Home Blog Page 241

CyberMDX Announces Integration With Microsoft Azure for IoT Security

Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial

CyberMDX, a provider of medical cybersecurity solutions announced the completion of integration certification for Microsoft Azure Security Center for IoT. The new cooperation integrates CyberMDX’s visibility and detection capabilities with Microsoft Azure Security Center for IoT to receive intelligent clinical context security analytics.

Founded by Amir Magner in 2016, CyberMDx offers cybersecurity preventive measures for medical devices and other Internet of Medical Things (IoMT). He said, “Today’s world of hyper-aware hospitals requires total visibility, operational insight, and protection for every networked device. We are thrilled to partner with Microsoft Azure Security Center for IoT, joining forces to bring true end-to-end security for healthcare delivery organizations, helping transform medical device and IoT/OT security.”

Michal Braverman-Blumenstyk, CTO and GM, Cloud and AI Security Division at Microsoft Corp, said, “The Microsoft Azure Security Center dashboard provides a single pane of glass for on-prem and cloud assets, delivering comprehensive device context and supporting, further risk management and incident response efforts. We are pleased to welcome CyberMDX to the Azure Security Center for IoT, enabling us to deliver best-in-class visibility and incident response solution for healthcare organizations.”

Medical IoT Devices Vulnerable to Cyberattacks: CyberMDX

Earlier, security researchers from CyberMDX revealed that an anaesthetic machine can be hacked and controlled remotely if left accessible on a hospital computer network. The researchers discovered a security flaw in a number of GE Healthcare devices used by the National Healthcare Services (NHS) hospitals that could allow hackers to manipulate the amount of anaesthetic delivered to patients. CyberMDX stated that the remotely exploitable flaw could enable hackers to silence device alarms, alter the date and time settings, adjust anaesthetic dosages, and switch anaesthetic agents.

U.K. and International Community Blames Russia of Cyberattack on Georgia in 2019

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

The U.K., Georgia, and the U.S. accused the Russian General Staff Main Intelligence Directorate (GRU) of a disruptive cyberattack against Georgia on October 28, 2019, which affected the Georgian population, operations of several thousand Georgian government and privately-run websites, and interrupted the broadcast of two major television stations.

The U.K.’s National Cyber Security Centre (NCSC) stated that the criminal group behind these attacks is known by multiple names including Sandworm team, BlackEnergy Group, Telebots, and VoodooBear. The criminal group is operated by the GRU’s Main Centre of Special Technologies, often referred to as GTsST or with its field post number 74455.

According to Dominic Raab, the Foreign Secretary of U.K., the attacks are part of Russia’s long-running campaign of hostile and threatening activity against Georgia. It’s said that the GRU launched the attacks to undermine Georgia’s sovereignty, create insecurity, and undermine democratic institutions.

Raab also stressed, “The GRU’s reckless and brazen campaign of cyber-attacks against Georgia, a sovereign and independent nation, is totally unacceptable. The Russian government has a clear choice: continue this aggressive pattern of behavior against other countries, or become a responsible partner which respects international law. The UK will continue to expose those who conduct reckless cyber-attacks and work with our allies to counter the GRU’s menacing behavior.”

Michael R. Pompeo, the U.S. Secretary of State, condemned the Russian hacking activities against Georgia. Pompeo stated that U.S. helps in enhancing Georgia’s cybersecurity landscape.

Pompeo said, “The United States calls on Russia to cease this behavior in Georgia and elsewhere.  The stability of cyberspace depends on the responsible behavior of nations.  We, together with the international community, will continue our efforts to uphold an international framework of responsible state behavior in cyberspace. We also pledge our support to Georgia and its people in enhancing their cybersecurity and countering malicious cyber actors.  We will offer additional capacity building and technical assistance to help strengthen Georgia’s public institutions and improve its ability to protect itself from these kinds of activities.”

