Home Blog Page 246

83 percent of Cybersecurity Personnel Feel Overworked: Tripwire Survey

active directory
active directory

Cybersecurity firm Tripwire recently announced the results of its survey that examined how organizations and security pros are experiencing skills gap issues. The survey findings, based on the responses from 342 security professionals, revealed that 83 percent of respondents feel more overworked going into 2020 than they were in 2019. It’s said that 82 percent of security pros felt that their teams were understaffed.

According to the research, 85 percent of them acknowledged that it became more difficult over the past few years to hire skilled cybersecurity professionals. It’s said that only 19 percent of cybersecurity companies provide resources for managing the stress associated with the specific issues of security.  

Other Major Findings

  • Most companies (85 percent) believe managed services are a good option for addressing security skills gaps
  • Around 46 percent stated that they plan to use more managed services in 2020
  • Over 50 percent of respondents said they will invest more in cybersecurity training for its staff
  • The survey also highlighted that 40 percent of security pros believe their CISOs are not involved enough in day-to-day operations

Tim Erlin, the Vice President of product management and strategy at Tripwire, said, “It’s getting harder and harder for organizations to fill open positions on their security teams. Larger organizations, which you might assume have more resources, are experiencing the skills gap issue even more acutely than smaller organizations. It’s a challenge to hire the right skill sets – they keep changing along with security, which is always evolving. Nearly all of those we surveyed said the skills required to be a great security professional have changed over the past few years.”

“CISOs should be focusing on high-level strategy, but because their teams are understaffed and have an overwhelming volume of work on their desks, they may have to get involved in daily operations, if they haven’t already. To solve the problems caused by skills gap issues, training and managed services are both good approaches. By partnering with providers, organizations can free themselves from operational work and gain insights that will help inform decisions. And because recruiting and training isn’t always possible, managed services provide businesses a way to augment their teams,” Erlin added.

OurMine Group Hacks Facebook’s Official Twitter and Instagram Accounts

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

The social media accounts of social networking and technology giant Facebook were temporarily compromised by a hacking group named OurMine. The incident came to light after the hacking group posted on Facebook’s official Twitter and Instagram accounts, However,  it restored the social media accounts immediately after the news exposed it.

“Some of our corporate social accounts were briefly hacked but we have secured and restored access,” Facebook said in a media statement.

OurMine hacking group claimed that they attacked Facebook to expose potential vulnerabilities in the system. The group posted a statement on Facebook’s official Twitter account stating, “Hi, we are OurMine. Well, even Facebook is hackable but at least their security is better than Twitter.”

Twitter confirmed that the intrusion occurred through a third-party. The microblogging site stated, “As soon as we were made aware of the issue, we locked the compromised accounts and are working closely with our partners at Facebook to restore them.”

OurMine’s High-Profile Targets

Based out in Dubai, OurMine is an infamous cybercriminal group that attacked multiple social media accounts of high-profile individuals and enterprises in the past.

Recently, OurMine hacked 15 Twitter accounts of the U.S. National Football League (NFL) teams including NFL’s handle and posted a message, “Hi, we’re back. We are here to show people that everything is hackable.”

The details of the account hijacking remained unclear, however, most of the tweets posted by the OurMine operators on the hijacked accounts came from Khoros. It is a web-based third-party application used by the organization’s digital marketing and public relations departments to manage their social media accounts and gain useful insights into public engagements across different platforms.

In 2017, OurMine operators hacked Twitter handles of Futbol Club Barcelona and Real Madrid Club de Futbol. The hackers sent out tweets from Real Madrid Club de Futbol’s Twitter account in English and Spanish, which announced the joining of major rival player Lionel Messi. They also posted video footage from an earlier match, which showed Messi scoring for Barcelona against Real Madrid. The tweets were visible for almost 90 minutes on the football club’s handle but were later removed. The welcoming post of Messi had grabbed the attention of the fans by then, as the tweet received almost 2,800 likes and 3,100 retweets.

