Home Blog Page 237

CrowdStrike Report Reveals Telecommunications Industry Attacks on the Rise

Telecommunications

CrowdStrike Inc. the developer of cloud-delivered endpoint protection solutions, announced the release of the 2020 CrowdStrike Global Threat Report. Findings from the report indicate that during 2019, financially motivated cybercrime activity occurred on a nearly continuous basis. CrowdStrike observed an increase in incidents of ransomware, maturation of the tactics used, and increasing ransom demands from eCrime actors. Increasingly these actors have begun conducting data exfiltration, enabling the weaponization of sensitive data through threats of leaking embarrassing or proprietary information.

Moving beyond eCrime, nation-state adversaries continued unabated throughout 2019, targeting a wide range of industries. Another key trend in this year’s report is the telecommunications industry being targeted with increased frequency by threat actors, such as China and DPRK. CrowdStrike Intelligence assesses that various nations, particularly China, have an interest in targeting this sector to steal intellectual property and competitive intelligence.

Combatting threats from sophisticated nation-state and eCrime adversaries requires a mature process that can prevent, detect and respond to threats with speed and agility. CrowdStrike recommends organizations to pursue the “1-10-60 rule” in order to effectively thwart cyber threats. 1-10-60 guidelines are the following: detect intrusions in under one minute; investigate in 10 minutes; contain and eliminate the adversary in 60 minutes. Organizations that meet this benchmark are much more likely to eradicate the adversary before an attack spreads from its initial entry point, ultimately minimizing organizational impact.

“2019 brought an onslaught of new techniques from nation-state actors and an increasingly complex eCrime underground filled with brazen tactics and massive increases in targeted ransomware demands. As such, modern security teams must employ technologies to detect, investigate and remediate incidents faster with swift preemptive countermeasures, such as threat intelligence, and follow the 1-10-60 rule,” said Adam Meyers, Vice President of Intelligence at CrowdStrike. 

Other notable highlights from the 2020 Global Threat Report include:

  • The trend toward malware-free tactics accelerated, with malware-free attacks surpassing the volume of malware attacks. In 2019, 51% of attacks used malware-free techniques compared to 40% using malware-free techniques in 2018, underscoring the need to advance beyond traditional antivirus (AV) solutions.
  • China continues to focus many operations on supply chain compromises, demonstrating the nation-state’s continued use of this tactic to identify and infect multiple victims. Other targeting of key U.S. industries deemed vital to China’s strategic interests — including clean energy, healthcare, biotechnology, and pharmaceuticals — is also likely to continue.
  • The industries at the top of the target list for enterprise ransomware (Big Game Hunting) observed were local governments and municipalities, academic institutions, the technology sector, healthcare, manufacturing, financial services and media companies.
  • In addition to supporting currency generation, DPRK’s targeting of cryptocurrency exchanges could support espionage-oriented efforts designed to collect information on users or cryptocurrency operations and systems. In addition, CrowdStrike Intelligence suspects that DPRK has also been developing its own cryptocurrency to further circumvent sanctions.

“This year’s report indicates a massive increase in eCrime behavior can easily disrupt business operations, with criminals employing tactics to leave organizations inoperable for large periods of time. It’s imperative that modern organizations employ a sophisticated security strategy that includes better detection and response and 24/7/365 managed threat hunting to pinpoint incidents and mitigate risks,” said Jennifer Ayers, Vice President of OverWatch at CrowdStrike.

Ultrasonic Waves Used to Launch Surfing Attacks on Smartphones

Reliance Jio’s Coronavirus Symptom Checker App Exposes User Data

This might be a disturbing news for those who highly rely on smart devices. A group of researchers at the Washington University discovered a new trick to attack smartphones via inaudible voice assistant commands. The researchers demonstrated how they exploited voice assistant features in smartphones to make phone calls, take photos, and read messages without even touching the device.

According to researchers, the unknown vulnerability affects all smartphones that run voice assistant features; iPhones running Siri and Android devices running Google Assistant. Dubbed as “SurfingAttack”, this attack method is a trick to remotely control voice assistants using inaudible ultrasonic waves.

How SurfingAttack Works?

The researchers stated that ultrasonic waves can be used to send commands via air. These waves propagate through solid surfaces to activate voice recognition systems with the help of some equipment.

