Home Blog Page 228

45% of Indians Don’t Backup Their Information: Avast Survey

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

According to a new survey from Avast, a provider of digital security products, 45% of Indians don’t backup their data, as they don’t think it’s important enough to secure their data or files. Over 34% of the people who don’t backup their files, claim that they don’t have any critical data to back up. Further, 32% respondents said they don’t know how to back up their data; 22% said they forget to backup, and 22% reported that they don’t have time.  The findings are based on the responses from 728 Avast and AVG users, surveyed from February 20  to March 25, 2020.

Of those who do back up their data, over 42%  back up to a cloud storage, 36% back up their data to an external hard drive, 23% on a USB flash disk, 18% backup their phone to their PC, and 10% backup to a network storage drive.

The survey also revealed that around 53% take backups once in a month, 12% continuously, 15% every 6-12 months, and 7% less than yearly. The percentage of iPhone and Android phone users who backup is nearly the same, with 69% and 70% respectively. However, the monthly backup frequency of iPhone and Android users varies, with 67% and 59% respectively.

Several industry experts express concern about data loss caused by users when they accidentally delete their information. This could have a big impact on consumers if no data backup is available.  Especially, in situations like data breach incidents and ransomware attacks, which can either encrypt or destroy files;  there is no guarantee that files can be released even after paying the ransom.

In its earlier research, Avast revealed that Adware (advertising-supported software) is responsible for 72% of all mobile malware and the remaining 28% related to banking trojans, fake apps, lockers, and downloaders. Adware is a kind of software that hijacks mobile devices to spam the victim with unwanted ads. The threat intelligence team from Avast stated that Android adware is a rising issue with its number increased by 38% in the past year alone.

According to Avast, Adware disguises itself in the form of gaming and entertainment apps to infect the devices when a user clicks on ads. These apps appear genuine while installing, but once opened, they start spamming the user with ads (mostly with malicious content). This happens when a user downloads apps that run stealthy activities without the user’s knowledge like downloading an encrypted .dex file in the background of a device.

Trend Micro and CyberX to Drive Cybersecurity Awareness in Saudi Arabia

Saudi Arabia

Trend Micro announced a partnership with CyberX, a government-backed initiative, to drive cybersecurity awareness in Saudi Arabia.

Showing the strong need for cybersecurity, the Kingdom ranked as the most-attacked GCC country for malware and banking malware in 2019, with Trend Micro’s 2019 Security Roundup Report recording 2,352,570 malware attacks and 4,731 banking malware attacks.

Trend Micro will serve as Strategic Technology Contributor of CyberX, a Saudi community initiative under the umbrella of “Attaa initiative” to raise awareness of cybersecurity threats in society.

CyberX is a non-profit and aims to enrich the readable and audible Arabic content in the field of cybersecurity through a set of products such as: podcast, 60 seconds, Meet the specialists, CyberX awareness, Infographics and CyberX videos for awareness and educational content designed to cover multiple topics for several categories.

In addition to educational content presented in various forms that are appropriate to the nature of the content, CyberX is characterized by renewed ideas that are analyzed by experts in the field in which they discuss key security topics, concerns, and how to tackle them.

Trend Micro’s Initiative for Education is the parent program for numerous global initiatives that support Internet safety for kids and families, small businesses, and universities.

Cybersecurity Training

In a related development, Kaspersky and Saudi Federation for Cybersecurity, Programming and Drones (SAFCSP) signed an MoU for cybersecurity training in Saudi Arabia.

As per the MoU, Kaspersky will support the SAFCSP in its CyberHub initiative, which will gather students from 28 different universities from across the region to set up specialized cybersecurity clubs. Kaspersky will provide SAFCSP with training materials on cybersecurity and programming. The company will also contribute to CyberHub by organizing various conferences, workshops, and invite speakers to provide students with a first-hand overview of the requirements, opportunities, and challenges in the cybersecurity sector.

Industry experts opine that this kind of private and government entities’ alliance will enhance the technological advancements and increase the cybersecurity readiness of Saudi Arabia.