Attacks on Web Applications Surged in 2019: Report

A research study from cybersecurity firm SonicWall revealed that cyberattacks on web applications increased by 52 percent in 2019. The research report, SonicWall Cyber Threat Report”, stated that attackers targeted web applications to obtain financial and personal information from victims’ devices.

Most Targeted Web Applications

According to the research, attackers mostly targeted popular web applications like SharePoint, Atlassian Confluence, Drupal Oracle WebLogic, Microsoft Windows GDI, Slack, G Suite, and Dropbox, which offer cloud-first interfaces and web versions to complement on-premise software.

Other Major Findings

The research also highlighted statistics on different attack vectors like ransomware, cryptojacking, and other cyberattacks. It revealed that 9.9 billion malware attacks were reported during 2019, from which 187.9 million were detected as ransomware attacks. Encrypted threats increased by 27 percent whereas cryptojacking attacks had fallen by 78 percent, the research stated.

SonicWall President and CEO Bill Conner said, “In a modern, citizen-centric environment, successful ransomware attacks are highly disruptive. Networks from city hall, law enforcement agencies, sanitation, courthouses or the DMV could be compromised in minutes and everyday operations held for ransom, often at exorbitant costs. Once these attacks are weaponized by mainstream criminal groups, we will see critical damage across infrastructure, servers, security appliances, data repositories, mobile devices and a wide range of endpoints.”

SonicWalls’s RTDMI Technology

In an earlier research, SonicWall’s Real-Time Deep Memory Inspection (RTDMI) identified over 74,000 never-before-seen attacks, a number that already surpassed in the first quarter of 2019 with more than 173,000 new variants detected. The company’s patent-pending RTDMI technology identified over 83,000 unique, never-before-seen malicious events, of which over 67,000 were PDFs linked to scammers and more than 5,500 were PDFs with direct links to other malware. SonicWall stated that this fraud campaign took advantage of recipients’ trust in PDF files as a safe file format that is widely used and relied upon for business operations.

Cyberattacks Concern Small and Medium-Sized Businesses in the U.K.

cyberattacks on U.K. organizations

The small and medium-sized businesses (SMBs) in the U.K. revealed that potential cyberattacks and malware infections trigger severe concern than staffing or cash flow issues. According to a research report, “Securing Growth:  How cyber risks among smaller U.K. companies change with size and time”, from cybersecurity firm Sophos, SMBs in the U.K. are being targeted by determined threat actors or have their network systems infected by malware. It’s said that the organizations don’t have enough resources or expertise to maintain a standard cybersecurity posture, which represents poor cyber-readiness.

Cyberattacks are Major Concern

The research stated that almost half (45 percent) of the organizations surveyed consider that malware infections and cyberattacks are a major business concern, compared to data breaches (42 percent), staffing issues (40 percent), or cash flow issues (32 percent). It also revealed that 31 percent of active companies don’t know which cloud services they use. The research findings are based on responses from over 400 business and technology decision-makers across the U.K.

A statement from the research report states, “The findings challenge a few widely held assumptions: that smaller businesses aren’t as concerned about cyberthreats as perhaps they should be, or that an organization’s cyber risk profile can be broadly defined by its number of employees. In fact, our research suggests that the biggest risk differentiator is years of operation, and that smaller firms do worry about cyberthreats – it’s just that this doesn’t always translate into secure behavior.”

Security Incidents on U.K.’s Mid-Market Businesses

A similar research from business and financial adviser Grant Thornton revealed that the mid-market businesses in the U.K. have lost around £30 billion (approximately US$37 billion) in 2019 due to security breaches. The research, “Cybersecurity–the Board Report”, stated that businesses were not prepared to manage cyber risks.

Grant Thornton surveyed over 500 U.K. mid-market companies, in which half of them reported losses of up to 10 percent of their income over cyberattacks. The research also revealed that 63 percent of the companies don’t have a cybersecurity team. Only 36 percent stated that they’ve provided cybersecurity training to their employees and more than half of the businesses (59 percent) don’t have a cyber incident action plan.

