to Nitro PDF. Thus, these issues have now been resolved and an update is made available for its affected customers.

Nitro PRO PDF Vulnerabilities Details

Nitro PRO PDF remote code execution vulnerability (CVE-2020-6074)
An exploitable code execution vulnerability is present in the Nitro Pro 13.9.1.155 version. A specific type of PDF document caused a use-after-free that lead to remote code execution. Any target who opens a malicious file could trigger this vulnerability. The severity of the vulnerability can be gauged from the fact that the CVSSv3 Score of this vulnerability was 8.8.

Nitro PRO PDF object code execution vulnerability (CVE-2020-6092)
This code execution vulnerability also exists in the Nitro Pro 13.9.1.155 version and parses Pattern objects.  A malicious PDF file can trigger an integer overflow that can lead to arbitrary code execution and trigger this vulnerability.

Nitro Pro PDF information disclosure vulnerability (CVE-2020-6093)
This vulnerability exists in the XML error handling of Nitro Pro 13.9.1.155 version. A specifically created PDF document can cause uninitialized memory access, resulting in unauthorized information disclosure.

Vulnerabilities Summary
Vulnerability Names
  • Nested pages remote code execution vulnerability
  • Pattern object code execution vulnerability
  • Javascript XML error handling information disclosure vulnerability
CVE Numbers
  • CVE-2020-6074
  • CVE-2020-6092
  • CVE-2020-6093
Affected Software Nitro PRO PDF
Affected Version 13.9.1.155
Vulnerability Timeline
  • 2020-02-19 – Vendor Disclosure
  • 2020-05-18 – Public Release

 

9 In 10 Data Breaches Are Financially-Driven: Report

Financial Sector

Financial gain remains the key motivator for cybercrimes with nine in 10 (86%) data breaches that were investigated and proved to be financially driven, according to the Verizon’s 2020 Data Breach Investigations Report.

The research revealed that credential theft and social attacks like phishing and BEC (business email compromise) attacks caused the majority of data breaches (over 67%), with 37% of credential theft breaches using stolen credentials, 25% involved phishing, and human error accounted for 22%. Nearly, 86% of data breaches for financial gain, which is an increase from 71% in 2019. The research also found 43% increase in web application breaches, and 80% of them were performed using stolen credentials. Ransomware attacks also increased by 27% when compared to 24% in 2019.

“As remote working surges in the face of the global pandemic, end-to-end security from the cloud to employee laptop becomes paramount. In addition to protecting their systems from attack, we urge all businesses to continue employee education as phishing schemes become increasingly sophisticated and malicious,” said Tami Erwin, CEO, Verizon Business.

SMBs are at Risk

The increased use of cloud and web-based applications made small and medium-sized businesses (SMBs) primary targets for cybercriminals. It is found that phishing attacks are the biggest threat for SMBs, accounting for over 30% of breaches.

Industries Under Cyber Risks

The research stated the type of attack vectors is different across various industries. The other significant findings include:

  • External actors leveraging malware, such as password dumpers, app data capturers and downloaders to obtain proprietary data for financial gain, account for 29% of manufacturing breaches
  • 99% of incidents were financially motivated, with payment data and personal credentials continuing to be prized. Web applications, rather than Point of Sale (POS) devices, are now the main cause of Retail breaches
  • 30% of breaches in the financial and insurance sector were caused by web application attacks, primarily driven by external actors using stolen credentials to get access to sensitive data stored in the cloud.
  • Ransomware attacks doubled this year in the educational sector, accounting for 80% of malware attacks vs. last year’s 45%, and social engineering accounted for 27% of incidents.
  • Human error accounted for 31% of health care breaches, with external breaches at 51% (up from 42% in 2019), slightly more common than insiders at 48% (59% last year). This vertical remains the industry with the highest number of internal bad actors, due to greater access to credentials.
  • Ransomware attacks accounted for 61% of malware-based incidents in the public sector. 33% of breaches are accidents caused by insiders. However, organizations have got much better at identifying breaches: only 6% lay undiscovered for a year compared with 47% previously, linked to legislative reporting requirements.

