Home Blog Page 233

Profiting from Panic

COVID-19

The great American businessman and philanthropist, John Rockefeller once said “I always tried to turn every disaster into an opportunity.” I doubt he ever envisaged that his words would be heeded by criminals waiting to profit from panic.

By Ashish Thapar, Managing Principal and Head – APJ Region, Verizon

Our friends from Recorded Future have confirmed the registration of thousands of fake coronavirus-related websites. Make no mistake, these domains are being used to phish for information or to infect computer networks with malware. Preying on current fears due to the global outbreak of COVID-19, criminals are banking on unsuspecting employees clicking on coronavirus-related links without thinking. The threat risk is further exacerbated by the hundreds of thousands of employees worldwide now working from home.

In its weekly summary, Verizon’s Threat Research Advisory Center outlined a number of security-related developments including patches for over 116 Microsoft products and a number of attacks involving multiple advanced persistent threat (APT) actors.

What are they doing?

Among the multiple organizations issuing warnings, the Federal Trade Commission has issued a memo alerting consumers about the increase in spoofed emails, text messages, and phone calls that claim to be from the Centers for Disease Control (CDC). These websites offer a “cure” to the virus with remedies, vaccines and testing kits.

According to the UN health agency, criminals are also attempting to pose as WHO representatives in an effort to carry out a variety of scams, from account takeovers to phony donation requests and the spread of malware.

KrebsonSecurity reported that an interactive dashboard of Coronavirus infections and deaths produced by Johns Hopkins University is being used in malicious websites to spread malware.

How are they doing it?

Even before COVID-19 crept up on us, phishing was a popular and effective technique for attackers. Phishing is an attempt, usually to steal your credentials and obtain sensitive information. These can include an email message containing a link to a fake website that looks like a log-in page from a cloud-based email provider. In 2019, nearly a third of all breaches involved a phishing attack, making it the top threat action used in successful breaches, according to Verizon’s 2019 Data Breach Investigations Report (DBIR).

When the bad guys come looking for you, they’re aware that your company has security protocols in place, so threat actors are usually forced to take at least a few actions before they get what they want. The DBIR goes on to note that 28% of the more than 2000 breaches involved malware infections – usually delivered by email – and 29% involved the use of stolen credentials, both of which are frequently accomplished through phishing attacks.

Mobile OS and apps also restrict the availability of information often necessary for verifying whether an email or webpage is fraudulent. For instance, many mobile browsers limit users’ ability to assess the quality of a website’s SSL certificate. Likewise, many mobile email apps also limit what aspects of the email header are visible and whether the email-source information is even accessible

 – 2019 Verizon Data Breach Investigative Report

What can you do?

To avoid any risk, if you spot emails coming from coronavirus-related domains, do not click on any attachments, simply delete the emails. Be wary of websites soliciting for donations, offering medical advice and supplies and advice on the financial markets. In short, don’t take the bait by clicking on links from sources you don’t know.

If the email message is conveying an important or urgent matter from an organization you know e.g. your bank or hospital, contact the sender through alternate and official channels. Of course, it goes without saying that you need to keep your system security up-to-date and encrypt/password-protect sensitive information. If you’re working from home, please ensure that your VPN contains two-factor authentication to secure your network.

Cost of Data Loss Increased to US$1 Million in the Past Year: Research

Financial Sector

The latest research from Dell Technologies revealed that the cost of data loss was increased from US$995,613 in 2018 to US$1,013,075 in 2019. In its research report, “Global Data Protection Index 2020 Snapshot”, Dell stated that the cost of data breaches are significantly increased for those organizations using more than one data protection vendor. It also highlighted that the cost of disruption is also increasing with the average cost of downtime surged from US$526,845 in 2018 to US$810,018 in 2019.

The research findings based on responses from 1,000 IT decision makers across 15 countries at public and private organizations, suggested that most organizations are managing almost 40% more data than they were a year ago, with 81% of respondents reported that their present data protection measures are not going to meet their future business needs. And more than 50% of organizations struggle to find sufficient data protection solutions for emerging technologies like 5G and edge infrastructure (67%), and AI and ML platforms (64%).