IIT-Madras Cyberattack Affects its Email Services, Microsoft Offers Help

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

IIT-Madras (IIT-M), India’s premier technical university, faced a cyberattack, which resulted in a takedown of its email services and servers. The type and extent of the cyberattack are not certain but for technical assistance and expertise, IIT-M onboarded Microsoft. The move was made considering that majority of the affected servers and systems on the University campus are run on Windows.

IIT-Madras Cyberattack

On February 17, 2020, the email services of employees and students of IIT-M were disrupted as they were unable to send or receive emails. Soon a server-related dysfunction was found to be the cause. But this dysfunctionality showed traces of a cyberattack targeted towards the Windows-based systems and network of the University. Thus, without wasting much time Microsoft was called upon to join the team of senior officials at IIT-M investigating the incidence for an additional set of expertise.

Fortunately, the University had a risk mitigation plan in place following an increased number of cyberattacks and hacking attempts in the recent past. This meant that a backup for the University’s email system, just prior to the attack, was available with IIT-M’s network administrator. Owing to this, the S-mail services, which is an internal email service for the University’s students, were restored by the evening of February 20, 2020. The faculty’s Outlook email services though were still in the process of restoration.

Educational institutions have seen a steep rise in cyberattacks as it has a larger number of systems (computers) connected on a single or interconnected network(s) and comparatively less security as compared to business and enterprise networks. One such identical incident is the ransomware attack on the Maastricht University in the Netherlands.

Maastricht University Ransomware Attack

The massive ransomware attack that hit the Maastricht University just two days before Christmas 2019 took down almost all Windows systems at the university and particularly affected the University’s email services. In order to contain the damages and complete the ransomware attack analysis, the University itself took down all its systems. The Maastricht University eventually ended up paying the ransom amount of 30 bitcoins amounting to US$220,000 (€200,000) for unlocking the systems and servers compromised during the ransomware attack.

Pcysys’ PenTera to Validate Israel National Research Institute’s Cybersecurity

Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

Proactive Cyber Systems (Pcysys), a provider of Automated Penetration Testing services, announced that the National Research Institute for the Behavioral Sciences and Henrietta Szold Institute chose“PenTera” as its penetration-testing platform, with an aim to continuously test and validate its cybersecurity defenses. Pcysys provides automated penetration-testing platform services to enterprises to help assess and reduce corporate cybersecurity risks. The company claims that its security software solutions identify, analyze, and prioritize remediation of cyber defense vulnerabilities.

What is PenTera?

Pcysys’ PenTera platform allows companies to perform on-demand penetration tests to validate their security controls with the latest hacking techniques and maintain proper cyber posture. The company claims that most security professionals and global service providers use PenTera to perform continuous machine-based penetration tests that protect against cyber risks across their organization networks.

Arie Shimoni, CTO of Henrietta Szold Institute, said, “The need to validate remediation efforts and ensure that patches are properly applied and stay intact is imperative to the cyber posture of an organization. The fact that PenTera continuously exploits each vulnerability enables an ongoing accurate cybersecurity health check of the network–a practice the industry has been longing for.”

Sivan Harel, Regional Sales Director for Northern Europe and Israel at Pcysys, said, “Having the ability to prioritize remediation in a cost-effective manner will allow the Henrietta Szold Institute to easily update policies and grow their cyber resilience. It’s the call of the hour.”

PenTera’s Cybersecurity Validation

Recently, Pcysys announced that Israel’s largest suppliers of electrical power – Israel Electric Corporation and Electra Group have selected PenTera’s platform to automate their cybersecurity validation efforts. Electra Group stated that the PenTera platform scans and ethically penetrates the network with sophisticated technologies, prioritizing remediation efforts with a business impact perspective. It also stated that PenTera platform provides several security tools, including vulnerability assessment, security control validation, credential strength validation, segmentation integrity, sensitive data hygiene, network equipment testing, and privileged access audits.