Investment in Cybersecurity Training Benefits Telkom SA

RAT, Trojan, Remote Access Trojan

Telkom SA, a leading telecommunications service provider in South Africa, is placed in the Category 4 of the Cyber Exposure Index (CEI) with an exposure score of 269.61 (for January 2020). Owing to the high risk of cyber exposure, it decided to invest in employee cybersecurity awareness and training and immediately reaped big returns.

For a very long time, Telkom languished at the bottom of the list when it came to cybersecurity and inversely topped the list of companies with the most exposure to cyberthreats. Owing to the high-risk concerns and the subsequent business impact, the top brass of Telkom decided to analyze and fix this recurring issue. In its analysis, the company found that the lack of basic cybersecurity knowledge and training to its employees was the weak link for in its organization’s cybersecurity approach.

In an interview with Intelligent CIO, Eseu Choma, Senior Manager, Information Security Assurance of Telkom SA said, “We protect our entire network, invest in intelligent systems and solutions, but our employees are always vulnerable targets to cybercriminals. If not trained, they are most likely to live a careless life online.”

Telkom’s Three-point Cybersecurity Training and Approach

Telkom’s three-point cybersecurity training and approach consisted of – the learning platform, the assessment simulator (phishing simulator), and the phish alert button.

  1. Learning Platform: Its content was developed keeping the South African audience in mind. It only included important and relevant information. The training was designed to be short, smart and targeted so that employees could complete the training sessions within 10 minutes. The effectiveness of this learning platform can be gauged from the fact that almost 5,000 employees gave it an aggregated rating of 4.7 out of 5.
  2. Assessment Simulator: Telkom conducted a “Spot the Phish” game that consisted of a phishing simulator. This helped in employee assessment based on the training imparted to them on malicious emails. It was a brief 15 to 20-minute gamified tutorial that managed to achieve an average rating of 4.8 out of 5, with 95 percent positive feedback and employee engagement.
  3. Phish Alert button: In the final phase, Telkom added a “Phish Alert” button, which to date has seen around 8,000 phishing and malicious emails being reported.

The training has seen a huge shift in the cybersecurity awareness of Telkom’s employees, and overall 12,000 employees have already successfully completed the cybersecurity training that is divided into four modules.

Following Mitsubishi, Pasco and Kobe Steel Disclose Data Breaches

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

Japanese companies, Pasco Corp. and Kobe Steel, rendering services to the Japanese armed forces, disclosed a possible data breach that took place in May 2018 and June 2015, followed by a second attempt in August 2016, respectively.

Pasco Corp. is an aerial image surveillance provider and has tie-ups with the Japanese Ministry of Defense for delivering latest satellite images to monitor the work and progress at various defense bases and other locations. As far as Kobe Steel is concerned, it manufactures underwater launch tubes for Japanese submarines and provides critical submarine spare-parts for the Japan Self-Defense Forces (SDF). Therefore, an attempt of intrusion or data breach by threat actors in both cases is thought to be targeted directly at acquiring defense secrets of the country.

Was Data Breached or Not?

Both, Pasco and Kobe Steel’s official statements said that no damage has been done in either of the data breach attempts as no information leakage had been discovered so far during the joint investigations carried out by the Ministry of Defense and various government and state authorities. However, a report from Nikkei stated that 250 files containing information related to the Ministry of Defense and personally identifiable information (PII) of certain stakeholders were compromised during one of the cyberattacks.

Defense Minister Taro Kono revealed these cyberattacks on defense-related companies in a press conference held on January 31, 2020.. He said, “No secret has been leaked by the Ministry of Defense. I think it (data breach) should be publicly disclosed. It is necessary to get the world to know and think about (cyber) defenses.”