The findings also highlighted an increase in the number of organizations (80%) in 2019 that consider their data as valuable when compared to the number of organizations (74%) in 2018.  Organizations reported that there are now managing 13.53 petabytes (PB) of data, which is a 40% increase since the average 9.70PB in 2018, and an 831% increase since organizations were managing 1.45PB in 2016, according to research.

According to the study, organizations are making investments in emerging technologies, with the top five being: artificial intelligence (AI) and machine learning (ML) (53%), cloud-native applications (58%), software-as-a-service (SaaS) applications (51%), 5G and cloud edge infrastructure (49%), and Internet of Things/end point (36%).

Commenting on the research outcomes, Beth Phalen, president, Dell Technologies Data Protection, said, “Data is the lifeblood of business and the key to an organization’s digital transformation. As we enter the next data decade, resilient, reliable and modern data protection strategies are essential in helping businesses make smarter, faster decisions and combat the effects of costly disruptions.”

Phalen also highlighted that, “These findings prove that data protection needs to be central to a company’s business strategy. As the data landscape grows more complex, organizations need nimble, sustainable data protection strategies that can scale in a multi-platform, multi-cloud world.”

Axis Security Raises US$17 Million Funding, Emerges from Stealth

Axis Security Raises US$17 Million Funding, Emerges from Stealth

Axis Security, a private application access provider recently emerged from stealth mode and raised a total of US$17 million in a funding round led by Cyberstarts along with other investors like Sequoia Capital, Palo Alto Networks, Check Point, and Imperva.

Founded by Dor Knafo and Gil Azrielant, the California-based startup stated that the new funding will help the company launch its cloud-native security and analytics platform that offers organizations simple and secure control of private application access. Axis Security claims that its Application Access Cloud platform was built on a zero-trust approach and offers a new agentless model that solves the issue of implicitly open network access and removes the pain points of network-based security associated with Virtual Private Networks (VPNs).

Commenting on the new funding, Dor Knafo, co-founder and CEO of Axis Security, said, “Axis Security is helping to solve one of the most complex security challenges for IT teams. Enabling access to the basic tools of digital transformation should not be one of the biggest risks an organization takes. We’re giving IT teams what they’ve been lacking when it comes to applications and that is a single managed solution for access, security, control, and scalability without the complexity.”

Curtis Simpson, Chief Information Security Officer at Axis Security, said, “This new zero trust solution from Axis offers a modern solution to a modern problem. It enables organizations to truly monitor and manage third-party risk and is a true enabler to move users from a generally flat network to a better, more secure experience with nothing more than an internet connection. With new zero trust approaches that focus on secure application access, we are able to completely shift our strategy to securing our IT infrastructure, so that business can be accelerated, not brought to a halt. This is the way of the future.”

Singapore to Introduce Cybersecurity Labelling Scheme

Singapore cybersecurity

As part of the Safer Cyberspace Masterplan, the Cyber Security Agency (CSA) of Singapore is set to launch the Cybersecurity Labelling Scheme (CLS). For the time being, CSA will extend its rating-based CLS for Wi-Fi routers and IoT devices like smart home hubs.

Later this year, CSA will be launching the Safer Cyberspace Masterplan to increase the cyberspace hygiene in the country as it moves towards digitization and achieving the “Smart Nation” tag. The CLS is a first of its kind cybersecurity rating in the APAC region aimed at helping the consumers make informed choices. These cybersecurity labels will act as a scale or measure for the security provisions that a certain product offers. The rating will be decided on a series of assessments and tests including but not limited to:

  • Meeting of basic security requirements (e.g. unique default passwords)
  • Adherence to software and hardware secure-by-design principles
  • Common software security vulnerabilities should be absent
  • Resist basic penetration testing activity

The CLS will distinguish and grade the smart devices available in the market. CSA also plans to start incentive-based labeling with an aim to develop products with improved security features. Currently, consumer-based IoT devices are often designed to optimize functionality, reduce cost and have a very short time-to-market cycle, thus giving cybersecurity a backseat. However, the implementation of CLS shall change this perception and give more stress on the cybersecurity quotient of these IoT devices.