Hackers Target Australians with Phishing Attacks Amid COVID-19 Crisis

Cryptocurrency scams in Australia

With majority of the employees working remotely, cybercriminals are taking advantage of the ongoing COVID-19 crisis across the globe. Several industry experts stated that remote work increased the risks of cyberthreats like never before. We continue to see malware attacks, weaponized websites, and phishing attacks targeted to trick people into opening Coronavirus-related malicious links or attachments.

Australia has seen a sudden surge in cyberattacks amid the pandemic, which led the Australian Cyber Security Centre (ACSC) to release a new threat report exposing how cybercriminals are exploiting the situation for their own gain through phishing schemes and malicious activities. The report is intended to raise awareness of increasing COVID-19-related malicious cyberthreats and provide cybersecurity advice in real-time that organizations and individuals can follow to reduce cyber risks.

Coronavirus-Related Malicious Cyber Operations

According to the report, enterprises in Australia have seen a significant increase in COVID-19 themed malicious cyber activities since early March 2020. The Australian Competition and Consumer Commission’s (ACCC) Scamwatch has suffered over 100 reports of scams about COVID-19 in the last three months. It’s said that between March 10 and 26, 2020, the ACSC received around 45 cybercrime and security incident reports from individuals and businesses, which are related to COVID-19 themed scam and phishing activities. It’s expected that the number of these malicious activities are likely to be much higher, as these numbers only represent those incidents reported only to the ACSC and ACCC.

Cyberthreat Mitigation Strategies

ACSC also recommended a few threat mitigation strategies to combat COVID-19-related phishing scams. These include:

  • Before opening an email, consider who is sending it to you and what they’re asking you to do. If you are unsure, call the organization you suspect the suspicious message is from, using contact details from a verified website or other trusted source.
  • Do not open attachments or click on links in unsolicited emails or messages.
  • Do not provide personal information to unverified sources and never provide remote access to your computer.
  • Remember that reputable organizations locally and overseas—including banks, government departments, Amazon, PayPal, Google, Apple and Facebook—will not call or email to verify or update your personal information.
  • Use email, SMS or social media providers that offer spam and message scanning.
  • Use two-factor authentication (2FA) on all essential services such as email, bank and social media accounts, as this way of double-checking identity is stronger than a simple password. 2FA requires you to provide two things, your password and something else (such as a code sent to your mobile device or your fingerprint) before you – or anyone pretending to be you – can access your account.

Japanese Consumers in Panic Buying Mode for Face Masks; Become Victims of Phishing

Japan restricts foreign equipment and tech, Japan Embraces AI Tools to Fight Cyberattacks with US$237 mn Investment

The Japan Times reported that the Japan Cybercrime Control Center has raised the alerts for cybercrimes in Japan, triggered by hackers taking advantage over fear and certainty due to COVID-19. Criminals are capitalizing on fear to lure victims into elaborate traps and hackers are reaching out to victims via hoax and phishing emails.

Many instances are being reported about hoax emails with offers for free surgical masks, which are in short supply. For instance, one message in Japanese says: “Pneumonia caused by the new Coronavirus is a problem that is spreading. We’ve sent you free surgical masks. Please confirm.”

Hackers are sending these email messages to Japanese consumers and the messages even promise home deliveries. Most Internet users in Japan access email on their mobile phones and could click on these malicious links impulsively to trigger an attack on their devices.

Such mails have a hyperlink that the recipient is encouraged to click. Clicking on the hyperlink takes the recipient to a seemingly legitimate website, where they are asked to install an app. This will make the phone vulnerable to hackers, enabling them to steal their Apple ID and password, and perhaps even their credit card details.

The Japan Cybercrime Control Center also received reports from people who were trying to buy face masks online but were instead redirected to fake shopping sites designed to look like legitimate sites. However, when they ordered the masks and paid for those, the masks were never delivered. The fake sites also collected their personal information and credit card details.

The earliest phishing scams related to COVID-19 that targeted some regions in Japan were discovered by IBM X-Force researchers at the end of January 2020.

