Home Blog Page 214

Research Finds Changes in Adversarial Cyber Activity

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

Nuspire, a Managed Security Services Provider (MSSP), recently announced its “Quarterly Threat Landscape Report Q1 2020” that detailed the cybercriminal activities, tactics, techniques, and procedures (TTPs) during the first quarter of 2020. The research found that cybercriminals have been targeting known exploits in VPN, IoT, and authentication technologies. It also revealed that the vulnerability exploitation increased by 6.3% over the quarter and phishing attempts doubled to reach 141% over the last three months.

According to the research, there is a 7% increase in malware activity, with several dramatic spikes throughout the quarter. “As the world closed its doors and embraced the new normal, cybercriminals quickly adjusted their strategies to capitalize on the world’s changing behaviors, which has, undoubtedly, created new security challenges,” the research report said.

Other notable findings include:

  • A sharp increase in Executable and Linkable Format (ELF) variants targeting Internet of Things (IoT) devices with an attempt to further spread the Mirai Botnet this quarter. At its peak in Week 11, Nuspire observed an 86% increase in activity.
  • DoublePulsar, the exploit developed by the NSA and leaked by Shadow Brokers, continues to be the most utilized exploit (15,275,010 hits to be exact).
  • Emotet malware activity surged in Q1, peaking from March 1-7, a 1,317% increase in activity from its lowest point.
  • Necurs botnet activity sharply decreased after Microsoft disrupted the botnet in March. By March 8-15, the Necurs botnet went completely silent, as zero traffic was observed.
  • Although the command and control servers the Andromeda botnet operated on were shut down in 2017, it still remains the most frequently observed botnet. However, activity began to decrease at the beginning of Q1, decreasing by 58% by the end of the quarter.
  • Common themes of phishing campaigns seen throughout the quarter include IRS Tax documents, financial invoices, and COVID-19 information.
  • After the disclosure of the GhostCat exploit in Tomcat AJP protocol, Nuspire observed an uptick in exploit attempts demonstrating the importance of swift and responsive patching practices.

Top 10 Commonly Exploited Vulnerabilities Between 2016-2019

microsoft, flaws in SonicWall SRA SMA

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the broader U.S. government released a list of the top ten commonly exploited security vulnerabilities between 2016 and 2019. The agencies issued a security alert (AA20-133A) through the National Cyber Awareness System (NCAS) to help security professionals in public and private organizations prioritize patching the most common vulnerabilities in their security environments. The alert provides details on Common Vulnerabilities and Exposures (CVEs) that are routinely exploited by foreign threat actors.

“The public and private sectors could degrade some foreign cyber threats to U.S. interests through an increased effort to patch their systems and implement programs to keep system patching up to date,” CISA said.

“A concerted campaign to patch these vulnerabilities would introduce friction into foreign adversaries’ operational tradecraft and force them to develop or acquire exploits that are more costly and less widely effective. A concerted patching campaign would also bolster network security by focusing scarce defensive resources on the observed activities of foreign adversaries,” CISA added.

The CVE list includes:

Vulnerability  

Associated Malware

 

CVE-2017-11882 Loki, FormBook, Pony/FAREIT
CVE-2017-0199

 

FINSPY, LATENTBOT, Dridex
CVE-2017-5638

 

JexBoss
CVE-2012-0158 Dridex
CVE-2019-0604 China Chopper
CVE-2017-0143 Multiple using the EternalSynergy and EternalBlue Exploit Kit
CVE-2018-4878 DOGCALL
CVE-2017-8759 FINSPY, FinFisher, WingBird
CVE-2015-1641 Toshliph, Uwarrior
CVE-2018-7600 Kitty

Data Source: us-cert.gov

Most Exploited Bugs

The alert stated that threat actors often exploited bugs in Microsoft’s Object Linking and Embedding (OLE) technology, with Apache Struts web framework being the second-most-reported vulnerable technology. “Of the top 10, the three vulnerabilities used most frequently across state-sponsored cyber actors from China, Iran, North Korea, and Russia are CVE-2017-11882, CVE-2017-0199, and CVE-2012-0158. All three of these vulnerabilities are related to Microsoft’s OLE technology,” CISA said.