Earlier in November 2019, in order to boost cybersecurity and tackle next-generation cyberthreats, the Singapore government decided to adopt new data protection measures. The government also established a committee, named Public Sector Data Security Review Committee, to review its data security practices.

As per reports, the committee chaired by the Minister-in-charge of Public Sector Data Governance, Teo Chee Hean, inspected around 336 network systems across 94 government agencies and observed international data security practices in the financial and healthcare sectors.

Hellman & Friedman to Acquire Cybersecurity Firm Checkmarx

Hellman & Friedman to Acquire Cybersecurity Firm Checkmarx

Hellman & Friedman, a private equity and venture capital firm that invests in high growth technology organizations, has entered into a definitive agreement to acquire cybersecurity firm Checkmarx, from private equity firm Insight Partners, at a valuation of US$1.15 billion. Checkmarx stated that the new acquisition will further boost its growth and expand its business reach.

Headquartered in Israel, Checkmarx provides Application Security Testing solutions for modern enterprises. It helps enterprises deliver secure software solutions by making security quality essential to software development.

Speaking on the new acquisition, Emmanuel Benzaquen, CEO of Checkmarx, said, “With more corporations leveraging software development to scale their businesses than ever before, executives are acutely aware of the increased risks caused by software exposure. More than 40 of the Fortune 100 have turned to Checkmarx to mitigate risk, secure code, and embed security into every aspect of their software development. We are thrilled to partner with H&F in our journey that takes our ‘software equals security’ vision to the next level.”

“As cybersecurity threats continue to intensify, we strongly believe that embedding security early in the software development lifecycle is critical. Only one company – Checkmarx – has the breadth of products, developer-centric DNA, and culture of relentless innovation to serve the entire software security market,” said Hellman & Friedman Partner, Tarim Wasim.

NCSC Issues Guidelines to U.K. Citizens to Check Covid-19 Fraud

cyberattacks on U.K. organizations

Opportunistic cybercriminals are taking advantage of the fear and uncertainty that’s created due to the Covid-19 pandemic. The U.K.’s National Cyber Security Center (NCSC) has issued a public alert to warn citizens about this, with guidance on how to protect themselves from cybercriminals.

According to the National Fraud Intelligence Bureau, there are multiple reports of fraud involving coronavirus links, with losses to victims reaching close to £1m (approximately US$ 1.23 million). The losses are mostly due to victims attempting to buy protective face masks from fraudulent online sellers. One victim lost more than £15,000 (approximately US$ 18,378.96) when they purchased products that were never delivered. Similar incidents are also being reported elsewhere in the world.

The NCSC has issued guidelines on how to identify and deal with a suspicious phishing email and how organizations should defend themselves from malware and ransomware attacks. Citizens can also report suspicious emails, phone calls or SMS messages to Action Fraud – National Fraud & Cyber Crime Reporting Centre, which also offers a 24/7 online reporting tool for businesses.

Paul Chichester, Director of Operations at the NCSC, said: “Our advice to the public is to follow our guidance, which includes everything from password advice to spotting suspect emails. In the event that someone does fall victim to a phishing attempt, they should look to report this to Action Fraud as soon as possible.”

NCSC also offers advice for protecting data and devices at home, and this is useful for employees who are asked to work from home. In addition, it offers a guide for small businesses. And NCSC provides information for the self-employed and sole traders too.

If organizations have already been infected, then they can follow NCSC’s advice here. And organizations that have networks of national significance can use Cyber Incident Response (CIR) certified companies to help them deal with targeted attacks.

