Home Blog Page 215

Teen Hackers Accused of Cryptocurrency Theft, Sued For $71 Mn

Nickel, Hackers, Twitch source code

A cryptocurrency investor accused a teen hacker and his crew of juvenile hackers for stealing $24 million in cryptocurrency via a SIM swap attack. According to a lawsuit filed in federal court in New York, Michael Terpin, the founder and CEO of blockchain advisory firm Transform Group, claimed that a teenage hacker Ellis Pinksy (aged 15), along with his group of teen hackers, compromised his phone and stolen his cryptocurrency in 2018. Terpin is suing Pinsky (now aged 18) for $71 million under a federal racketeering law that allows for triple damages, Bloomberg reported.

“Pinsky and his other cohorts are in fact evil computer geniuses with sociopathic traits who heartlessly ruin their innocent victims’ lives and gleefully boast of their multi-million-dollar heists,” Terpin said in his complaint.

Terpin stated that Pinsky’s group identified people with cryptocurrency holdings and illicitly took control of their phones by launching SIM swapping attack to divert authentication messages, gain information, and breach victims’ cryptocurrency accounts.

What Is a SIM Swapping Attack?

A SIM swapping attack is one of the simplest ways for cybercriminals to bypass users’ 2FA protection. In a SIM swap attack, the attacker calls service providers and tricks them into changing a victim’s phone number to an attacker-controlled SIM card. This allows the attacker to reset passwords and gain access to victims’ sensitive data.

In a similar cyber heist, Jack Monroe, a popular food blogger and activist, revealed that she lost about £5,000 (around US$ 6,395) from her bank account after being hit by a SIM-Swapping attack. The British-based writer stated that her phone number was seized and re-activated on another SIM card, despite using two-factor authentication (2FA). Monroe stated the attackers were able to receive her 2FA messages and accessed her bank and payment accounts.

“It seems my card details and PayPal info were lifted from an online transaction. The phone number was ported to a new SIM, meaning criminals access/bypass authentication and authorize payments. I’m an autistic, methodical, ruthless investigator, and I have a LOT of info to go on,” Jack Monroe said.

“Shiny Hunters” Hacker Group Keep 73 Mn User Records on Darknet

BLAZINGSUN: A New Breach on Joker’s Stash Dark Web

Members of the “Shiny Hunters” hacking group are flooding the dark web with leaked databases for sale. The hacking group is alleged of compromising 73.2 million user records from over 11 companies, BleepingComputer reported. The hackers are from the same group who are behind the Tokopedia data breach, in which 91 million user records were compromised and kept on sale on the hacking forums for $5,000. Later, the group breached India-based online learning platform Unacademy, which exposed details of 22 million users and kept the records for sale on the darknet forums for $2,000.

Security researchers from cybersecurity firm Cyble confirmed that Shiny Hunters is selling data from 11 different companies, including the food delivery company HomeChef, the photo print service ChatBooks, and Chronicle.com. Recently, ChatBooks confirmed that Shiny Hunters advertised its user records on a dark web market on May 3, 2020, asking $2,000 for 15 million user records.

Cyble stated that the hackers are allegedly selling stolen databases from various organizations  including:

 

Company

 

User Records

 

Price

Tokopedia

91 million $5,000

Homechef

8 million

$2,500

Bhinneka

1.2 million $1,200
Minted 5 million

$2,500

Styleshare

6 million

$2,700

Ggumim

2 million $1,300

Mindful

2 million

$1,300

StarTribune 1 million

$1,100

ChatBooks

15 million $3,500
The Chronicle of Higher Education 3 million

$1,500

Zoosk 30 million

$500

 

Several incidents have been reported in recent times on hackers selling stolen information on the darknet markets. Security experts from Cyble found hackers selling over 267 million Facebook records for £500 (US$623) on dark websites and hacker forums. Cyble claimed that the records contain information that could allow attackers to perform spear phishing or SMS attacks to steal credentials.

The exposed information includes email addresses, first and last names, last connection, status, age, phone numbers, Facebook IDs, dates of birth, age, and other personal data. Facebook clarified that none of the records include passwords. However, the information is enough for hackers to launch phishing campaigns and other online frauds, experts stated.