Vulnerabilities Exploited in 2020

The U.S. government also reported vulnerabilities that are routinely exploited by state-sponsored actors in 2020, which include:

  • CVE-2019-19781 – An arbitrary code execution vulnerability in Citrix VPN appliances
  • CVE-2019-11510 – An arbitrary file reading vulnerability in Pulse Secure VPN servers, continues to be an attractive target for malicious actors.

Cybersecurity weaknesses like poor employee education on social engineering attacks and a lack of system recovery and contingency plans continue to make organizations susceptible to ransomware attacks in 2020.

“March 2020 brought an abrupt shift to work-from-home that necessitated, for many organizations, rapid deployment of cloud collaboration services, such as Microsoft Office 365 (O365). Malicious cyber actors are targeting organizations whose hasty deployment of Microsoft O365 may have led to oversights in security configurations and vulnerable to attack,” CISA added.

CISA and NCSC Release Joint Advisory

In a recent development, the cybersecurity officials in the U.K. National Cyber Security Centre (NCSC), the U.S. Department of Homeland Security (DHS), and the CISA stated that cybercriminals and advanced persistent threat (APT) groups are targeting individuals and organizations with a variety of ransomware and malware attacks, thereby exploiting the COVID-19 outbreak for their personal gain. The security agencies have released a joint advisory describing the growing number of attackers and other malicious groups in the U.K. and the U.S.

Paying Ransom Doubles the Cost of Ransomware Attack: Research

Ransomware Attacks, Graff ransomware attack

Cybersecurity firm Sophos recently announced the findings of its global survey “The State of Ransomware 2020,” which revealed that paying ransom for data decryption post a ransomware attack is far more expensive. The research said that the total cost of recovery from a ransomware attack almost doubles when organizations pay ransom to cybercriminals.

According to the research, 51% of organizations experienced a significant ransomware attack in the last 12 months, compared to 54% in 2017. Data was encrypted in nearly three quarters (73%) of attacks that successfully breached an organization. It was found that the average cost of addressing the impact of ransomware attack was more than $730,000, which included business downtime, lost orders, and operational costs. However, the average cost increased to $1.4 million when organizations agreed to pay the ransom.

To understand what actually happens once ransomware hits an organization, Sophos surveyed 5,000 IT and security decision makers from 26 countries across six continents, including Europe, the Americas, Asia-Pacific and central Asia, the Middle East, and Africa.

Around 27% of organizations hit by ransomware admitted paying the ransom. More than half (56%) of the IT managers surveyed stated that they were able to recover their data from backups without paying the ransom. A small minority if cases (1%) said paying ransom did not lead to the recovery of data while this figure rose to 5% for public sector organizations. In fact, 13% of the public sector organizations surveyed never managed to restore their encrypted data, compared to 6%, overall.

The public sector was least affected by ransomware, with just 45% of the organizations surveyed in this category stating they were hit by a significant attack in the previous year. At a global level, media, leisure, and entertainment businesses in the private sector were most affected by ransomware, with 60% of respondents reporting attacks.

Chester Wisniewski, Principal Research Scientist, Sophos said, “Organizations may feel intense pressure to pay the ransom to avoid damaging downtime. On the face of it, paying the ransom appears to be an effective way of getting data restored, but this is illusory. Sophos’ findings show that paying the ransom makes little difference to the recovery burden in terms of time and cost. This could be because it is unlikely that a single magical decryption key is all that’s needed to recover. Often, the attackers may share several keys and using them to restore data may be a complex and time-consuming affair.”