SurfingAttack method requires three main components: a signal processing module, an ultrasonic transducer, and a tapping device. The target device is placed on a table with a microphone (to hear the assistant’s responses) and a piezoelectric transducer is attached to the bottom of it. SurfingAttack generates signals of voice commands that can propagate in the table to be received by the device’s microphone through a mechanical coupling.

The voice commands are generated using the speech synthesis and text-to-speech (TTS) Module. The controller produces the baseband signals v(t) of the voice commands or dialogues, and then transmits them to the attack device preferably through wireless. The attack device hidden beneath the table is used for ultrasonic signal modulation and voice recording. Without direct control over the voice controllable system, the attacker needs to design inaudible voice commands.

The researchers stated that they’ve performed tests on 17 phones and discovered that the attack method worked on 15 devices from four mobile manufacturers, which include Google (Pixel 1, Pixel 2, Pixel 3), Motorola (G5, Z4), Samsung (Galaxy S7, Galaxy S9), Xiaomi (Mi 5, Mi 8, Mi 8 Lite), and Apple (iPhone 5/5s/6 Plus/X).

Explaining about the SurfingAttack vector, Ning Zhang said, “If you know how to play with the signals, you can manipulate them such that when the phone interprets the incoming sound waves, it will think that you are saying a command. We did it on metal. We did it on glass. We did it on wood. They tried placing the phone in different positions, changing the orientation of the microphone. They placed objects on the table in an attempt to dampen the strength of the waves. It still worked even at distances as far as 30 feet.”

“I feel like not enough attention is being given to the physics of our computing systems. This is going to be one of the keys in understanding attacks that propagate between these two worlds,” Zhang added.

FDA Reveals Potential Vulnerabilities in Certain Medical Devices

Medical device cybersecurity

The U.S. Food and Drug Administration (FDA) has notified patients, health care providers about a set of cybersecurity vulnerabilities mentioned as “SweynTooth.” According to a statement from the FDA, attackers can exploit SweynTooth vulnerabilities to remotely crash devices, stop it from working, or access device functions normally only available to the authorized user. It’s also said that the vulnerabilities may pose risks to a variety of medical devices like pacemakers, glucose monitors, and ultrasound devices.

According to the FDA, SweynTooth affects the wireless communication technology known as Bluetooth Low Energy (BLE), that allows two devices to pair and exchange information to perform their intended functions while preserving battery life and can be found in medical devices as well as other devices such as consumer wearables and IoT devices.

Suzanne Schwartz, deputy director at the FDA’s Center for Devices and Radiological Health, said, “Medical devices are becoming increasingly connected, and connected devices have inherent risks, which make them vulnerable to security breaches. These breaches potentially impact the safety and effectiveness of the device and, if not remedied, may lead to patient harm. The FDA recommends that medical device manufacturers stay alert for cybersecurity vulnerabilities and proactively address them by participating in coordinated disclosure of vulnerabilities as well as providing mitigation strategies. An essential part of the FDA’s strategy is working with manufacturers, health care delivery organizations, security researchers, other government agencies and patients to address cybersecurity concerns that affect medical devices in order to keep patients safe.”

Patient Medical Data Highly Vulnerable to Data Breaches

According to a study from Greenbone Networks, nearly one billion medical images have been exposed online. Greenbone carried out an analysis of over 2,300 medical Picture Archiving and Communication Systems (PACS) servers. PACS servers are governed by a standard called DICOM (Digital Imaging and Communications in Medicine). This standard lays the guideline for medical imaging devices that are networked in order to exchange and archive information about patients and images. DICOM makes use of the IP protocol. PACS servers digitally archive medical images (such as X-ray, CT, MRI scans etc.), which can be shared with or accessed by the attending provider from anywhere across the globe.

Thoma Bravo Acquires Sophos for US$3.9 Billion

Thoma Bravo Acquires Sophos for US$3.9 Billion

Cybersecurity firm Sophos is acquired by Thoma Bravo LLC, a private equity investment firm, in an all-cash deal of US$3.9 billion. Under the terms of the transaction, Sophos stockholders receive US$7.40 per share in cash. As a result of the completion of the acquisition, Sophos common stock was removed from listing on the London Stock Exchange.