“Attackers always look for and exploit trending topics”

Shyam Sundar Ramaswami, Lead Security / Threat Researcher, Cisco, Cisco Umbrella

CISO MAG met Shyam Sundar Ramaswami, Lead Security / Threat Researcher, Cisco, at the NULLCON event held in Goa, in February 2020. Ramaswami is a security researcher who uses superhero characters like Batman and Avengers to spread awareness about cybersecurity.  He leads the India team for Umbrella Research at Cisco. Ramaswami is also responsible for the Asia Pacific research at Cisco.

Ramaswami (Twitter: @hackerbat) is also a TEDx speaker and has presented his research on malware analysis in conferences such as Black Hat USA, Qubit, NULLCON, Cisco live, and in several IEEE forums. He also teaches “Advance attacks and defenses” for the Stanford Cyber Security program. When he isn’t speaking or teaching, he runs a mentoring program called “Being Robin,” where he mentors students across the globe on cybersecurity.

Shyam Sundar Ramaswami, Lead Security / Threat Researcher, Cisco, Cisco Umbrella

Tell us about Umbrella Research. And what is your contribution to the project?

Built into the foundation of the internet, Cisco Umbrella is a cloud security platform that provides a first line of defense against threats, wherever users access the internet — on or off the corporate network.  Umbrella is deployed enterprise-wide in minutes and gives your security team the threat intelligence and context they need to block threats before they become attacks.

Domain names are the carriers of malware today. Everything is domain-based today, be it your entertainment, grocery, or shopping.

As a research team, we build honeypots and trap samples by pasting the IP address where a honeypot is hosted; and also the website, which runs on a weak server in that IP address of our honeypots in several public forums and pages. We put the honeypot username in fake, free movie sites by registering as a username in that site. Attackers try to compromise our servers and host malware or phishing pages. This aids us in learning the entry mode, attacker behaviors, and type of malware that is about to trend the cyber world.

When a new (Avengers) movie launches, there is a lot of Google SEO spamming that takes place saying, “free Avengers movie download HD print” and people fall prey to it. “Free” always comes with a price. Attackers always look for trending topics and lure users to click on malicious ads.

So, we collect these samples and research the malware patterns and we feed this intelligence back to the product.

We also act as incident response. If the customer experiences a zero-day attack, they submit the sample back to us. We examine it and reverse the process, find out what domains it talks to, etc. This is a big opportunity for us. This is how we found out about Paradise ransomware, and there are very few articles on the internet about it. Since we got the samples from our customers, we were able to reverse it and figure out the full potential. This turned out to be an intelligent, evasive, and dynamic ransomware, which set the trend for the new age evasive malware.

We also work with our sales teams to show customers real attack scenes, and how we mitigate it during sales pitches. I interact with CIOs, CSOs, and CEOs and I show them real malware, phishing campaigns, and how Umbrella blocked it. Apart from this I also speak in public forums, and write blogs to spread awareness.

Umbrella Research offers me a tailor-made role as it involves different dimensions.

What trends are you seeing today in terms of the nature of the attacks? What types of attacks is Umbrella Research tracking these days? 

Email is the primary form of attack today. These are targeted and campaign-based attacks. The attacks are tailored to the events happening in that region. For instance, in India, citizens receive notices during the time of filing their returns, about taxes that are due. In the EU, it is about insurance premiums. The entertainment industry is the most targeted industry today with Netflix phishing. Also, for Microsoft Office 365 subscriptions. People receive phishing emails with links urging them to renew their subscriptions to these services. These come with invoices in the attached Word documents. And when you open those attachments it unleashes the embedded Trojans.

We also see a trend of evasive malware. There are many free online sandbox services (like Any run, Hybrid Analysis, and VirusTotal) to test the effectiveness of malware on security products.

A lot of APTs are surfacing and many government organizations and embassy websites are targeted for APT attacks.

The other target is WordPress sites. Attackers look for small scale industries. For instance, small traders in India’s computer bazaars have WordPress sites created years ago, and they have not bothered to update WordPress and the plugins. Attackers scan these sites and use these to serve malware.

Bulletproof hosting is another target. There are bulletproof hosting sites that host sites for low rates ($10-$20) and do not care what one puts on these sites, hence malware gets hosted on those sites.

Remote Monitoring Tools act as RATs – Remote Access Trojans. Hackers use RATs for keylogging. They can switch on the webcam and record what users are doing. And these recorded videos are used for blackmailing users, especially children and teens.

What type of attacks are trending today?  

Phishing and malwares are always trending. In the past few years Malwares have become extremely evasive, super smart in studying the environment it runs in, and changing the payload dynamically according to the environment. It even uninstalls AV services or endpoint detection services.