 Attackers Pressurize for Ransom

In its another research report “Maze Ransomware: Extorting Victims for 1 Year and Counting,” Sophos researchers explained the tools, techniques, and procedures used by the advanced threat actors, which are designed to increase pressure on the victim to pay the ransom.

“An effective backup system that enables organizations to restore encrypted data without paying the attackers is business critical, but there are other important elements to consider if a company is to be truly resilient to ransomware. Advanced adversaries like the operators behind the Maze ransomware do not just encrypt files, they steal data for possible exposure or extortion purposes. We have recently reported on LockBit using this tactic. Some attackers also attempt to delete or otherwise sabotage backups to make it harder for victims to recover data and increase pressure on them to pay. The way to address these malicious maneuvers is to keep backups offline, and use effective, multi-layered security solutions that detect and block attacks at different stages,” added Wisniewski.

5 Tips for Keeping Remote Workers Secure

Remote work covid-19

With the growing proliferation of COVID-19 also comes an increasing potential for phishing campaigns as threat actors capitalize on the changing dynamics around remote work. Exploits including ransomware that can expose passwords, and data or attack vectors launched through phishing and social engineering can wreak more havoc than ever in this new work-from-home era.

By Phil Richards, CISO at Ivanti

Consider the phishing campaign that’s pushing Netwalker/Mailto ransomware using the attachment “CORONAVIRUS_COVID-19.vbs.” This embedded executable perpetrates a TXT file ransom and instructs targets to pay on a Tor site. Both a public health district and an Australian logistics company have fallen victim.

Another Coronavirus malware kit uses a seemingly legitimate map from Johns Hopkins University in a Java-based malware scheme. The kit is sold for up to $700 with the seller’s certificate, and while users think the Preloader is the map, the malware is stealing passwords. In other instances, a TrickBot Trojan slips detection by using text from Coronavirus articles and an actual ransomware called “CoronaVirus” uses email extortion promising to infect your family with Coronavirus. The climate is indeed scary.

With many workers now confined to operate from home, protecting from these malicious acts can be trickier than ever. To become an expert in the art of RemoteSec, here are five tips you may not have considered for keeping your remote workers secure.

  1. Track and manage all your remote assets and networks. As employees connect from home, on both home networks and devices, you have an expansive wave of new assets penetrating your corporate networks and data. Be sure you have the ability to properly perform remote asset discovery – so you know just what is entering your network. And gain further insight into asset and network performance, not only to efficiently enable workforce productivity, to pinpoint performance anomalies that might indicate malicious behavior – such as large bandwidth consumption at an off hour that might reveal that large amounts of data is being downloaded without consent.
  2. Train and enforce good security hygiene. Just like you might squirt hand sanitizer every time you come home, or are spraying objects entering your home with Lysol, you need to train work-from-home employees to practice good computing hygiene. Advise users how to be smart about the sites they’re visiting, or the links they’re clicking. Do this through adding additional employee training and security communication advisories. Remember, the end user’s home is now becoming the easiest way into your network, so ensure that devices used at home are up-to-date, patched and protected. If you fear there may still be gaps, lock down critical applications with limited admin privileges and dynamic whitelisting so that you can prevent unauthorized code from executing in your environment.
  3. Be mindful of your VPN configuration settings. Your VPN is your first line of defense so be sure that it’s properly configured to allow devices only. Here configuration management is your friend. Pay extra attention to your GPO policies and ensure that you are in control of all the systems that attach to you network. Don’t just open up your VPN to EVERYONE either. Segment users and be sure that external parties, including customers and contractors, have the right security structure in place before gaining access to your network.
  4. Patch to infinity and beyond. Never before has patching been more critical – especially knowing that you need to patch many non-corporate owned devices as well as those you already control. Users will be accessing your network with any device they prefer, and many home computers are out of date, running Windows 7, or worse. Ensure that you have a best-in-class remote patch management solution that can discover out of compliance devices, and patch systems no matter where they are. One missed device could be the proverbial leak in the dam.
  5. Antivirus/anti-malware is a must on all remote systems Ensure that active AV is protecting all your remote devices. This can be done with ease. Global rollouts of AV can be easily automated and performed when you have an advanced solution for endpoint management so users may not even notice that protection is installed or running.