Regional Attack Targets

Northern America: The attack technique commonly used was stolen credentials, with 79% of hacking breaches. Around 33% of breaches were associated with either phishing or pretexting.

Europe, Middle East and Africa (EMEA): Denial of Service (DoS) attacks accounted for over 80% of malware incidents, with 40% of breaches targeted on web applications.

Asia Pacific (APAC): 63% of breaches were financially motivated, and phishing attacks stand at over 28%.

The findings are based on the analysis of 32,002 security incidents and 3,950 confirmed breaches from 81 global contributors from 81 countries.

 

New BIAS Vulnerability Affects All Modern Bluetooth Devices

BrakTooth Flaws

Academic researchers at the École Polytechnique Fédérale de Lausanne (EPFL), a research institute and university in Lausanne Switzerland, discovered a new vulnerability in the Bluetooth wireless protocol, which is used to interconnect modern devices like smartphones, laptops, IoT devices, and other smart devices.

In an official statement, the researchers stated that the vulnerability is dubbed BIAS (Bluetooth Impersonation Attacks) and the attacking device needs to be within wireless range of a vulnerable Bluetooth device that has previously established a BR/EDR connection with a Bluetooth address known to the attacker.

The BIAS Attack

The researchers found that it is possible for an attacking device to spoof the address of a previously bonded remote device to complete the authentication procedure with previously paired devices, without the link key.

Explaining the BIAS attack, research experts from the CERT Coordination Center, said, “An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key. The BIAS attack could be combined with the Key Negotiation of Bluetooth (KNOB) attack to impersonate a Bluetooth device, complete authentication without possessing the link key, negotiate a session key with low entropy, establish a secure connection, and brute force the session key.”

By initiating a KNOB attack, a threat actor could gain complete access as the remote paired device. If the attack is unsuccessful, the attacker cannot establish an encrypted link, but may still appear authenticated to the host, according to researchers.

The Remedy

The Bluetooth Special Interest Group (Bluetooth SIG) stated that it updated the Bluetooth Core Specification and recommended cross-checks for encryption-type to avoid a downgrade of secure connections to legacy encryption, which will be introduced in the upcoming specification. The Bluetooth SIG also urged users to install the latest updates from the device and operating system manufacturers.

“The Bluetooth SIG is strongly recommending that vendors ensure that reduction of the encryption key length below 7 octets is not permitted, that hosts initiate mutual authentication when performing legacy authentication, that hosts support Secure Connections Only mode when this is possible, and that the Bluetooth authentication not be used to independently signal a change in device trust without first requiring the establishment of an encrypted link,” the company said.

Other Bluetooth Vulnerabilities

Earlier, researchers from the Ohio State University revealed that mobile applications that work with Bluetooth devices have a built-in design flaw that makes them vulnerable to hacks. The researchers said the vulnerability lies in the way Bluetooth Low Energy devices, a type of Bluetooth used in modern gadgets, communicate with mobile apps. Wearable devices like smart speakers, health and fitness trackers or smart home assistants communicate with the apps on mobile devices by broadcasting UUID (Universally Unique Identifier), which allows the mobile apps to recognize the Bluetooth device, according to the research.

 

“db8151dd” An Untraceable Data Breach: 22 Mn Emails Compromised

"db8151dd" An Untraceable Data Breach: 22 Mn Emails Compromised

Security researcher Troy Hunt discovered an open Elasticsearch database containing around 22 million of email records. The researcher has said that he has not been able to trace source of the database.

In February, Troy Hunt reported about an open database named as “db8151dd” that contained around 90GB of data containing 22.8 million emails.  It is said that the data was not obtained by scraping public sites and was collected in a different kind of hacking approach.

Hunt stated that it is mostly scrapable data from public sources with some key differences. “Firstly, my phone number is not usually exposed and that was in there in full. Yes, there are many places that (obviously) have it, but this isn’t a scrape from, say, a public LinkedIn page. Next, my record was immediately next to someone else I’ve interacted with in the past as though the data source understood the association. I found that highly unusual as it wasn’t someone, I’d expect to see a strong association with and I couldn’t see any other similar folks,” Hunt said in a post.