This could be due to the “availability” of resources on the internet. There is even the marketing trend of “Trail of security products for 90 days.” The attacker can try out security products or endpoint detections systems, tune the malware according to such systems and end up evading systems!

Are the legacy tools effective to counter all these threats? Enterprises have invested heavily in these tools. What are the adoption strategies of organizations?

Security companies are aware of the investments in products. And this is where the concept of feeds service comes in. Legacy products are moving to a model of “Listen, learn and adapt.” Their engine is not static anymore and is able to pair up with a lot of old, existing, and open source products. There are open-source feeds and paid feeds. If you subscribe to these feeds you get a categorized list of bad domains. Companies are also taking a multi-layered approach to security. They look at products that are open to all feeds: open source feeds, threat feeds, paired priced feeds. It should be hybrid. One device can learn from everything. And it’s all going to the cloud.

What are the biggest security challenges raised by organizations?

The internal tools that come with the operating system are being misused by the bad actors. Take PowerShell (a scripting language built on .NET), for instance. A careless click on a link will install malware on the user’s system. The malware then uses PowerShell to do an HTTP/HTTPS call which aids in the exfiltration of data or downloading tailor-made malware.

BYOD is also causing a lot of havoc. People are using their devices to watch free movies, listen to free songs, etc. They use torrents, go to free media websites and this compromises the device and infects it. Using free-Wi-Fi in public hotspots is another problem.

And the operating system is not updated. There are systems used in healthcare institutions that use old versions of Windows that are no longer supported. Hence, there is no security and these systems have vulnerabilities that are exploited. Most of the ransomware attacks in hospitals are due to the use of old, outdated Windows or even free Windows versions. The same has been the case with several ATMs.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

“InfinityBlack” Hacking Group Busted in Poland, 5 Hackers Arrested

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

Five suspected members of a hacking group “InfinityBlack” were arrested on April 29, 2020, in a special operation carried out by the Polish National Police (Policja) in coordination with Europol, Eurojust, and Swiss law enforcement authorities.

InfinityBlack was behind several cybercrime activities including, stealing online credentials and loyalty reward points. The group is known to sell stolen credentials to other cybercriminal gangs on the darknet. According to Europol press release, the Police seized hackers’ electronic equipment, hard drives, and physical cryptocurrency wallets worth around €100,000 (US$108,479). The group maintained two cybercrime platforms to offer their services – one for stolen databases and other for login credentials known to many as combos.

“The hacking group created online platforms to sell user login credentials known as combos. The group was efficiently organized into three defined teams. Developers created tools to test the quality of the stolen databases, while testers analyzed the suitability of authorization data. Project managers then distributed subscriptions against cryptocurrency payments. The hacking group’s main source of revenue came from stealing loyalty scheme login credentials and selling them on to other, less technical criminal gangs. These gangs would then exchange the loyalty points for expensive electronic devices,” Europol said in the release.

InfinityBlack’s Swiss Connection

The authorities stated that hackers created a sophisticated script to gain access to a large number of Swiss customer accounts. It was found that InfinityBlack members accessed more than €600,000 (US$650,580) in loyalty points and sold them to other criminal groups. The investigation by the Cyber Investigation Division (DEC) of the Vaud Cantonal Police in Switzerland identified the connection between buyers in Switzerland and sellers in Poland. The fraudsters and hackers were unmasked while using the stolen data in retail stores in Switzerland.

“A number of investigation measures by specialists from the Cyber Investigation Division (DEC) of the Vaud Cantonal Police made it possible to dismantle the InfinityBlack hackers network set up to exploit this data to the detriment of businesses. Between April 30 and May 2, 2019, five arrests were made in the canton of Vaud, Switzerland,” the authorities said.

Cyber Espionage Campaign “Naikon APT” Targets Government Entities in APAC Region

Cyber Espionage Campaign Naikon APT

A Chinese hacker group is behind an ongoing cyber espionage campaign targeting government entities in the Asia-Pacific (APAC) region, according to a new report from Check Point Research. The group codenamed “Naikon APT” is reportedly undiscovered for five years of spying organizations in the Philippines, Australia, Thailand, Indonesia, Vietnam, Myanmar, and Brunei.

The researchers stated that the Naikon APT group is active since 2015 carrying out a series of cyberattacks on government entities, including ministries of foreign affairs, science and technology ministries, as well as government-owned companies using a new backdoor dubbed “Aria-body” to operate secretly.