U.S. CyberDome Forms PC-ISAO Group to Share Cyberthreats Information

U.S. CyberDome, a cybersecurity provider to political parties, announced that it’s going to share cyberthreat information with political campaigns. The organization also founded the Political Campaign Information Sharing and Analysis Organizations (PC-ISAOs) through the U.S. Presidential Executive Order for Promoting Private Sector Cybersecurity Information Sharing.

The PC-ISAO was chartered to help organizations that are often in need of outside cybersecurity support. Political campaigns at all levels of U.S. federal, state, local, tribal, and territorial government are invited to participate.

“The PC-ISAO is a neutral and non-partisan venue where technologists can share critical cybersecurity alerts and best practices,” said former Homeland Secretary Michael Chertoff, who serves on the U.S. CyberDome Board of Advisors. “The PC-ISAO helps members collaborate on critical cybersecurity challenges.”

U.S. CyberDome provides free cybersecurity services to political parties, elected representatives, and candidates across party lines, to ensure the integrity of the process and confidence in the results. It is comprised of cybersecurity experts who have trained and practiced at the world’s largest accredited computer forensics and incident response institute in the world, the Defense Cyber Crime Center, the U.S. Department of Defense, and the National Institute of Standards and Technology.

“U.S. CyberDome is a non-partisan, not-for-profit organization that protects political campaigns from cyber and dis-information threats. The organization furthers that effort today by announcing the formation of the first-ever information sharing and analysis organization for political campaigns,” said former Homeland Secretary Jeh Johnson, who serves as Chairman of U.S. CyberDome’s Board of Advisors.

88% of Security Pros Believe the World is in State of Cyber War: Venafi Survey

cyber war

A survey from cybersecurity firm Venafi revealed that 88% of security leaders and professionals believe the world is in a state of cyber war. The survey findings, based on the responses of 485 security decision-makers, found that 90% of security pros are concerned about the future of digital infrastructure due to rising cyber epidemic.

According to the survey, organizations that are undergoing digital transformation are the most vulnerable to cyber risks. Nearly 60% of respondents said industries in power, water, healthcare, and transportation sector are also vulnerable to cyberattacks, with 19% believing that the power sector was most vulnerable, followed by healthcare (12%), and transportation and water (5%).

Venafi provides machine identity protection services for enterprises to secure machine-to-machine connections and communications. It offers global visibility of machine identities and cyber risks associated with them for enterprises on-premises, mobile, virtual, cloud, and IoT.

Speaking on the survey outputs, Kevin Bocek, Vice President of security strategy and threat intelligence at Venafi, said, “Security professionals are under constant siege from very sophisticated threat actors targeting government, military and private organizations. Powerful attack methods, like establishing backdoors with machine identities, are now available as commodity malware, making it harder for security professionals to defend against these attacks.”

“The sophisticated cyberattacks that are the hallmark of nation state attacks often target digital keys and certificates that serve as machine identities. These critical security assets are often poorly protected and provide attackers with the ability to hide in encrypted traffic, pivot across networks and eavesdrop on sensitive data. Any organization that isn’t protecting machine identities at least as well as they protect usernames and password is at greater risk of becoming a victim of a cyberattack. And, unfortunately, these risks are unlikely to change in the near term because most organizations are just beginning to understand these risks,” Bocek added.

A similar survey by cloud security firm Morphean, which surveyed over 1000 IT decision-makers across Europe, revealed that physical security systems are not optimized. According to the survey, 77% of IT managers said that physical security is not optimized and 20% identified physical security as a priority for improvement in 2020. While nearly 50% of IT managers stated that they’re using cloud-based video surveillance (VSaaS) or access control (ACaaS) solutions.

Dutch Researcher Claims Google’s US$100,000 Bug Bounty

Google Cloud, Google bug bounty

In August 2020, Google introduced an annual bug bounty or vulnerability reward program (VRP) for its Google Cloud Platform (GCP). Sighting under-representation of research on the GCP, Google kept a bounty prize of US$100,000 to generate interest among bounty hunters. They seem to have succeeded in their endeavor, as a Dutch researcher by the name of Wouter ter Maat has been announced as the winner of 2019 GCP VRP prize for his findings of Google Cloud Shell vulnerabilities.