After three months of investigation Hunt turned up with three clues, which include:

  • This contact information was synchronized from Exchange. If you want to change the contact information, please open OWA and make your changes there
  • Exported from Microsoft Outlook (Do not delete)
  • Contact Created By Evercontact (Evercontact is a contact management app available on Android.)

“Today is the end of the road for this breach investigation and I’ve just loaded all 22,802,117 email addresses into Have I Been Pwned.  Why load it at all? Because every single time I ask about whether I should add data from an unattributable source, the answer is an overwhelming Yes,” Troy Hunt concluded.

Unprotected databases have been a severe issue for several organizations/individuals with hundreds of millions of confidential data been exposed. There have also been multiple Elasticsearch database breaches reported earlier. In the most recent one, around 5,088,635,374 records (more than five billion) were exposed after a U.K.-based security firm inadvertently exposed its “Data breach Database”, which stored huge information related security incidents from 2012 to 2019, without password protection.

Security researcher Bob Diachenko discovered the leaky database. Describing it as “Data was very well structured”, Diachenko stated that the leaky database contains huge data of previously reported and non-reported security incidents details, which include: Hashtype (the way a password was presented: MD5/hash/plaintext, etc.), Leak date, Password (hashed, encrypted or plaintext, depending on the leak), Email, Email domain, and Source of the leak.

 

Diversify Your Supply Chain to Survive Pandemics, says Deutsche Telekom CSO

Fireside Chat Tschersich

CISO MAG hosted its third Fireside Chat series with Thomas Tschersich, Chief Security Officer (CSO) Deutsche Telekom for a slew of cybersecurity experts comprising of CISOs, CEOs, CIOs and several other senior leaders and executives from U.S., UK, Germany, Bulgaria, and Asia. The topic of the webinar was “Back to a New and Secure Normal.” The Fireside Chat held on May 14, 2020, was moderated by Brian Pereira, Principal Editor of CISO MAG.

The webinar began with an exchange of knowledge between Pereira and Tschersich on the plight of COVID-19 in each of their nations—India and Germany and the preparedness both the countries took in combating the pandemic. Talking about the impact COVID-19 had on Deutsche Telekom, Tschersich recounting the immediate effect of the lockdown that was announced in Germany, narrated, “At that point, our core work was to ensure all the employees who were offsite was brought back to the office. Then came a bigger challenge of setting up computers for thousands of employees with laptops and desktops. The first thing we noticed was that productivity increased. But then our next hurdle was to increase the LAN capacity. There was a lot of positives and negative from the initial experience. Overall, we did well.”

Picking up from there, discussing the lessons that were learnt in the COVID-19 situation, he believed there was both good and bad with the pandemic and the lockdown.

“Unlike the epidemics that we had witnessed before, which were mostly dealt at country or regional level, Coronavirus showed the world what a global pandemic would look like and what damage it can cause.”

According to him the sector which was severely affected was the supply-chain.

“Until the Coronavirus, the world did not know the dependency it had on China, not just the financial sector, but even physical dependency.”

“The biggest learning from the incident was to review our dependency strategy and also look at the supplier of the supply. The best way is to diversify our supply chain to become robust in these kinds of scenario,” he established while stressing that the situation is also an opportunity. “Some call it a crisis, but I call it the biggest digitization process on the planet. If we take the right learning from the crises, we can get stronger out of this.”

Cloud Migration

With COVID-19 several organizations have also started migrating to cloud which was earlier considered apprehensive. “I am sure, for a lot of enterprises, it is safer to have their infrastructure on the cloud than on-premises. Especially small and medium businesses. Secondly, nobody is moving all the workload to a single cloud. There is one for CRM, there is one for finance, there is one for HR. These are more diversified. The main aspect we should be focusing on is creating defenses—we need better security. In fact, zero-trust policies must be a standard in the future,” he added.