As we all take a deep breath and adjust to this new work-from-home norm, protect your corporate data from the risk of threat actors by doubling down on the protection of remote devices accessing your environment. It will be just one way you can breathe a sigh of relief in an uncertain time.

About the Author

Phil Richards is the Chief Information Security Officer (CISO) for Ivanti. He has held other senior security positions including the Director of Operational Security for Varian Medical Systems, Chief Security Officer for Fundtech Corporation and Business Security Director for Fidelity Investments. In his security leadership roles, he has created and implemented Information Security Policies based on industry standards. He has also implemented global privacy policies, including addressing privacy issues in the European Union.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Texas Court Systems Affected by Ransomware Attack

Texas Court Systems Affected by Ransomware Attack

Websites of the Texas Supreme Court and the state’s appellate courts remained shuttered after being hit by a ransomware attack. The attack affected websites of key Texas judicial organizations including the Office of Court Administration (OCA), which provides IT support to the appellate courts and state judicial agencies within the Texas Judicial Branch. The OCA in a statement detailed that it tracked and stopped the attack from spreading.

The OCA revealed that the attack did not affect emails for the court systems and there was no evidence that any sensitive information was compromised. The agency is now working with law enforcement bodies including the Texas Department of Information Resources to investigate the attack and have vowed not to pay the ransom demanded by the attackers. The authorities also setup a temporary site for operations.

“The attack began on May 8, 2020, during the overnight hours. The attack is unrelated to the courts’ migration to remote hearings amid the coronavirus pandemic. Immediately upon discovery, OCA IT staff disabled the branch network including websites and servers to prevent further harm. The network has remained disabled since this time and will continue to do so until the breach is remediated. OCA is working with law enforcement and the Texas Department of Information Resources (DIR) to investigate the breach. DIR and other information security authorities are providing assistance to OCA with recovery support,” OCA said in a statement.

“OCA was able to catch the ransomware and limit its impact and will not pay any ransom. Work continues to bring all judicial branch resources and entities back online. In the meantime, a temporary web site has been established with critical judicial branch information, including information concerning the COVID-19 pandemic,” OCA added.

Research Finds Critical Industry 4.0 Attack Methods

Skimmer, formjacking

In its latest research, cybersecurity solutions provider Trend Micro revealed how advanced hackers could leverage unusual and new attack vectors to disrupt smart manufacturing units. For the research, Trend Micro collaborated with Politecnico di Milano in its Industry 4.0 lab, which houses real-time equipment to demonstrate malicious threats in Industrial IoT(IIoT) environments for financial gain.

Politecnico di Milano is a scientific-technological university that trains engineers, architects, and industrial designers.

Just like with IT threats, the languages in the critical smart manufacturing equipment can be abused to input malicious code, traverse through the network, or steal confidential information without being detected. According to the research, the systems and machines that could be exploited by attackers include the manufacturing execution system (MES), human-machine interfaces (HMIs), and customizable IIoT devices.

The report offers a detailed set of defense and mitigation measures, which include:

  • Deep packet inspection that supports OT protocols to identify anomalous payloads at the network level
  • Integrity checks run regularly on endpoints to identify any altered software components
  • Code-signing on IIoT devices to include dependencies such as third-party libraries
  • Risk analysis to extend beyond physical safety to automation software
  • Full chain of trust for data and software in smart manufacturing environments
  • Detection tools to recognize vulnerable/malicious logic for complex manufacturing machines
  • Sandboxing and privilege separation for software on industrial machines

Bill Malik, Vice President of infrastructure strategies for Trend Micro, said, “Past manufacturing cyberattacks have used traditional malware that can be stopped by regular network and endpoint protection. However, advanced attackers are likely to develop Operational Technology (OT) specific attacks designed to fly under the radar. As our research shows, there are multiple vectors now exposed to such threats, which could result in major financial and reputational damage for Industry 4.0 businesses. The answer is IIoT-specific security designed to root out sophisticated, targeted threats.”