Infection Chain

According to the researchers, the attackers used different infection chains to deliver the Aria-body payload. “We observed a malicious email sent from a government embassy in APAC to an Australian state government, named The Indians Way.doc. This RTF file, which was infected (weaponized) with the RoyalRoad exploit builder, drops a loader named intel.wll into the target PC’s Word startup folder. The loader in turn tries to download and execute the next stage payload from spool.jtjewifyn[.]com,” the researchers said.

The researchers also stated that they found this version of the RoyalRoad malware in the Vicious Panda APT group activities reviewed in March 2020.

Check Point found different infection methods during the investigation. These include:

  • An RTF file utilizing the RoyalRoad weaponizer
  • Archive files that contain a legitimate executable and a malicious DLL, to be used in a DLL hijacking technique, taking advantage of legitimate executables such as Outlook and Avast proxy, to load a malicious DLL
  • Directly via an executable file, which serves as a loader

“Given the characteristics of the victims and capabilities presented by the group, it is evident that the group’s purpose is to gather intelligence and spy on the countries whose Governments it has targeted. This includes not only locating and collecting specific documents from infected computers and networks within government departments, but also extracting data from removable drives, taking screenshots and keylogging, and of course harvesting the stolen data for espionage. And if that wasn’t enough, to evade detection when accessing remote servers through sensitive governmental networks, the group compromised and used servers within the infected ministries as command and control servers to collect, relay and route the stolen data,” the report stated.

Microsoft Offers $100,000 Bounty to Hack Its Azure Sphere Linux IoT OS

bounty for DarkSide Ransomware Group, Microsoft Offers $100,000 Bounty

Microsoft recently announced its bug bounty program “The Azure Sphere Research Challenge,” which offers security researchers up to $100,000 bounty to break into its Azure Sphere Linux IoT OS platform and discover vulnerabilities.

Linux IoT OS is a custom made and compact version of Linux built by the technology giant last year for its Azure Sphere OS. It was designed to run on specialized chips for IoT devices. The Azure Sphere Research Challenge is an extension of Azure Security Lab, which was announced at Black Hat USA in August 2019, with a reward of $40,000.

The duration of the Azure Sphere Research Challenge is three months (from June 1  to August 31, 2020), and security researchers are required to execute codes on Azure Pluton and Azure Secure World. Interested ethical hackers/security professionals can register for the project by May 15, 2020.

Microsoft provides eligible security researchers with the necessary resources to support their research, including:

  • Azure Sphere development kit (DevKit)
  • Access to Microsoft products and services for research purposes
  • Azure Sphere product documentation
  • Direct communication channels with the Microsoft team

Commenting on the bug bounty program, Microsoft said, “This new research challenge aims to spark new high impact security research in Azure Sphere, a comprehensive IoT security solution delivering end to end security across hardware, OS and the cloud. While Azure Sphere implements security upfront and by default, Microsoft recognizes security is not a one-and-done event. Risks need to be mitigated consistently over the lifetime of a constantly growing array of devices and services. Engaging the security research community to research for high-impact vulnerabilities before the bad guys do is part of the holistic approach Azure Sphere is taking to minimize the risk.”

Most large organizations usually conduct bug bounties for finding potential vulnerabilities in their systems, which can be fixed before attackers can exploit them. The bug bounties offer fiscal rewards to hackers for finding technical flaws, making it a win-win situation for both. Earlier, Microsoft paid around $4.4 million to researchers as bug bounties at the Black Hat USA 2019 security event in Las Vegas.

How Law Firms Can Demonstrate Strong Cybersecurity Practices

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Law firms have long been known as a “soft target” for bad actors in the technology space. The amount of sensitive data that exists at a law firm is a treasure chest for hackers or bad actors – privileged communications, confidential financial data, nonpublic personal information are just a few of the examples. Public breaches of DLA Piper in 2017 or the other 100 law firms that have experienced breaches over the past few years show that the threat is real. Despite this reality, American Bar Association Legal Technology Resource Center’s ABA TechReport 2019 says lawyers are failing on cybersecurity.

By AJ Yawn, Cloud Security Expert

Like most large corporations and professional service entities, reputations in the legal profession are foundationally important to the firm’s profitability. There are several examples of events that can impact a law firm’s reputation, but few have the immediate and public impact as a data breach or cybersecurity incident. The nature of the information exchanged between an attorney and their client warrants the utmost protection. For this reason, it’s hardly a mystery why a law firm suffers a considerable reputational blow when their clients discover that their sensitive and confidential information has been pilfered and exposed to bad actors.