During the webinar the audience also took part two snap polls following which Tschersich later took questions from the audience: You can see the results of the snap polls here:

 

Thomas Tschersich began his career with Deutsche Telekom in 1989 as a telecommunications technician. He then went on to complete his degree in Electrical Power Technology at Dortmund University of Applied Sciences. Tschersich then continued to fulfil various roles within Deutsche Telekom before becoming Assistant VP of IT Security and Information Protection for Group Security in 2000, between 2001 and 2007 he was VP of Security Strategy and Policy for Group Security. Tschersich then furthered his career when he was promoted to VP of Technical Security Services for Group Business Security, a role he fulfilled between 2007 and 2009. Afterwards, he took the role as the SVP of Group IT Security Service followed by the role as SVP of Group Security Services. In his last position, Tschersich was the SVP of Internal Security & Cyber Defense at Telekom Security.

Tschersich is also a Member of the Board of Deutschland sicher im Netz and active in numerous advisory functions, including being a member of the Cyber Security Council and the UP Kritis Council.

Following the webinar, five lucky attendees who tweeted about the webinar won a one-year subscription of CISO MAG.

You can watch a recording of the  Fireside chat here.

The next Fireside chat on the topic “CISA and cybersecurity in times of a Pandemic” will be held on May 20, 2020, with Bryan Ware, Assistant Director for Cybersecurity for CISA.

Register for the next webinar at https://attendee.gotowebinar.com/register/9084986810641579534

Through the Fireside Chat series, CISO MAG will be partnering with industry experts and solution providers from across the world to host similar webinars thrice a month to discuss some of the pressing issues and trends in the cybersecurity. Stay tuned.

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world.

Hackers Launch Cryptocurrency Mining Attack on Supercomputers Across Europe

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

Several supercomputers used in research institutes across Europe have been infected with cryptocurrency mining malware by threat actors since January 2020. The malware attacks have been reported in the U.K., Germany, and Switzerland at their respective high-performance computing centers and laboratories. The supercomputers are temporarily shut down to investigate the incident.

The incident came into light after the University of Edinburgh, which runs the ARCHER supercomputer, reported the security exploitation on the ARCHER login nodes. “Due to a security exploitation on the ARCHER login nodes, the decision has been taken to disable access to ARCHER while further investigations take place,” the authorities said in a statement. It is said that attackers infected the login portal of the supercomputers, however the machinery that runs the computations were not impacted in the incident.

Similarly, bwHPC, the organization that coordinates research projects across supercomputers in Germany, reported that five of its high-performance computing clusters were taken down due to security incidents.

“Due to an IT security incident the state-wide High Performance Computer (HPC) systems- bwUniCluster 2.0, ForHLR II, bwForCluster JUSTUS, bwForCluster BinAC, and Hawk are currently not available. Our experts are already working on an assessment of the problem,” bwHPC said.

In Switzerland, the Swiss Center of Scientific Computations (CSCS) confirmed that its supercomputer facilities had been attacked and that it had temporarily closed access.

“CSCS detected malicious activity in relation to these attacks. Due to this situation, the external access to the center has been closed until having restored a safe environment. The users were informed immediately and are kept up to date. Not affected are the weather forecasts of MeteoSwiss, which are also calculated at CSCS,” the authorities said.

More security incidents surfaced reporting similar kinds of attacks. A similar intrusion was reported at a high-performance computing center located in Spain. Security researcher Felix von Leitner claimed that a supercomputer stored in Barcelona was affected by a security issue and had been shut down.

It is unclear if the attacks were linked to a particular hacking crew. The authorities did not provide any further information on the security incidents.

 

Cyberattack on BlueScope Steel Derails Australia Operations

Remote Access Scams

BlueScope, an Australian steel products manufacturer, reported a cyber incident that affected its manufacturing and sales operations in Australia. The type or source of the cyberattack is still unknown, but as per the company’s official statement, operations only in Australia were affected.

The cyber incident in BlueScope Steel was detected in one of the company’s U.S. businesses and the team had acted promptly to respond to this incident.

BlueScope Steel is one of the oldest steel product manufacturers in Australia and has partnerships with the Asian heavyweights of this industry like the Tata conglomerate and Nippon Steel. Their customer base and operations pan across the Pacific Rim from Asia, Australia, New Zealand, right to the west coast of North America. Thus, the cyberattack of any magnitude could have easily derailed its global operations.