Iran’s Strait of Hormuz Port Reports a Failed Attempt of Cyberattack

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

As per the reports shared with ILNA news agency, Ports and Maritime Organization’s systems (PMO) recently faced a failed attempt of cyberattack. Although the cybercriminals were able to gain access to private operating systems installed at the Strait of Hormuz Port, no penetration into the PMO’s network was detected.

A recent cyberattack failed to penetrate the Ports and Maritime Organization’s systems (PMO) and was only able to infiltrate and damage a number of private operating systems at the ports (Shahid Rajaei Port near Bandar Abbas).

The Importance of The Strait of Hormuz

The Strait of Hormuz, located in southern Iran, has strategic importance as 85% of the total import of oil by Asian countries like Japan, India, South Korea, and China, from the Gulf countries is transported through this route.

Blocking or disrupting the operations of such a critical infrastructure like the Port operations in Hormuz, will have devastating monetary losses. However, the port has been a hotbed for various forms of physical attacks and cyberattacks in the past.

The organization is well protected, but still needs to continuously strengthen and update the layers of protection to minimize the risk of a (future) cyberattack.

Last week, the PMO office in the Hormozgan province of southern Iran initially denied the reports of a cyberattack. But, Mohammad Rastad, Managing Director of the Ports and Maritime Organization (PMO), in a statement to ILNA said, “A recent cyberattack failed to penetrate the Ports and Maritime Organization’s systems (PMO) and was only able to infiltrate and damage a number of private operating systems at the ports (Shahid Rajaei Port near Bandar Abbas).”

Although Rastad did not confirm the form or exact extent of damages from the cyberattack, he assured that “the organization is well protected, but still needs to continuously strengthen and update the layers of protection to minimize the risk of a (future) cyberattack.” However, in a press release to the Fars News Agency, Rastaad mentioned the hand of a foreign entity aimed at disrupting the critical operations and trade in the region.

When U.S. Launched Cyberattack Against Iran

Earlier in 2019, the military cyber forces of the U.S. launched a cyberattack against Iranian Military computer systems in response to Iran’s shootdown of $240 million worth U.S. surveillance drone. According to the Islamic Revolutionary Guard Corps, the drone was taken down when it entered Iran’s airspace near the Kouhmobarak district in the south of Hormuz. The attack was performed with the approval from President Donald Trump and was specifically targeted on the Iranian military computers that used to control their entire missile operations.

Millions of Computers Open to Thunderbolt Port Vulnerabilities

A security researcher at the Eindhoven University of Technology, Bjorn Ruytenberg, have discovered that Thunderbolt-equipped computers contain vulnerabilities that could leave millions of computers exposed to “Thunderspy” attacks. Ruytenberg revealed that he found seven vulnerabilities in Intel’s Thunderbolt port design and created nine attack vectors.

In a blogpost, Ruytenberg stated that Thunderspy flaws affect Windows and Linux devices that are manufactured before 2019. Attackers, who have the right hardware tools and a few minutes with the machine can bypass defenses, access, and copy the data on targeted computers. “All the attacker needs is five minutes alone with the computer, a screwdriver, and some easily portable hardware,” Ruytenberg said.

Vulnerabilities Found:

  • Inadequate firmware verification schemes
  • Week device authentication scheme
  • Use of unauthenticated device metadata
  • Downgrade attack using backward compatibility
  • Use of unauthenticated controller configurations
  • SPI Flash interface deficiency
  • No Thunderbolt security on Boot camp

How Is the Attack Performed?