On the other hand, law firms are also growing cybersecurity and data privacy practices in service to their clients. According to BTI Consulting Group, “Cybersecurity & Data Privacy is the fastest growing practice of any area of law … this critical developing practice is demanding law firms be well-informed … and well-positioned.” A cybersecurity incident or data breach undermines law firms’ efforts to position themselves as leaders in cybersecurity and data privacy. Organizations of all sizes need strategic legal guidance on how to adapt to the evolving cybersecurity and privacy landscape. They need these services from a law firm that practices what they preach and implements the necessary cybersecurity processes required to protect sensitive data.

While this seems bleak and may not be new to anyone that has been following the cybersecurity and legal professions, there is a way forward for law firms and their clients to enable a culture of security in the legal space.

Clients are increasingly asking law firms to prove their security in a variety of ways. Law firms complete long security questionnaires and allow third-party auditors into their offices because providing proof that their client data will be secured is not nice to have, it is required. The problem with this method is the operational drain it places on your internal information technology teams or legal staff that manages vendor relations. Responding to each client’s questions or auditors can be draining and time-consuming.

Law firms have addressed the requirement to prove security to their customers by achieving the internally recognized ISO/IEC 27001:2013 certification. While this certification is a great way to establish an information security management system, it does not provide transparency to your customers regarding the exact practices in place at your organization. The deliverable of an ISO 27001 certification is a ‘certificate’ from a third-party with very little information about what exactly an organization has implemented to achieve that certification.

ISO 27001 is an internationally recognized standard that is valuable and should be pursued, this article is not discrediting that certification.

However, there is a better way for law firms to transparently demonstrate security to your clients. A report that describes what your information system is comprised of, the controls you have in place and whether those controls were operating effectively over a period of time.

SOC (or System and Organization Controls) 2 examinations were designed by the American Institute of Certified Public Accountants (AICPA) to help service organizations, like law firms, provide an independent assessment of controls at their organization relevant to the security, availability, processing integrity, confidentiality and privacy of the system. SOC 2 is a reporting framework that, unlike other frameworks, is less prescriptive and allows organizations to tailor their report to suit their needs and their customer’s needs.

During a SOC 2 examination, organizations are assessed against a set of Trust Services Criteria which are based on the COSO framework, which notes that “an organization adopts a mission and vision, sets strategies, establishes objectives it wants to achieve and formulate plans for achieving them.” This is the flexibility of SOC 2, the framework is not prescriptive in telling organizations how to implement security practices. The cybersecurity practices in each law firm will be different and need a flexible framework that can adapt to their technology or organizational needs.

According to the American Bar Association, 58% of lawyers are using cloud-based technology and interacting with SaaS or IaaS organizations that undergo SOC examinations. SOC 2 examination assists law firms with transparently displaying security in a manner that their vendors and customers understand. The contents of the report include a system description that describes the infrastructure, software, data, people and procedures that make up your law firm information system. The report also includes a list of controls the evaluated law firm has in place and the status of those controls operating effectiveness.

These external benefits of displaying security are ostensibly financially and reputationally clear. However, the most important aspect of a SOC 2 examination is that it requires law firms or other service organizations to establish and maintain a robust cybersecurity program that will protect their organization from data breaches or cybersecurity incidents.

About the Author

AJ Yawn is a cloud security subject matter expert that possesses over nine years of senior information security experience and has extensive experience managing a wide range of compliance assessments (SOC, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers. He has earned several industry-recognized certifications, including the CISSP, AWS Certified Security Specialty, AWS Certified Solutions Architect-Associate, and PMP. AJ is involved with the AWS training and certification department, volunteering with the AWS Certification Examination subject matter expert program.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

“ColdLock” Ransomware Hits Taiwanese Organizations

Hive Ransomware

Researchers discovered a new ransomware codenamed “ColdLock” that targeted several organizations in Taiwan. According to researchers from Trend Micro, the ransomware appears to target databases and email servers for encryption.

The researchers found similarities between ColdLock and previously discovered ransomware variants – Lockergoga, Freezing, and EDA2. “There have been no indications that this attack has hit any other organization outside of those targeted; we do not believe that this family is currently in widespread use,” the researchers stated.