What is Google Cloud Shell?

The GCS grants both–administrators and developers, quick access to cloud resources. It provides a Linux shell that is accessible from the front-end through a browser. The shell comes with pre-installed tools required for working on Google Cloud Platform projects, such as google cloud, Docker, Python, vim, Emacs and Theia, a powerful opensource IDE.

Wouter ter Maat discovered a total of nine vulnerabilities in the GCS which is mentioned in the video streamed on LiveOverflow YouTube channel. He was able to connect with the resources after launching the Cloud Shell, entered a container, escaped from it and then accessed the full host by examining the file system. The security researcher was alerted when he found two Docker UNIX sockets:

  1. /run/docker.sock
  2. /google/host/var/run/docker.sock

Of the two, the second was a host-based Docker socket. By simply writing a few quick scripts, Wouter established communication with the host-based Docker socket, then escaped the container and gained privileged root access. Privileged root access helps attackers to potentially control and access everything on the GCP.

Google Cloud Platform Vulnerability Reward Program (VRP) 2020

Since the previous Google bug bounty program has worked in Google’s favor, it has now decided to triple the GCP VRP prize money for 2020. It will pay total prize money amounting to US$313,337 among top six vulnerability submissions as follows:

  • 1st prize: US$133,337
  • 2nd prize: US $73,331
  • 3rd prize: US$73,331
  • 4th prize: US$31,337
  • 5th prize: US$1,001
  • 6th prize: US$1,000

DESC launches Industrial Control Systems Security Standard for Dubai

Dubai

To provide a new and improved framework for industrial security, the Dubai Electronic Security Center (DESC) has launched Industrial Control Systems (ICS) Security Standard for the city. The ICS Security Standard is aimed at fortifying the industrial sector’s digital infrastructure against the rise in cyberattacks while also trying to position Dubai among the safest cities in cyberspace.

The framework for the regulation has been evolved through a series of workshops with several stakeholders who have given the initial framework a thorough examination and have aligned it with several global ICS security standards. The new regulation also places a key emphasis on industrial control systems and operational technologies.

“UAE is committed to lead in the race towards digital transformation by adapting Artificial intelligence (AI) tools, the application of Internet of Things (IoT) and other smart technologies, especially ones that rely on 5G networks,” said Dr. Bushra Al Blooshi, Deputy Director of Information Services Department at DESC, at the launch conference, while also stressing that the new regulations are a “crucial step towards protecting digital data across all sectors and at all cost.”

Amer Sharaf, Director of Compliance, Support and Alliances at DESC, noted that the regulation “aligns with DESC’s strategy of applying the best security standards to promote the safety of information systems and enable it to confront and tackle challenges in this domain.” He stressed that the DESC has been supporting government entities in several projects while also the highest levels of electronic security standards within safe and stable environments.

According to an earlier market research report “Industrial Cybersecurity Market is expected to be valued at US$22.79 billion by 2023, growing at a CAGR of 8.6% from 2017 to 2023. Ever since the grids on the Industrial sector have taken the connected road, it has opened a floodgate of threats. Previously, industrial facilities were largely air-gapped, so hackers had to manipulate staff through social engineering attacks, or infiltrate facilities themselves. But as more industrial IT components connect to the internet, they become more exposed to cyberattacks from advanced persistent threats (APTs).

“Industrial facilities have become more connected. Cloud computing has prompted a growing number of enterprises to shift their workload online. More facilities are also incorporating smart devices into their infrastructure. Unfortunately, this is also expanding the attack surface. Given how tenacious threat groups are these days, increasing connectivity can make these enterprises vulnerable to attack,” Oren Eytan, CEO of enterprise cybersecurity firm odix, shared in an earlier report in CISO MAG.