To carry out a Thunderspy attack on a vulnerable computer, an attacker is just required to unscrew the backplate, attach a device momentarily, reprogram the firmware (to control the Thunderbolt port), and reattach the backplate. Now the reprogrammed firmware allows the hacker to change Thunderbolt port settings and open the way for any malicious device to access it. Ruytenberg stated that this method works even when the device is locked with a password, its hard disk data is encrypted, and the Thunderbolt port access is disabled.

In a proof of concept video, Ruytenberg demonstrated that he was able to unscrew the bottom panel of a Thunderbolt-equipped ThinkPad to access its Thunderbolt controller.

“Thunderspy is stealth, meaning that you cannot find any traces of the attack. It does not require your involvement, i.e., there is no phishing link or malicious piece of hardware that the attacker tricks you into using. Thunderspy works even if you follow best security practices by locking or suspending your computer when leaving briefly, and if your system administrator has set up the device with Secure Boot, strong BIOS and operating system account passwords, and enabled full disk encryption,” Ruytenberg said.

The researcher reported the issue to Intel authorities with a report on Thunderbolt, discussing issues related to invasive physical attacks on Thunderbolt hosts and devices. Intel clarified that it has created a Thunderbolt security system known as Kernel Direct Memory Access Protection to prevent Thunderspy attacks. “While the underlying vulnerability is not new and was addressed in operating system releases last year, the researchers demonstrated new potential physical attack vectors using a customized peripheral device on systems that did not have these mitigations enabled,” Intel said in a post.

Don’t Abandon Security During a Crisis

CISA, cybersecurity, cybersecurity technologies

Working within dispersed teams is often part and parcel of a CISO’s job. In fact, before COVID-19, 7% of Americans were working remotely either part or full-time, according to the 2019 National Compensation Survey from the Bureau of Labor Statistics. But in the wake of social distancing, almost all organizations are operating 100% remotely.

Other members of the C-Suite might elevate the importance of productivity with remote teams. But as security executives, we should approach the issue from a cybersecurity angle. This is not the time to take our eyes off security in trade-off for expediency.

By Martin Littmann, CTO, CISO, Kelsey-Seybold Clinic and Steve Moore, Chief Security Strategist, Exabeam

For IT professionals in industries not well-versed in remote work, this notion is especially true. The sudden shift to remote work across entire organizations has highlighted faultlines in some professions, with industries like health care, education and service/production feeling the pressure. CISOs within these industries are called to expand on already successful security strategies with their teams — who are often already dispersed to some extent — in a potentially unexpected way.

These CISOs are pressed to weigh operational efficiency with security, forced to manage risks while maintaining “normalcy,” and ease up on employee end users in order to allow for more productivity across the company. They also might be having conversations with the COO/CIO or even the CEO about which processes impact operational efficiency the most. But this is actually the time to be just as strict, if not stricter, with end users and policies than before.

A Virtual Workforce Changes Everything

This remote work scenario means several things for security teams — from shifting the way they handle day-to-day remote access to narrowing in on potential insider threats — CISOs and their teams have to stand their ground by advancing wise business and security decisions before convenience.

Insider Threats

Some organizations have discovered their own stress test of their remote access systems, both virtual and even more traditional like VPN. While they’re licensed appropriately, they’ve figured out that their hardware can’t keep up, so they have the provision outside of the VPN and direct access to certain systems in the cloud. This is where employees may circumvent existing security procedures in order to access something they need.

When employees are operating under the notion that their activity on company networks is flying under the radar, organizations can run into the issue of insider threats, in both proactive and passive scenarios. Employees may be deviously searching and accessing privileged information, or they can be letting down safeguards involuntarily, which can lead them to fall for phishing scams on company devices. Both types of insider threats are dangerous and will experience spikes during the months of mandated social distancing.