Sophos develops security products for communication endpoints, encryption, network security, email security, mobile security, and unified threat management. The company is primarily focused on providing security software solutions to mid-market businesses.Kris Hagerman, CEO, Sophos, said, “Our transition to become a fully next-gen cybersecurity leader continues to rapidly progress. Last quarter, our next-gen product portfolio represented over 60% of our entire business,  and grew 44% year-over-year. And very recently, we launched our most significant network security technology ever, the Sophos XG Firewall with Xstream architecture. With Thoma Bravo as a partner, we believe we can accelerate our progress and get to the future even faster, with dramatic benefits for our customers, our partners and our company as a whole.”

Seth Boro, managing partner at Thoma Bravo, said, “Sophos has been constantly raising the bar with its industry-leading synchronized security, advanced deep learning technology and rapid growth within the MSP channel. We are excited to partner with Sophos to help build upon their success as they further drive innovation in cybersecurity.”

The announcement comes after Sophos partnered with Mapua, a Philippines-based technology university, to offer cybersecurity courses and training to university students. The training alliance comes on the heels of a skills shortage in the cybersecurity sector and frequent data breaches in recent years. The partnership intended to enhance students’ skills and knowledge of cybersecurity. As per the partnership, Sophos will offer train-the-trainer-style education on XG Firewall, which would earn Mapua faculty members the certification to teach the courses and embed these into the university curriculum.

Nigeria Among Top 10 Countries Impacted by Mobile Malware: Kaspersky Lab

Pegasus Spyware, Mobile Security, spyware

In its report titled “Mobile Malware Evolution 2019,” global cybersecurity firm Kaspersky Lab states that Nigeria is among the top 10 countries in the world where users are attacked by mobile malware. The report adds that Nigeria dropped four places to the number seven spot in the list, recording 33.16% attacks of the total share.

Two other African countries made it to the list: Algeria in fourth place (40.2%) and Tanzania in eight place (28.51%). The list was topped by Iran (60.64%) with the highest number of attacks on users. Pakistan and Bangladesh are in second and third place respectively.

The good news, according to Kaspersky Lab, is that there has been an overall decline in the number of mobile threats distributed as installation packages or apps, over three consecutive years.

To quote from the report: “For three consecutive years, we have seen an overall decline in the number of mobile threats distributed as installation packages. The picture largely depends on specific cybercriminal campaigns: some have become less active, others have completely ceased, and new players have yet to gain momentum.

The situation is similar to the number of attacks using mobile threats: whereas in 2018 we observed a total of 116.5 million attacks, in 2019 the figure was down to 80 million.”

Last month, Kaspersky reported that cybercriminals are targeting the popularity of pop stars such as Ariana Grande, Taylor Swift and Post Malone, with over half (55%) of detected malicious files named after them. Another teenage pop music sensation, Billie Elish, has seen a tremendous increase in fan following owing to her notable hits like, Bad guy, Xanny and Everything I wanted. This has led to a subsequent rise in cybercriminals abusing her name and songs to target her followers.

The regions most affected with these malware attacks are the UAE and Nigeria.

Silence Hacking Crew Threatens of a DDoS Attack Against Australian Banks

DDoS Attacks

Australian banking and financial institutions received extortion emails threatening them of possible distributed denial of service (DDoS) attacks against them. To avert this situation the extortioners demanded a ransom that needs to be paid in the form of Monero (XMR) cryptocurrency. The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) is aware of this extortion campaign and issued threat advice to all Australian organizations.

The DDoS Scare for Australian Banks

The Silence Hacking Crew claimed the responsibility of this threat campaign, however, ACSC was not able to confirm these claims until going to print. Silence hackers are one of the most active Advanced Persistent Threat (APT) actors’ group reportedly backed by Russian state-sponsors. The crew is specifically targeting the financial sector due to the huge amount of customer PII data that these institutions possess (which also makes them most vulnerable in case of a cyberattack) and their capability of paying larger ransom amounts.

The ACSC confirmed that although the ransom driven DDoS (better known as RDoS) campaign has been running actively across the country, no instances of successful DDoS attacks have been reported yet. However, it also recommended that being prepared for such type of a cyberattack is the best immediate incidence response strategy before a DoS attack is initiated.