How the Ransomware Is Injected

Hackers infuse the ransomware payload as a .NET executable (as a .DLL file), which is packed/protected using the ConfuserEx packer. It uses PowerShell reflective loading of .NET executables to run the .DLL file.

“It contains two checks to verify if it’s running. Firstly, it checks for the presence of %System Root%\ProgramData\readme.tmp, which is used by the ransom note. This check prevents a system from being reinfected by the same threat. More unusually, it will check the system clock. It will only run at or later than 12:10 PM on any given day; if it is earlier, it will sleep for 15 seconds until it is past the said time,” the researchers explained.

Encryption

Before encrypting the files, ColdLock performs certain preliminary routines. Initially, it terminates various services on the system if they are preventing file access violations. These services include:

  • mariadb
  • msexchangeis
  • mssql
  • mysql
  • oracleservice

The ransomware also terminates the Outlook process and checks the Windows version running on the system. If it is running Windows 10, it carries out several Windows 10-specific routines. Windows Defender and Push notifications are disabled, including the ability to send feedback/malware samples to Microsoft.

“The encryption process uses the AES function in CBC mode. It generates the needed key and initialization vector (IV) using a salt and secret key; the former is embedded in the code while the latter is generated dynamically using the SHA-256 hash of a randomly generated 32-byte long string. This is then encrypted using a hard-coded public RSA key and then embedded in the ransom note. Encrypted files get the .locked extension,” the researchers added.

The ransom note is stored in different locations on the victim’s system, which include:

  • %Desktop%\How To Unlock Files.Txt
  • %System Root%\ProgramData\readme.tmp
  • %User Startup%\How To Unlock Files.Txt
  • {Encrypted Drive}:\How To Unlock Files.Txt

Ransom Note           

Image Courtesy: Trend MicroThe ransomware alters several registry settings and changes the system’s wallpaper for all users, it now contains an instruction to read a ransom note.

Trend Micro recommended some practices for users to protect against ransomware:

  • Periodically back up files using the 3-2-1 rule. The rule entails creating three backups in two different formats and storing one copy offsite
  • Regularly patch and update applications, software, and operating systems to address any exploitable vulnerabilities. For zero-day vulnerabilities, take advantage of virtual patching
  • Activate sandbox analysis. This enables safe monitoring as malicious files can be executed in an isolated environment

76% Security Professionals Face Cybersecurity Skills Shortage: Report

active directory
active directory

A report from cybersecurity research firm Stott and May revealed that most of the cybersecurity leaders are struggling with skills shortage. The research report “Cybersecurity in Focus 2020” highlighted that 76% of respondents believe there is a shortage of cybersecurity skills in their organization, which represents an improvement when compared to 2019 (88%). Nearly 72% of organizations are still struggling to procure cybersecurity talent with no improvement from 2019.

In a time where cybersecurity is becoming critical, most of the businesses are still battling to manage their cybersecurity functions and execute security strategies, according to research.

The other research findings include:

  • Internal skills still represent the biggest inhibitor in delivering cybersecurity strategy (39%), while senior security leaders report increased year on year challenges around budget (30%).
  • The business perception of cybersecurity is moving away from unnecessary expense (15%) towards strategic priority (54%) in the wake of well publicized breaches resulting in fines and reputational damage.
  • Customers are becoming more educated and demanding around the issue of cybersecurity, driving most respondents (69%) to conclude that their business feels that functions can add value to their companies’ overall proposition.
  • As more businesses move towards the cloud 54% of cyber leaders believe we will see an increase in incidents.
  • Security leaders are getting more creative around resourcing their functions with 30% looking internally for transferable skills and some (46%) believing that AI and Machine learning could be used to offset staffing issues.

The findings are based on the responses from 55 cybersecurity leaders. Their views range across several issues including skills shortage, the boardroom perception of cybersecurity, talent attraction and the challenges associated with securing business in the cloud.

Jim Rutt, CISO at the Dana Foundation, and one of the participants in the research, said, “I think it’s more apparent in individual contributor roles like Security Architects, Security Engineers and high level SecOps professionals. There is a shortage of good talent in those areas. But at that leadership level, whether it be Directors or CISO’s, I see no real shortage.”