The company’s Chief Financial Officer, Tania Archibald, said, “The cyber incident in BlueScope Steel was detected in one of the company’s U.S. businesses and our team had acted promptly to respond to the incident. In the affected areas the company has reverted to manual operations wherever possible, while it fully assesses the impact and remediates as required, to return to normal operations at the earliest.”  Archibald also confirmed that BlueScope’s North Star, Asian, and New Zealand businesses continued as normal with minor disruptions and latencies due to the impact from Australian operations.

Australia’s Toll Group Affected by Mailto Ransomware

Earlier in February 2020, Australia’s logistics giant, Toll Group, was targeted by a cybersecurity incident that compromised around 1,000 systems affecting local and global deliveries across the country. As per the findings of the experts from the Australian Cyber Security Center (ACSC), the logistics company’s computer and network infrastructure were hit by the Mailto ransomware attack.

The report of Toll Group being affected by ransomware first surfaced when the company issued a press release on its website and Twitter handle, officially informing its users about the incident. Post the attack discovery, Toll promptly shut down several systems across multiple sites and business units in Australia to contain the spread of the cyberattack. However, it continued to function its regular pickup, process, and dispatch services but at a slow pace due to manual processing of local and international parcels across Australia.

Improving Cyber Hygiene with Greater Social Cybersecurity Engagement

Improving Cyber Hygiene

You don’t have to look too far around to find someone who may not be practicing proper cyber hygiene in order to protect themselves and others, from the ill effects of cybercrime or cybersecurity issues.  For instance, we may be aware that using the same user ID, email account and password for different cloud services are considered risky behaviors and could result in a potential account hack or data breach. However, we do not change this behavior. How often do you share your best practices for securing your devices, cloud service applications, mobile applications and home networking equipment for connecting to the Internet with those around you in a social situation or manner?  Do you recommend the use of available security settings to those around you in your social circles?  Do you show them how quick it can be to implement the security settings? In this article, we discuss some ways for improving cyber hygiene.

Contributed by: Stan Mierzwa,  Director, Kean University Center for Cybersecurity

Social Cybersecurity is a new and emerging concept and paradigm that basically involves how better cybersecurity behaviors can be inclined positively  using social influence. It’s worth to keep an eye out for the research going on regarding social cybersecurity, because it may have some answers to getting people and companies to better protect themselves.  Even if this approach has a small positive effect on improving cyber hygiene, it is worth it, because something must change if we are going to help individuals better protects themselves.

Background on Social Cybersecurity

There exist any number of tasks and approaches that can be undertaken to protect our computer systems from cybersecurity risks.  This ranges from ensuring you install and keep your anti-virus or endpoint protection system up to date, apply software security updates, encrypt sensitive data, backup our important data, and this list can continue to grow.  Social Cybersecurity brings a dimension with consideration for the individual, not the computer, and how with social psychology, usable and powerful social forces, such as social norms, can have outsized influences on people’s behaviors and perceptions of risk. [1]

The Human-Computer Interaction Institute at Carnegie Mellon University and other researchers are bringing focus to this new scientific area of cybersecurity.  As their website (www.socialcybersecurity.org) mentions, this group is leveraging insights from social psychology and other fields to develop novel interventions and strategies for nudging adoption of expert-recommended tools and practices.  Can we leverage social interactions or the influence of social situations to enhance our cyber hygiene or help thwart cyber threats?  As anyone who uses technology knows, we often opt for convenience rather than security, and there lies a big problem, with short-cuts, we expose ourselves, and those around us to cybersecurity threats.

A worthy research presentation by Sauvik Das, Ph.D, from the Georgia Institute of Technology, hosted at the below link provides a good background on the topic of how social influences affect the adoption of security behaviors. [5]  He presented a test case with the use of Facebook’s security features. The presentation is located at the following link:  https://www.usenix.org/node/208148 . Das made the claim via supported evidence that: Social influences strongly affect cybersecurity behaviors, and it is possible to encourage better cybersecurity behaviors by designing security systems that are more social. [5] The research results from interviews done provided a theme that the observability of security feature usage was a key enabler of socially triggered behavior change and conversation – in encouraging the spread of positive behaviors, discouraging negative behaviors, and getting participants in the study to talk about security. [8] The work presented is innovative and brings encouragement and opportunities in how systems can be designed to encourage better cybersecurity behaviors.