Silence Hackers Target Banks Around the Globe

Earlier in January 2020, researchers from Kaspersky discovered thousands of attack notifications on popular banks in the sub-Saharan Africa (SSA) region. Researchers said that signatures of the Silence hacker group were observed in these attacks. They reportedly deployed a malicious code on the bank’s network to run malicious commands on hosts and allegedly used the access to orchestrate fund withdrawals from the bank’s ATMs.

In another instance, the research firm Group-IB discovered that the same group of hackers breached multiple banks in 25 plus countries worldwide, including Bangladesh, India, Sri Lanka, and Kyrgyzstan. The worst-hit of them was the Dutch Bangla Bank where the attackers apparently scooped out more than US$3 million in an ATM cash-out attack in May 2019.

54% of Organizations Don’t Follow Best Data Security Practices: Report

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

Cybersecurity firm Netwrix announced the release of its report called “2020 Data Risk & Security” that surveyed nearly 1,045 decision-makers in the security field to know about how their organizations treat sensitive and regulated data during each stage of its lifecycle. The study is intended to identify common security gaps in data processing activities.

According to the report, 91% of respondents were certain their sensitive data is stored safely while one in four organizations admitting they had discovered such data outside of designated secure locations last year.

The report also highlighted that 61% of organizations that are subject to the GDPR collect more customer data than the law permits. It’s found that 66% of CIOs don’t have cybersecurity and risk KPIs that are regularly reported to their executives. Nearly 54% of organizations said that they do not follow the security practices like reviewing user access rights to data on a regular basis. It also revealed that 30% of system administrators granted direct access to sensitive and regulated data base only on user requests.

Steve Dickson, CEO, Netwrix, said, Even as cybersecurity budgets grow, data breaches continue to increase in both number and size. Cybersecurity leaders need to find more effective ways to manage data security risks and show return on investment to the executive team. Gaining more visibility into data, internal processes and user activity will enable them to prioritize their efforts, mitigate security and compliance risks more efficiently, and prove the effectiveness of their investments.”

“Unstructured data often accounts for nearly 80% of the data footprint of an organization. The true extent and size of unstructured data are often unknown due to compression, deduplication and the number of copies of data within the organization. Beyond the substantial proportion of dark data prevalent in the average organization, within the unstructured dataset is often found more than 10 copies of the same files just through data protection, backup and recovery, business continuity, testing, and other automated activities,” Dickson added.

Raytheon Partners IronNet for Enhanced Protection for OT/IT Systems

Raytheon Partners IronNet for Enhanced Protection for OT/IT Systems

Military contracting giant Raytheon and cybersecurity startup IronNet Cybersecurity Inc. have partnered to develop cyber solutions for defense of operational and information technology (OT/IT) systems. The new alliance integrates Raytheon’s managed security services with IronNet’s advanced analysis and threat sharing tools to build new solutions for enterprise protection.

Raytheon stated that the combined solutions are intended to be a part of defense offering for critical infrastructure and national security networks. The partnership strengthens OT/IT platforms to increase resiliency for systems that orchestrate sensing, control, networking, and analytics to interact with the physical world, and enable secure performance.

John DeSimone, Vice President of cybersecurity at Raytheon Intelligence, Information and Services, said, “Protecting critical infrastructure is no longer a private sector concern, but a national security imperative. We know malicious actors seek to disrupt global economies through attacks on technology systems that keep our lights on, food supplies safe and militaries prepared. This partnership offers the integration of advanced cyber products and operations experience to the global market.”

GEN (Ret.) Keith Alexander, CEO and Founder of IronNet Cybersecurity, said, “Considering the role Raytheon plays in securing government agencies, global businesses, and even nations, we are excited to work together as we shift the cybersecurity defense paradigm from one that sees organizations defending alone to one that operates as a part of a collective. We can all benefit from working together to increase the visibility we have into incoming threats, sharing that information, and defending more quickly.”

Earlier, Raytheon received US$406 million Indefinite Delivery/Indefinite Quantity contract award from the U.S. Army for ARC-231A radio systems. The ARC-231A is software-defined and can accommodate rapid upgrades without requiring the radio to be removed from its platform. The radios will be installed on a variety of army platforms, including the UH-60 Black Hawk, UH-72 Lakota utility helicopter, and the AH-64 Apache attack helicopter.