The Emotet Malspam

The earliest phishing emails in Japan were discovered at the end of January 2020. Analysts from IBM X-Force and Kaspersky along with infosec community discovered attempts to spread the Emotet Trojan and other malware using phishing emails. The experts found that Emotet operators used previously compromised account templates to target potential victims for the Emotet malspam campaign.

According to IBM, the attackers seem to be geo-targeting the email content and language to inflict fear among audiences in these areas, thus, making them more likely to click on the malicious attachment. One of the malspam emails said that the Coronavirus had been detected in the Gifu region of Japan, while another mentions Osaka. A few of these emails also have a footer that mentions a legit address, as well as phone and fax numbers of disability welfare service providers and public health centers in the surrounding areas.

 

Cybercriminals Target Zoom Domains to Distribute Malware

Verizon’s Chatbox Flaw Leaks Customers’ Personal Information

With the COVID-19 pandemic, organizations across the world restricted their employees to work from home as part of social distancing and to prevent the spread of the virus. On the flipside, opportunistic cybercriminals are taking advantage of the situation. Hackers have now set their sights on the global workforce working from home. Several industry experts stated that remote work increased the risks of cyberthreats like never before. We continue to see malware attacks, weaponized websites, and phishing attacks targeted to trick people into opening malicious links or attachments.

With the majority of the employees working remotely, online communication platforms like Zoom saw a sudden increase in its popularity.  According to a report from Check Point, hackers are taking advantage of the rise in Zoom usage by registering fake and malicious Zoom domains. The report stated that around 1,700 new Zoom domains have been registered since the pandemic, with 25% of the domains registered in the past seven days alone.

Zoom is a cloud-based enterprise communication platform with over 74,000 customers and 13 million active users. It offers chat, audio, video conferencing, and options to host webinars and virtual meetings online.

In addition, Check Point also detected malicious files named as “zoom-us-zoom_##########.exe” and “microsoft-teams_V#mu#D_##########.exe”. If one runs/downloads these files, it’ll lead to the installation of malicious file “InstallCore PUA” on the victim’s device, which could lead to additional malicious software installations.

Coronavirus-themed Domains 50% more Malicious than Other Domains

Based on Check Point’s Threat Intelligence Report, there are over 4,000 coronavirus-related domains registered globally, in which 3% (approximately 120 domains) were found to be malicious and an additional 5% (200 domains) are suspicious. The report stated that Coronavirus- related domains are 50% more malicious than other domains registered in the same period.

Check Point also recommended few tips to help users protect against attacks, these include:

  • Be cautious with emails and files received from unknown senders, especially if they are offering special deals or discounts
  • Don’t open unknown attachments or click on links within the emails
  • Beware of lookalike domains, spelling errors in emails and websites, and unfamiliar email senders
  • Ensure you are ordering goods from an authentic source. One way to do this is NOT to click on promotional links in emails, and instead, Google your desired retailer and click the link from the Google results page
  • Prevent zero-day attacks with a holistic, end to end cyber architecture

IoT Connections to Reach 83 Billion by 2024: Report

IoT Connections to Reach 83 Billion by 2024: Report, CISA alerts critical infrastructure, CISA – FBI holiday season alert

A new report from Juniper Networks, a provider of AI-driven networks, found that the total number of IoT connections will reach 83 billion by 2024, from 35 billion connections in 2020, which represents a growth of 130% over the next 4 years.

The research, “The Internet of Things: Consumer, Industrial & Public Services 2020-2024”, revealed the industrial sector as a key player for IoT connections growth. It’s said that the industrial sector accounted for 60 billion IoT connections presently. The research findings also highlighted that the industrial sector, including manufacturing, retail, and agriculture will account for 70% of IoT connections by 2024. It’s expected that the emergence of cost-efficient private cellular networks would be a key driver of growth over the next 4 years, with nearly 180% growth over the next 4 years.

Research co-author Sam Barker said, “Industrial networks will need to scale rapidly as industrial IoT users adopt new technologies to expand the services available on their networks. However, IoT platforms must ensure that the security processes can scale alongside this network growth.”