To use health care as an example, COVID-19 heightened interest in things such as testing, and vaccine research; mean health care might be especially susceptible to these malicious threats. If there is somebody who might be tempted to profiteer from privileged data within an organization that has let down certain safety measures, things can go sour quickly. They perceive themselves to be in a position where they’re not being monitored as closely because they’re physically not in the office.

On top of that, we know that humans tend to make cloudy judgment calls during crises or emergency situations. End users might be more susceptible to follow a spam link to free N95 masks if they are desperate enough, for instance.

Being a Resource from Afar

The new work setup also impacts how CISOs and their teams relate and work both as an internal entity and with their organization’s end users. Even in industries that operate primarily on-prem, there will be individuals working remotely. In health care, that’s administrative staff, IT and support people. In these professions, people often aren’t technically trained or conceptually prepared to work remotely. So, they need security teams to be accessible. They’ll have questions like, “Is it safe for me to work from my home computer?” or “How can I access this resource now that I’m away from the company network?”

Technical personnel will find that they’re called to interact much more with end users than they have in the past, yet they can’t simply sit down and coach someone through a problem. Technical teams will need to strategize how they’ll handle the increase in tickets and service requests flowing in, even in the face of fewer team members on call, slower internet speeds or unknowns in process and protocol. They’ll also need to deliberate methods of staying connected and communicating amongst each other in order to stay cohesive and efficient while away from their cohort routines and schedules.

Mitigating the Complications of BYOD

With children out of school and many spouses working from home, employees will be pulled in many directions. They’ll be distracted more than ever, which means they’ll likely be tempted to place convenience over security when it comes to keeping personal and professional separate. We can all imagine a scenario where an employee is away from his or her corporate phone but needs to access a network to review, say, a shared file or an urgent email. Nine times out of ten, they’ll use whatever device they can get hold of and circumvent security rules. Over the many weeks these employees are at home, this might happen several times on multiple personal, shared devices. When it’s all said and done, this employee may have authorized three or four unsanctioned devices to access company files. Even after we return to work, those devices might still have access to company information. Allowing convenience to trump safety and letting down walls won’t stay isolated once employees return to work. If a CISO wouldn’t allow unsanctioned devices to connect to the company network before, it shouldn’t allow it to happen now.

Keep Security a Constant

It is possible to maintain a healthy security posture through an emergency. In fact, the current situation could even allow for a unique learning opportunity for a CISO’s team: how to stay on guard during any situation.

Monitor Activity

At Kelsey-Seybold, we have different tools in place to monitor behavior, access rules, generate alerts and evaluate alarms through a log management system or other intelligent systems like SIEM. Looking at and evaluating those alerts and evaluating whether there’s something really going on is a constant process that’s shared across our security organization. Because we have that technology in place, we can keep a greater eye on the information being accessed by employees while they’re at home. In addition, while the majority of people can connect to the network through VDI or Citrix, we limit certain activities that can be done from home. For example, employees can’t print from their local session to a local printer at home. This can keep us from losing valuable data.

Keep One-on-One Time

In the time of crisis, CISOs must maintain efficiency with inbound user queries as well as ensure greater communication among security teams. Use collaboration software to create quick touchpoints, replicate meetings and quick chats that would have been done in the office. Employees, especially those that are not as technologically skilled and unfamiliar with a work-from-home structure, are going to appreciate having access to experts that can answer questions for them in real time.

Stand Firm on Existing Policies

With more people attempting to keep patients, customers, and constituents happy while working from home, they might be tempted to ignore policies that were in place before. But CISOs need to play the long game and focus on consistency first. For example, Kelsey-Seybold has always required a phone interview between IT and a physician that might want to download our EMR application to their computer. Since this is such a high-touch process, we want to verify with the physician that they installed it and talk through any questions. Not only is this quicker for the physician than filling out a form, but it’s more trustworthy for our purposes. Even through recent changes in the day-to-day, we have kept that process in place to protect our staff and our patients.