Canadians Neglect Personal Data Security: Equifax Reports

Most individuals in Canada think they’re not vulnerable to identity thefts and neglect checking credit reports that help detect fraud, a recent consumer survey conducted by Equifax revealed. The credit reporting agency advised Canadians to remain vigilant against online fraudsters and identity thefts after it found that only 29% of survey respondents checked their credit report last year and only 38% indicated they would report fraud to a credit bureau. Equifax asked individuals to report any fraud alerts on their credit reports to prevent fraudulent activities.

While most (92%) agreed that fraud and identity theft is a serious issue, the new survey data also suggests Canadians are feeling less vulnerable to fraudsters online, on-the-go, at-home and in-store. In the same survey conducted by Equifax in 2017 and 2019, 80 percent of survey respondents said they felt vulnerable to online fraud versus only 72% in 2020.

The survey also highlighted that millennials are at risk of identity theft. According to Equifax, a greater number of millennials don’t know how to address identity theft. The survey cites that they clicked on fraudulent email links, they don’t worry about credit card fraud or believe they won’t be targeted because they don’t have enough money; they don’t check bank or credit card statements, and are less likely to change social media passwords as needed.

Julie Kuzmic, Director of Consumer Advocacy, Equifax Canada, said, “Hackers, fraudsters and identity thieves are always on the hunt to get your personal information. We can’t be complacent about this and one of the best ways to spot identity theft is by checking credit reports for unrecognized activities, which may provide an indication that someone has been applying for credit in your name or fraudulently accessing your accounts. I’m particularly concerned for younger adults who may be misguided in some of their beliefs and actions surrounding identity theft.”

Canadian Legislation Lacks Cybersecurity Awareness

Earlier, a similar survey from Keyfactor, a provider of secure digital identity management solutions, revealed that the Canadian government isn’t doing enough to protect businesses and consumers from data breaches. It found that 87% of surveyed cybersecurity pros think that more privacy and security legislation is required to better protect Canada’s businesses and consumers.

According to the survey, 58% of respondents think regulators and the Canadian officials have not tried to regulate the security guidance on measures like data encryption. The survey also highlighted that 50% of respondents thought of manual and complex processes as their greatest challenge in managing Public Key Infrastructure (PKI), while 43% of respondents were concerned about their ability to securely adopt DevOps, cloud, and IoT.

Cyberthreats: The New Threat Frontier for Singapore Armed Forces

Cyber weapons, cyber threats

The threat landscape for governments is no longer limited to land, air and sea. This is very evident from the policy and budget restructuring that Singapore is doing, keeping in mind the country’s digital boundaries and the cyberthreats associated with it. Singapore’s Defense Minister, Ng Eng Hen, announced the formation of a integrated cyber command and force to defend the country’s digital frontier.

Speaking in the Singapore Parliament on behalf of the Ministry of Defence (MINDEF), Dr. Ng further stated that the responsibility of finding the right personnel with the right aptitude will be overseen by a team led by the Chief of Defence Force (CDF) and Permanent Secretary (Defence Development). The process of complete integration will take time, but it is important to “build an integrated cyber command and force, especially against foreign cyber actors, both state and non-state who seek to undermine our stability and/or pose a threat to national security.” Once the CDF is completely established and functional, it will continue to oversee mission outcomes, while the Chief of Command, Control, Communications, Computers and Intelligence (C4I) will report the daily cyber warnings to the CDF.

The new SAF cyber command will have the responsibility of providing advanced threat intelligence, assessment and issue warnings for potential cyberattack threats. “The universe of cyber threats and activists is large, and the cyber command will have to prioritize its efforts and focus on key threats so as to not dissipate resources,” Dr. Ng added.

Besides cyberthreats, the Defence Minister also said that the country’s maritime capabilities and counter-terrorism intelligence are also being restructured keeping in mind the geopolitical stress in the surrounding region.

Earlier, in order to boost cybersecurity and tackle next-generation cyberthreats, the Singapore government decided to adopt new data protection measures. The government also established a committee, named Public Sector Data Security Review Committee, to review its data security practices.  As per reports, this committee inspected around 336 network systems across 94 government agencies and observed international data security practices in the financial and healthcare sectors.