Growing IoT Networks Bring New Security Threats

With the number and purpose of connected devices increasing rapidly, the concerns over security threats also increase. The research stressed that IoT networks must implement steps to maximize security in all layers of the IoT ecosystem, including devices and connectivity. The research advised enterprises to implement necessary security measures to defend from cyberattacks. It suggested two key areas of focus:the use of network segmentation to mitigate cyber risks, and ensuring that the lifecycle management of network assets is properly maintained.

70% of Organizations Suffer IoT Attacks

A similar survey, from the security firm Extreme Networks, revealed that organizations remain highly vulnerable to IoT-based attacks. The research, which surveyed 540 security professionals across organizations in North America, Europe, and the Asia Pacific, found that 84% of organizations have IoT devices on their corporate networks. It also stated that more than 50% of the organizations don’t maintain necessary security measures beyond default passwords.

Telecom Firm Virgin Media Faces Class-Action Suit Over Customer Data Breach

Surveillance Legislation (Identify and Disrupt) Amendment Bill

Legal organization Your Lawyers and leading newspapers like the Daily Mail and The Sun in the U.K. report that Virgin Media, faced a class-action lawsuit of £4.5billion (approximately US$5.5 billion) after exposing its customers’ private details online for almost 10 months, from April 2019 until February 28, 2020. Virgin Media is a provider of telephone, television, and internet services in the U.K. It could be forced to pay a compensation for financial and emotional distress suffered by the victims, which is expected to be around £5,000 (around US$6,145) per claimant.

Breach Overview

Earlier this month, Virgin Media revealed that it discovered an unsecured database that exposed the personal information of around 900,000 customers, which is 15% of the company’s entire customer base. According to the official release, the exposed information includes names, home addresses, emails, phone numbers, product information, and details of their porn searches. The incident response team at Virgin Media stated that the database was used for marketing activities and did not contain sensitive information like passwords, credit/debit card numbers, and other financial details.

The company stated it already notified the Information Commissioner’s Office, the U.K.’s data protection watchdog, for further investigation on the security incident. It also warned the affected customers to be vary of phishing attacks.

Virgin Media’s Cybersecurity Negligence  

Your Lawyers, a U.K. legal organization supporting the affected consumers, stated that Virgin Media failed to protect its customers from the security incident, which left the victims vulnerable to various scams like phishing attacks, account takeovers, identity theft, and other cyber risks.

Aman Johal, Director at Your Lawyers, said, “Virgin Media failed to take the steps required to keep customer data safe. It is vital for the company to understand the severity of this breach. When data is left exposed online it is open season for fraudsters to scam and attack vulnerable people. Your Lawyers has formally notified Virgin Media that we are taking action and our claimant base is growing daily. We urge anyone affected by the breach to make a claim as soon as possible.”

Several industry experts blamed Virgin Media for its negligence in implementing proper cybersecurity measures to protect its customers from the data leak. It’s is also believed that the company might face other financial costs in the form of a GDPR fine.

International Cybersecurity Experts Come Together to Fight COVID-19 Related Cyberthreats

Top Cybersecurity Jobs in 2021

The COVID-19 outbreak has led to a rise in hacking attempts, affecting cyberspace. Threat actors are distributing malware disguised as Coronavirus-related health care products to steal personal information from regular internet users. They even designed multiple websites related to Coronavirus information to lure users to click/download malicious applications. The ongoing pandemic has also led organizations across the world to restrict their employees to work from home.

In order to address rising cyberthreats globally, an international group of 400 cybersecurity professionals has come together to combat these cyberattacks. The group, named “COVID-19 CTI League (for cyber threat intelligence), consists of members from more than 40 countries and includes security leaders from major organizations like Microsoft and Amazon.

The COVID-19 CTI League

According to Reuters, the Cyber Threat Intelligence League was founded by security decision-makers Ohad Zaidenberg, Nate Warfield, Chris Mills, and Marc Rogers. Primarily, the group is aimed at preventing cyberattacks against health care facilities and providers. The group is defending health care organizations from cyberattacks and is also using its contacts in internet infrastructure providers to avert phishing attacks and other financially motivated cybercrimes that are using the fear of this pandemic to lure internet users.