World Password Day: Review Your Defense and Revamp Your Passwords

World Password Day

Today is World Password Day. A day meant to remind everyone about the importance of protecting themselves through strong passwords. World Password Day is an annual observance that falls on the first Thursday of every May, also meant to commemorate the 2005 book by Security researcher Mark Burnett, “Perfect Password: Selection, Protection, Authentication,” where he encouraged people to not only have safe and smart passwords but to also have a password day.

By Augustin Kurian, Senior Feature Writer, CISO MAG

Burnett’s tips were taken up by Intel Security, which took the initiative to declare the first Thursday in May as World Password Day, in May 2013, following which the Registrar of National Day Calendar formally designated it.

Passwords, in some form or another, have long been associated with security. We see it in literature all the time: to unlock a door, to pass a guard, or to distinguish friend from enemy. These ambiguous words or phrases are the keys to magical spells or the secret codes to identify one spy to another.

– Mark Burnett, “Perfect Password: Selection, Protection, Authentication

Even after several campaigns and a hue and cry from several cybersecurity experts, and every other stakeholder of safe internet, password hygiene continues to be one of the biggest concerns that have marred the cybersecurity sector. A recent study by Clario and OnePoll suggest that three-quarters of millennials in America use the same password for more than ten different devices, apps, and other social media accounts. The study also revealed certain alarming statistics about the password practices followed by Americans. Most of the respondents admitted they were using the same password in over 50 different places.

Practicing good password hygiene is one of the most essential security measures to deter online intruders. If you compare old threat vectors with the new ones, one vector which has stayed redundant is poor password management. “There’s the lower level or ‘Bottom Feeders’ taking advantage of unpatched networks or devices, poor password management, and targets conducting poor cyber hygiene,” Marcus Fowler, ex-CIA executive and Director of Strategic Threat at Darktrace, told CISO MAG.

Several times people choose easy-to-remember passwords rather than focusing on security. With the rising concerns over data breaches and troves of usernames and passwords being dumped on the dark web every day, password hygiene is more important than ever. “The sheer volume of stolen users’ passwords available for sale on the Dark Web highlights that the issue is less about creating strong passwords or phrases, and more about users creating unique codes for each online account to limit the damage from database breaches,” Adam Palmer, Chief Cybersecurity Strategist at Tenable said.

“Every time a researcher with time on their hands searches through the stolen password databases, it reveals millions are still using 123456 as a password, so the chances of changing password behavior is nothing short of a miracle,” he added while also stressing on the need for automation.

“Passwords hold the key to our digital lives – from financial information to corporate documentation, personal photos and more. They are the first line of defense in safeguarding vital online information from cybercriminals. We tend to create and use multiple accounts for personal and professional use – more the accounts, the more usernames and passwords we seem to accumulate. Data breaches are making headlines and our poor password habits are fueling the fire. In the event of a breach, compromised login credentials and passwords are sold on the darknet for a bargain. Hackers attempt using those credentials to access as many accounts as possible, fully aware that people often use the same password for multiple accounts,” said Venkat Krishnapur, Vice President of Engineering and Managing Director, McAfee India.

He continues, “Cybercriminals often reference the most common password combinations as their first login-guessing tool. Use complex passwords and well-built passphrases that you can memorize. If possible, passwords should consist of at least 12 or more characters. Layer up your passwords and use a combination of numbers, letters, and special characters. Choose unique passwords across all of your accounts. To make life easier, use a password manager to keep track of multiple accounts. Wherever possible, opt for two-factor or multi-factor authentication for an extra layer of security, as it requires multiple levels of verification. The 5Ps (Passwords, Phishing, People, Patching and Privileges) are the most common causes for breaches. Passwords would certainly be one of the top P’s to manage, to ensure you stay safe online. This World Password Day, review your defense and diligently revamp your passwords.”

CISO MAG has listed out some best practices to be established to keep intruders at bay. These include:

  • Using Two-Factor Authentication
  • Use Passphrases Instead of Passwords
  • Observe Proper Web Security
  • Avoid Reusing Passwords
  • Protect Your Password List
  • Use a mix of lower case and upper-case letters, numbers and at least one special character
  • Change your passwords frequently
  • Don’t Mix the Business Email Account with Personal
  • Use a VPN when using public Wi-Fi to avoid interception
  • Update your Antivirus

Final Notes

It is eminent that the world will rely on passwords for the foreseeable future. With the increase in virtual identities of human it is important that passwords do not become an easily penetrable door. Because at the end of the day, it all comes back to basics — a strong password means a secured account. Stay safe on World Password Day!

About the Author

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.