Hackers Made US$3.5 Billion in 2019 from Cyberattacks

Ransomware gangs

A report from the Internet Crime Complaint Centre (IC3) revealed that hackers secured as much as US$3.5 billion from cybercrime which were reported to the FBI alone in 2019. It’s said that the FBI received 467,361 complaints from individuals and businesses during the year and have had nearly five million since the year 2000.

The report, “2019 Internet Crime Report”, exposed that a total of 1,707,618 complaints with US$10.2 billion losses were reported in the last five years. It stressed that phishing and extortion remain the popular ways used by attackers to scam people while adding that hackers are using sophisticated techniques for their malicious activities, making it harder for security pros to detect. The most financially toiling complaints involved business email compromise, confidence fraud, and spoofing. The losses incurred from cyberattacks amounted to over US$54 million while cybercriminals netted over US$8.9 million from ransomware attacks. The FBI notified said that the complaints came from victims from 48 countries.

IC3 has been focused on providing reliable and convenient reporting mechanism for the public to submit information to the FBI concerning suspected Internet-facilitated criminal activity. The officials at both FBI and IC3 also urged individuals and enterprises to continue reporting crimes.

“We encourage everyone to use IC3 and reach out to their local field office to report malicious activity. Cyber is the ultimate team sport. Working together we hope to create a safer, more secure cyber landscape ensuring confidence as we traverse through a digitally-connected world,”  said assistant director of the FBI’s cyber division Matt Gorham in the report.

Recently, the FBI and the U.S. Department of Justice seized the domain “weleakinfo.com” for selling sensitive information that was hacked from other sources for the past three years. According to the official notice, published by the U.S. Attorney Jessie K. Liu of the District of Columbia and Special Agent in Charge Timothy M. Dunham of the FBI’s Washington Field Office, WeLeakInfo sold access data of more than 12 billion user records that included: names, usernames email addresses, phone numbers, and passwords for online accounts.

CyberArk’s Report Reveals Importance of Robotic Process Automation

median dwell time, Supercharged AI Cyberattacks are Unavoidable

CyberArk, a company involved in privileged account security, shared recommendations from information security executives at Global 1000 enterprises on how to securely drive innovation via Robotic Process Automation (RPA).

The report, “The CISO View: Protecting Privileged Access in Robotic Process Automation”, examines attack techniques and provides practical advice from early RPA adopters on how organizations can mitigate the risks associated with non-human privileged access, including providing robots with more privileges than required to perform functions and tasks.

According to the report, less than half of organizations have a privileged access management strategy in place for digital transformation technologies, like RPA. The report recommends tightening access to RPA tools, mandating secure practices for developing robot scripts, and emphasizes integrating RPA and enterprise security technologies in order to automate the management of credentials and detect misuse.

What is Robotic Process Automation? 

RPA is an enterprise-wide strategy with mandates from executive leadership. In RPA, software applications known as “robots” interact with the user interfaces of business applications. RPA requires less technical expertise than automation methods that use application programming interfaces (APIs). Also, more functions can be automated through a UI than through APIs. With RPA, professional-level software development skills are not necessarily needed to get robots up and running. A business team with little understanding of application security could buy an RPA tool out of their own budget and program a robot without involving the security team. In many organizations, business units are racing to identify tasks that can be automated.

The report also highlighted key recommendations from industry experts on how organizations can securely adopt RPA while mitigating potential risks, which includes:

Limiting access for reprogramming robots – Reduce the risk that comes with RPA permissions – like the ability to reprogram robots – by securely managing credentials to RPA tools and training RPA teams on secure software development practices.

Automating credential management – Successful RPA deployments require automated credential management, including machine-generated passwords, automatic password rotation, identity verifications, and just-in-time or time-limited credential access.

Establishing robust processes for monitoring RPA activity – Rapidly detect and respond to unauthorized or anomalous robot behavior by assigning human managers, enforcing least privilege and making actions traceable.