When world health and political leaders first began urging the practice of social distancing, it took quite a bit of persuasion (nearly pleading) to get people to stay home. Press conference after press conference convinced most Americans that if they stayed home, they could save lives. CISOs are in somewhat of a similar role: they have to talk through the impact an end user can have on the safety of the entire organization and what each individual’s contribution to that is. With end users, it’s focusing on security awareness and education when it comes to phishing threats and personal cybersecurity practices. At a leadership level, the CISO can inspire healthy attitudes toward security processes with executives by creating a “not if, when” narrative.

The world is certainly changing by the day, but security has to stay a constant. Some businesses lead with expediency and accessibility, but we believe cybersecurity should remain an issue at the forefront, or we risk compiling one emergency with another.

About the Authors

Martin Littmann is the Chief Technology and Information Security Officer (CTO & CISO) for Kelsey-Seybold Clinic and is responsible for IT Architecture & Strategy, Infrastructure, Network and Information Security. Littmann holds a Bachelor of Science in Geology and began his career as a geothermal exploration geologist, later transitioning into information technology development and architecture roles.

Stephen Moore has been Vice President and Chief Security Strategist of Exabeam, Inc. since August 2017, and is also the host of The New CISO podcast. Moore has more than 15 years of experience in information security, intrusion analysis, threat intelligence, security architecture and web infrastructure design. Prior to joining Exabeam, Moore spent more than seven years at Anthem, in a variety of cybersecurity practitioner and leadership roles. He was the architect of the new 6,000 square-foot Anthem Cyber Security Operations Center in Indianapolis.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

10 Mn Malware Attacks Detected Every Day In Last 30 Days

Trickbot Malware

Security researchers from Atlas VPN found nearly 404 million malware infections during the last 30 days (in April 2020) globally, which is over 10 million cases per day. According to the data compiled by Atlas VPN, more than 64% of the malicious attacks were targeted on educational institutions.

“In April, the number of global infections worldwide was rising and falling from 10 million to nearly 16 million daily cases. On the first day of the month, there have been around 12 million infections registered worldwide,” the researchers stated.

Since April 5, the total number of malware infections surged, reaching over 13.5 million on April 7. It decreased the next day but increased to 14 million infections on April 9. Post that, the number began to decline, dropping to 11 million cases. On April 16, the number of attacks reached its peak, hitting over 16 million cases worldwide. It then decreased and dropped to 11 million malware infections on April 19. The ensuing week the number fluctuated from 11.7 million to 15.1 million infections, per day. 

Image Courtesy: AtlasVPN

 Central Asia – The Most Targeted Region

Researchers suggested that the Central Asia region suffered the largest number of malware attacks. Around 32.13% of devices in Tajikistan were exposed to malware attacks, followed by Uzbekistan, with 31.44%. In both Venezuela and Brazil, about 12% of devices experienced malware infections, followed by at least 11% of infected devices in Mexico. Belarus and Russia were the most affected countries in the European region.

Education Sector Is the Most Targeted  

Atlas VPN revealed that the education sector suffered over 4.2 million malware infections, which makes 64.77% of the 6.5 million attacked devices. “Educational institutions were exposed to the largest number of malware attacks since criminals expect school staff or students are not well-trained in cybersecurity,” Atlas VPN said. The frequency of the attacks is expected to rise during the exam period.  

Image Courtesy: AtlasVPN

The second most suffered industry is the business and professional services sector. With over 623 thousand encounters, the industry experienced 9% of all cases. Similarly, retail and consumer goods faced 8% of all malware attacks, with nearly 540 thousand cases. Meanwhile, financial and insurance services suffered 5% of malware infections, globally.

The aerospace and automobiles field faced almost 200 thousand malicious attacks, with 3% of the total number of attacks. Next to it is mining, chemicals, oils, and gas, with nearly 3%, it was exposed to 194 thousand attacks. Transportation and hospitality sector with 162,000 malware attacks stood last at 2.5%.