One can also think of Social Cybersecurity in contrast and comparison to the criminological theory called “Social Learning Theory”. In Social Learning theory, delinquents are likely to engage in deviant or criminal behavior when those actions have been positively reinforced. Individuals may model their behavior after those engaged in by others – they may imitate the behavior of others. [2] With this criminological theory in mind, the premise of Social Cybersecurity as a goal of setting a model behavior with regard to cyber hygiene, is worthy and warranted to at least consider and perhaps pursue. Referencing cyber hygiene, transformation or a movement towards behavior modifications needs to occur, or we will just continue down the same path of poor cyber activities where citizens are in the position to deal with the aftermath of cyber incidents or breaches. There needs to be a motivation to encourage better cyber hygiene and work needs to be done. As in the words of Benjamin Franklin, “Motivation is when your dreams put on work clothes.”

Several Potential Areas of Cyber Hygiene to Be Improved

There are several areas that have a potential for improvements in cyber hygiene that may benefit from the possibility of Social Cybersecurity.  Some examples that are frequently advocated in cybersecurity include:

  1. Passwords
  2. Dual factor authentication
  3. Endpoint protection software up to date
  4. Security updates
  5. Not falling prey to scammers

One such area is two-factor or dual-factor authentication. The use of two-factor authentication is widely known in information security as a method that can reduce the issues with poor password management practices. However, in a Ponemon Institute survey produced in 2019, only 33% of respondents said they use two-factor authentication for personal use. [3] Two-factor authentication provides many benefits, but the main one is that it decreases the likelihood that an attacker can impersonate a user to gain access to a software application or data.  In its simplest form, two-factor authentication operates with a traditional user ID and password, in combination with a PIN or passcode provided to something that is owned by the user, such as a smartphone.  In some cases, security is further enhanced with the use of a biometric component.  A Google report in 2018 suggested that less than 10% of Gmail users employ two-factor authentication, which is considered one of their best security features. [4] Why aren’t we all using this method for safer authentication?

Additionally, with regard to password operations, 51% of respondents in the 2019 Ponemon survey, said they reuse an average of five passwords across business and personal accounts.  With respect to sharing passwords, 69% said they do share passwords. We generally don’t share our toothbrushes, so the same hygiene should take place with our account passwords.  This has the potential for another Social Cybersecurity opportunity, perhaps via friendly nudging and advice.

Although it may be difficult to predict with exact numbers, global surveys have demonstrated that over half of the global population are concerned about malware and other potential threats, with about one-quarter of PCs not protected with up-to-date endpoint protection software. [6] This averages out to be about  5.5 times more likely to get infected scenario, if unprotected. The Verizon Data Breach report of 2018 stated that it is quite difficult to estimate the actual numbers or percentages of many breaches, they continue to involve assets or devices without basic antivirus protection installed. [7] Computer or device endpoint anti-virus software isn’t anything new, but why is it that citizens will not install it?  What may be more surprising is that one can install free versions of anti-virus tools, such as Microsoft Security Essentials and Avast Free, which would be better than having no protection.

Conclusion

The purpose of this article is to bring attention to the idea of Social Cybersecurity to those leaders and information security experts who continue to grapple with better user adoption of security best practices.  For those in the information security field, we often state that the human or person is the greatest risk in cybersecurity.  Perhaps cybersecurity leaders can take a cue from the gaming industry. Gaming is a popular activity around adolescents and even adults.  In witnessing my own family members desire to procure or engage in specific games, particularly those that permit connectivity to other gamers, I found that deciding on which game to purchase is typically spread via word of mouth, socially.  If my friends or social group is playing a game, I want in as well.  Could we work towards this sort of uptake with regard to positive cyber hygiene?  Now cyber-hygiene isn’t as fun as a game, but how can we engage with citizens for better uptake on cyber best practices using social cybersecurity.  Let’s spread the joy of protecting ourselves better.

This article appeared in CISO MAG, April 2020 and has been adapted for the online platform.