According to Marc Rogers, VP of cybersecurity strategy at Okta and DEF CON’s head of security, the COVID-19 CTI League has already traced and dismantled a hacking campaign that used a software vulnerability to distribute malware. Commenting on how the Coronavirus outbreak led to a huge surge in phishing attacks, Rogers said, “I’ve never seen this volume of phishing. I’m literally seeing phishing messages in every language known to man.”

Cybersecurity Firms Allied to Thwart Cyber Risks

With a similar motive, investment firm C5 Capital recently created the C5 Alliance of leading cybersecurity firms including  ITC Secure, IronNet, Haven Cyber Technologies, Enveil, 4iQ, and Blue Cedar to combat new threat vectors. The alliance is a response to a 150% increase in healthcare cyberattacks in the last two months, such as phishing emails pretending to be from the World Health Organization (WHO), and ransomware. The alliance will help ensure hospitals and clinics protect their internal systems and databases for patients, healthcare workers, and volunteers.

As part of the alliance, Collective Cyber Defense for Healthcare initiative has been launched to free access for hospitals, clinics and other medical facilities in the U.K. and Europe, to C5’s IronDome system.  The collective crowdsourcing defense product, based on IronNet’s collective defense solution, will be managed by ITC Secure’s SOC in London.

How to Communicate Security to the Board

Board meeting, CISO, leadership

Effectively communicating with company executives has always been a challenge for us in information security. Sometimes I felt like a complete stranger in a land where nobody spoke my language. These stressful meetings inevitably ended up in two outcomes, neither desirable: executives either agreed with our recommendations without truly understanding the needs (a.k.a. “alright kids, here is some money, now go buy some toys and leave us alone”)—downright rejection.

By Glauco Sampaio, CISO for Cielo

Much of these communication issues can be blamed on how security professionals craft the message:

• Extensive use of security jargon and technical acronyms
• Assumptions that executives understand the roles of different solutions (such as firewall, anti-spam, anti-malware
• The use of terrorism, particularly when reacting to an important incident, to justify security requirements
• Justify the request only on legal requirements, audit findings or the need to obtain certifications

I always left these meetings with a nagging feeling that things could be different and that we should be able to establish a common understanding of challenges and recommendations. It was not uncommon for both sides to feel a bit embarrassed about the situation.

I once had a boss who nagged me a lot, until our presentations integrated technical jargon, carefully making the content understandable to my audiences. It was a long and sometimes frustrating journey until I understood that a new approach was needed. I was not able to lead my executive audience to develop the empathy required to fully appreciate security challenges.

Flawed approach

The adoption of security frameworks and best practices as a driver for the actions was a different approach. Being in compliance with these standards was a path that showed maturity in the security areas, in addition to being measurable. It was possible, after the execution of the proposed security plan, to show the evolution of security controls, justifying the budget and resources that were granted through numbers was something that brought comfort to our presentations and was understandable to executives.

In my experience, the problem with this approach is identifying the ideal maturity level for each company. Do we really need to be in the state of the art in all security disciplines? Is being within the market average enough or do we need to be at the top of the list of adherences to a certain framework? Hearing these questions is challenging and the answer can be complex.

With professional maturity, I started to understand that we need to approach executives presenting in a language that was intelligible to them. I gained an appreciation that executives engage when there is a mutual and clear understanding of the rationale behind specific tasks. For example, “DDoS Protection” takes on a whole different meaning when presented as a mechanism to prevent attacks that can lead to the unavailability of customer-facing services. The simple change in the way of presenting opens the opportunity for the executive to understand the “risk” that we are trying to mitigate. We cannot deny that the impact of major incidents caused by cyberattacks within the last few years and the media attention dedicated to these have helped a lot to raise awareness of the importance of cybersecurity to the executives.

I started to use risk concepts to justify security investment needs and associate these requests with possible impacts on the business. This is a similar approach I had used when building business continuity plans.