Ransomware Blocks U.S. Natural Gas Pipeline Supplies

Superior Plus, Saudi Aramco data breach

A ransomware attack on a U.S. natural gas supplying facility brought its operations to a standstill for two days when the organization’s incidence response team implemented a deliberate and controlled shutdown to contain the ransomware spread. In an alert issued by CISA (Cybersecurity and Infrastructure Security Agency), the government agency did not mention the time, date, type/name of the ransomware or the natural gas facility name that was impacted. But it did mention other vital information like the way this ransomware attack was carried out so that in future other organizations can take useful notes in planning their risk mitigation measures.

The Ransomware Attack

  • Initially, the threat actor used a Spear phishing link to obtain access to the organization’s IT network. Unfortunately, there was no network segmentation implemented to segregate the IT network and OT (Operational Technology) network of the gas facility. Thus, the threat actor slowly and successfully began compromising the OT network.
  • Simultaneously, a commodity ransomware was deployed to encrypt data on both these networks. This impacted the organizations’ OT network including its human machine interfaces (HMIs), data historians, and polling servers. The level of its impact was such that it resulted in a partial loss of control to its human controllers.
  • However, the programmable logic controllers (PLCs) used for controlling the supply chain of the gas facility were at no point compromised and thus, a total loss of operational control was averted when a complete shutdown was implemented.

Lessons Learnt

  • The organization did not implement network segmentation between its IT and OT networks. This allowed the threat actors to cross the IT-OT boundary and compromise both networks for a wider impact.
  • The attack was targeted towards Windows-based systems, whereas, PLCs only read the code programmed in their logic unit. Thus, no impact was recorded on PLCs directly reading and performing physical processes at the facility.
  • The gas facility had in place an incidence response for physical threats but never took into consideration a cyberthreat. Thus, they had a replacement equipment and last-known-good configurations backup ready. This at least facilitated a quick recovery process.
  • CISA also cited an absence of Multi-Factor Authentication system for remote access into the OT and IT networks from external sources. It strongly recommends having at least one additional check of authentication in such a critical infrastructure environment.

Nedbank’s Third-Party Data Breach Impacts 1.7 Million Customers in South Africa

data breach

South Africa-based Nedbank faced a customer data breach through a third-party service provider, Computer Facilities (Pty) Ltd. This firm takes care of Nedbank’s SMS and email marketing campaigns. Nedbank’s data breach has potentially affected its 1.7 million customers of which 1.1 million are active accounts.

Nedbank observed the data breach incident while running an internal system audit and monitoring its procedures. It immediately sounded an alert and contacted the service provider about its findings. With the help of the Computer Facilities (Pty) Ltd. team and a group of other cyber forensic experts, a detailed and extensive investigation was carried out to check the gradient of the data breach and the extent of the impact it had on its customers.

For preventive measures, Nedbank secured and destroyed all its customer data under the service provider’s possession. The incident is found to be limited to the third-party service provider’s systems only. Nedbank stated that none of its own systems or client accounts had been impacted. As a secondary precautionary perimeter, systems of Computer Facilities (Pty) Ltd were disconnected from the internet to quarantine the data breach.

Nedbank Group Chief Information Officer Fred Swanepoel said, “The third-party service provider namely, Computer Facilities (Pty) Ltd., did not have any links to our systems. Clients’ bank accounts have not been compromised in any manner whatsoever and clients have not suffered any financial loss.”

Earlier, Western Australia-based P&N Bank faced a data leak that exposed its customers’ personally identifiable information (PII) and sensitive account information. In an official notice, the financial services provider stated that the information breach occurred due to a cyberattack on its customer relationship management (CRM) platform during a server upgrade. However, the incident did not cause any loss of customer funds, customers’ credit card details, or banking passwords. It only exposed customer names, age details, residential addresses, email addresses, phone numbers, customer numbers, account numbers, and account balances.