About the Author 

Improving Cyber Hygiene; Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStanley Mierzwa is the Director, Center for Cybersecurity at Kean University in the United States. He lectures at Kean University on Cybersecurity Risk Management and Foundations in Cybersecurity.  He is a peer reviewer for the Online Journal of Public Health Informatics journal, a member of the FBI Infragard, IEEE and ISC(2).  Stan holds a M.S. in Management Information Systems from New Jersey Institute of Technology and a B.S. Electrical Engineering Technology from Fairleigh Dickinson University.  Stan is also a board member (Chief Technology Officer) for the non-profit Vennue Foundation, and is also a Certified Information Systems Security Professional (CISSP).

Kean University Background

Kean University enrolls almost 16,000 students and offers more than 50 undergraduate majors and 60-plus graduate options, with four campuses in New Jersey and the only public university in America to have a campus in China.  U.S. News & World Report has recently ranked Kean University among the top universities in the norther United States for helping economically disadvantaged students enroll and graduate within six years.  Kean is ranked 41st for social mobility out of 170 universities in the region.

References

  1. Hong, Jason; Das, Sauvik; Hyun-Jin Kim, Tiffany; Dabbish, Laura; Social Cybersecurity: Applying Social Psychology to Cybersecurity, Human-Computer Interaction Institute, Carnegie Mellon University.
  2. Yar, Majid; Steinmetz, Kevin F.; Cybercrime and Society, Sage Publishing, 2019
  3. Ponemon Institute LLC; The 2019 State of Password and Authentication Security Behaviors Report, 2019
  4. Morris, Ian; Google’s Best Security Feature is used By Less Than 10% of Users, Forbes, April, 2018
  5. Das, Sauvik; Social Cybersecurity: Reshaping Security through and Empirical Understanding of Human Social Behavior, Presentation: Georgia Institute of Technology, January 18, 2018
  6. Anderson, Sophie; Antivirus Facts, Trends and Statistics for 2020, SafetyDetectives, December 24, 2019
  7. Widup, Suzanne; Spitler, Marc; Hylender; David; Bassett, Gabriel.; 2018 Verizon Data Breach Investigations Report, 2018
    8. Das, Sauvik; Hyun-Jin Kim, Tiffany; Dabbish, Laura A.; Hong, Jason I.; The Effect of Social Influence on Security Sensitivity, USENIX Association, Tenth Symposium On Usable Privacy Security, 2014

“PentaGuard” Hacking Crew Busted in Romania

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

The Romanian law enforcement authorities arrested four cybercriminals that were planning to launch ransomware attacks on health care organizations in Romania. Three hackers were arrested in Romania and the fourth one was arrested in the Republic of Moldova.

The hackers were charged for committing crimes of illegal operations with computer devices and programs, illegal access to a computer system, alteration of computer data integrity, and computer forgery. According to the Romanian Directorate for Investigating Organized Crime and Terrorism (DIICOT), the threat actors were the members of a hacking group named “PentaGuard,” which was formed at the beginning of the year and created different kinds of malware and malicious tools.

The DIICOT stated that PentaGuard built malware like Remote Access Trojans, ransomware, tools to perform website defacements, and tools to exploit SQL injection vulnerabilities to breach web servers and steal data. The group has been reportedly active since 2000 and has been involved in mass-defacements of several websites of government and private entities.  However, from early 2020, PentaGuard stopped website defacements and have remained active on hacking forums.

“The information obtained so far showed that they intended to launch ransomware attacks in the near future, on some public health institutions in Romania, generally hospitals, using a social engineering toolkit and by sending a malicious executable application from the Locky or BadRabbit computer virus families, hidden in an e-mail and in the form of a file that apparently would come from other government institutions, regarding the threat of COVID19. The malicious executable application will then be automatically downloaded to the computer system, producing data encryption and thus disabling the computer platform,” DIICOT said in a statement.

The statement further added that such type of attack techniques disrupt the functioning of the IT infrastructure of hospitals, which play a decisive role in combating the pandemic.

The main intention of the group was the possession and development of malicious computer applications to use them for specific attacks like SQL Injection and defacement, followed by compromising content and, where appropriate, stealing stored computer data.