Another support for this approach was the use of threat modeling. Starting with the definition of the risk scenarios that need addressing, reframes the conversation around business impacts without the need for in-depth security knowledge.

The big question now revolves around how to measure these risks. Most of the analysis points out that the impacts and the probabilities are very high, defeating the purpose of any attempt on prioritization. All scenarios become a high risk to the organization, ignoring the existence of existing security controls that mitigate these can severely hinder attempts to prioritize.

An appetite for risk

How much do we need to invest in enhancing security controls? Do we need to drive towards residual risks whose impact becomes negligible? Companies must have a risk appetite culture. To make this possible, it’s our role to present the risks in a way that makes it feasible for executives to make decisions to fund investments, change processes and even modify the characteristics of products or services. We must learn to measure the company’s risks and know how to size and how much this scenario will be impacted by the proposed controls. At a simplistic level, a specific control implementation should not cost more than its total benefit for the company.

It may look utopian to think about making this type of measurement. In some cases it is relatively simple, especially when we are talking about the security of systems and business environments: how much the unavailability of service due to a denial of service attack costs or the total financial impact or how much the absence of a control or a vulnerability that enables fraud in a financial system can represent a monetary loss. Even the case of customer information leak, today with the establishment of privacy laws around the world, are more easily quantifiable due to fines being imposed by governments on companies.

Other scenarios, more technical, are harder to be measured and quantified. Security professionals need to develop an assumption-based model that allows for a general quantification of different impact scenarios to the business. While imprecise by nature, the usage of a consistent model across a variety of issues can provide a powerful tool for prioritization by executives.

Risk management must always be discussed with company executives, as they are the ultimate decision-makers. Our role, as persons being responsible for the security of our companies, is to support these decisions with reliable data. This collaborative governance process creates a shared responsibility model between security professionals and executives based on transparency and trust.

This topic is constantly evolving and there are some mature frameworks on the market that can help us to measure and quantify security risks. I recommend that they are studied and applied by all of us. Their application in different scenarios, cultures, countries, and levels of maturity will ensure that we stay on the right path.

About the Author

Glauco Sampaio is an information security professional who lives in Brazil. He has 20 years of experience and has served media companies such as iG and Editora Abril. He has also worked in financial institutions such as Santander Bank, Votorantim Bank and Original Bank. He is currently working as CISO for Cielo, where he oversees the security strategy for the largest Brazilian credit and debit card operator.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

“You’re Exposed to Coronavirus” Says Phishing Email

Phishing Campaign on FINRA

With cybercriminals taking advantage of the Coronavirus pandemic, we continue to see malware attacks, weaponized websites, and phishing attacks to trick people into opening malicious links or attachments.

Recently, a new kind of phishing campaign has been discovered that pretends to be from local hospital authorities informing the recipient that they’re exposed to the Coronavirus and need to be tested, the BleepingComputer reported. In addition, the attackers also claimed, in the email, that they’ve been in contact with the friend, colleague or family member who was tested positive for the COVID-19 virus. It further asked the recipient to print the attached “EmergencyContact.xlsm” document and bring it with them to the nearest hospital for testing.

Malicious Attachments

When users click/download the attachment, they will be prompted to “Enable Content” to view the protected document. This allows malicious macros to be executed by themselves to download a malware executable to the computer.

In its analysis, the BleepingComputer revealed that the malware can perform various malicious operations, which include:

  • Search for and possibly steal cryptocurrency wallets
  • Steals web browser cookies that could allow attackers to log in to sites with your account
  • Gets a list of programs running on the computer
  • Looks for open shares on the network with the net view /all /domain command
  • Gets local IP address information configured on the computer

Cybercriminals trying to benefit from the global epidemic to distribute malicious activity through various spam hacking campaigns.  In a similar phishing attack, a hacker group targeted the World Health Organization (WHO) via a sophisticated phishing attack, which involved an email hosted on a phishing domain that tried to trick the employees into entering their credentials. It’s said that WHO observed the hacking attempt in mid-March and is suspected to have come from DarkHotel, a threat group from Southeast Asia that has been active since 2004.