SentinelOne Raises US$200 Million for Next-Gen Endpoint Protection

Startup funding

Endpoint protection firm SentinelOne announced that it raised US$200 million in Series E funding led by private equity firm Insight Partners along with the participation from Tiger Global Management, Qualcomm Ventures LLC, Vista Public Strategies of Vista Equity Partners, Third Point Ventures, and existing investors.  The California-based company stated the new investment will be used to accelerate the company’s next-gen endpoint, cloud, and IoT protection platforms through its autonomous AI mechanism.

Founded in 2013, SentinelOne provides autonomous endpoint protection services to organizations to help them prevent, detect, respond, and hunt attacks across all major vectors. The company claims that its security platform is designed to save customers time by applying AI to automatically eliminate threats in real-time for both on-premise and cloud environments.

Speaking on the new funding, Tomer Weingarten, CEO and Co-founder of SentinelOne, said, “The cybersecurity demands of today’s enterprises have evolved, and we’ve taken endpoint protection far beyond what it once was. Instead of solely protecting laptops, desktops, and servers with EPP and EDR capabilities, we protect the entire network edge with flexible, autonomous technology–from containerized workloads in the cloud and data center to IoT devices. Leveraging AI to process enormous amounts of data in real-time allows our customers to stay secure from all vectors of attack. Delivering value to customers well beyond the traditional endpoint is what positions SentinelOne as the fastest growing and most promising cybersecurity platform.”

SentinelOne Partnerships

Last month, SentinelOne partnered with CRITICALSTART, a provider of managed detection and response (MDR) services, to jointly develop next-generation endpoint, cloud, and IoT protection security solutions. CRITICALSTART helps enterprises protect their data systems while reducing their security risks. The company offers a set of security solutions from the delivery of managed security services to security-readiness assessments like the defendable network, professional services, and product fulfillment.

In 2019, SentinelOne secured US$120 million investment in its Series D funding round which was also led by Insight Partners. The other investors that participated in the funding round included Samsung Venture Investment Corporation, NextEquity, Third Point Ventures, Redpoint Ventures, Granite Hill, and Data Collective (DCVC).

Nearly 70 Percent of Organizations Globally Suffered IoT Attacks: Survey

IoT Connections to Reach 83 Billion by 2024: Report, CISA alerts critical infrastructure, CISA – FBI holiday season alert

A recent survey from security firm, Extreme Networks, revealed that organizations remain highly vulnerable to IoT-based attacks. The research, which surveyed 540 security professionals across organizations in North America, Europe, and Asia Pacific, found that 84% of organizations have IoT devices on their corporate networks. It also stated that more than 50% of the organizations don’t maintain necessary security measures beyond default passwords.

The other key research findings include:

  • Nine out of 10 security professionals are not confident about their network security
  • Nearly 55% of security leaders believe that the main risk of breaches is mostly from outside the organization
  • 83% of organizations in EMEA (Europe, the Middle East, and Africa) are deploying IoT compared to 85% in North America
  • The main reason for unsuccessful Network Access Control (NAC) implementations are due to lack of qualified personnel (37%), huge maintenance cost (29%), and implementation complexity (19%)
  • Almost 72% of security personnel want network access to be controlled from the cloud

Potential Attacks from Shadow IoT Devices

A research from cloud-managed network services provider Infoblox stressed that enterprise networks pose potential cyberthreats by shadow IoT devices. The research report, “What’s Lurking in the Shadows 2020” surveyed 2,650 security professionals across the U.S., U.K., Germany, Spain, the Netherlands, and UAE to know the role of shadow IoT devices in enterprise networks.

According to research findings, 80 percent of IT professionals discovered shadow IoT devices connected to their company’s network. Nine in ten security leaders (89%) were worried about shadow IoT devices connected to remote or branch locations of their businesses. The research also revealed that 78% of global organizations found more than 1,000 personal devices like laptops, smartwatches, and mobile phones connected to their corporate network.