The NEC and Mitsubishi Data Breaches

The other two companies that reported of possible data breaches targeting Japan’s defense secrets were NEC and Mitsubishi. On January 31, 2020, NEC, in a brief statement, accepted the data breach and stated that its network was penetrated and compromised to a cyberattack that was launched in December 2016. The attack was spotted in June 2017, following which all unauthorized communications detected were blocked by the IT teams. The encrypted communication information between the compromised server and the external exfiltration server was finally decrypted in July 2018 and it was found that the defense business division’s 27,445 files were accessed illegally.

Cyberattack on Mitsubishi

A week earlier in January 2020, a Japanese electronics manufacturer, Mitsubishi Electric confirmed that it was hit by a cyberattack in June 2019. The Tokyo-based firm released a notice detailing the data leak in the wake of two news stories published recently by Asahi Shimbun and Nikkei.

According to the internal investigation, which began in September 2019, the security incident compromised the information of Mitsubishi’s public and private business partners, defense-related details, and data on critical social infrastructure like electricity and railways. It’s believed that intruders managed to access computers, servers, and company sites, including details on the company’s joint projects, negotiations, research documents, and data of government organizations like the Ministry of Defense, the Nuclear Regulation Authority, and the Agency for Natural Resources and Energy.

FBI Warns of DDoS Attacks on State-Level Voter Websites

FBI, FatPipe MPVPN zero-day

The FBI recently discovered a potential Distributed Denial of Service (DDoS) attack that targeted state-level voter registration and information site, according to the federal body’s Private Industry Notification (PIN) obtained by Bleeping Computer.

It’s said that the voter registration and voter information websites received anomalous Domain Name System (DNS) server requests with a Pseudo-Random Subdomain (PRSD) attack. The PIN stated that the requests occurred for one month in intervals of approximately two hours with request frequency of around 200,000 DNS requests during the period of the attack.

“PRSD attacks are a type of DDoS attack used by threat actors to disrupt DNS record lookups by flooding a DNS server with large amounts of DNS queries against non-existing subdomains,” the FBI explained.

Apart from disclosing potential targets, the FBI also provided precautionary measures to mitigate DDoS attacks which include:

  • Implementing an incident response plan, including a DDoS mitigation strategy, and practicing the plan prior to an actual incident
  • If the incident response plan involves external organizations, ensure the appropriate contacts with the external organizations are established prior to an incident
  • Enabling automated patches for operating systems, web browsers, and software
  • Maintaining a timeline of attacks while recording all relevant details

“The DDoS attack market is changing. New DDoS services appear to have replaced ones shut down by law enforcement agencies. As organizations implement basic countermeasures, attackers target them with long-lasting attacks. It is difficult to say if the number of attacks will continue to grow, but their complexity is showing no signs of slowing down. We recommend that organizations prepare themselves effectively, in order to withstand sophisticated DDoS attacks,” suggested an earlier report.

Google Plans to Floor Insecure Downloads in Chrome 83

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

In April 2019, with a view to prevent abuse, Google engineers showed the desire to block certain HTTP file downloads that load via an HTTPS URL. The proposal has finally materialized and shall soon be rolled-out in six phases, starting with Google Chrome 83.

Google’s Original Plan

As per Google, certain file types are considered “high-risk”, since they are most likely to be abused for hiding malware(s). To mitigate this issue, Google engineers suggested to block insecure downloads on sites that appear to be secure (loaded via secure HTTPS), but where the downloads take place via insecure HTTP. These “high-risk” file formats included EXE (Windows application binary), DMG (Mac application binary), CRX (Chrome extension package), and all the major archive formats, like ZIP, GZIP, BZIP, TAR, RAR, and 7Z, which Google proposed to block.

Chrome’s Six-Phase Roll-Out

Chrome does not plan to give a jolt to its users by immediately blocking the file download via HTTP. Instead, it has planned to do it gradually in the following six phases:

  • Phase 1 – Crome 81 (March 2020 release) and later:

Chrome will display a warning message about all mixed content downloads.

  • Phase 2 –Chrome 82 (April 2020 release):

Chrome will display a warning on mixed content downloads of executables (e.g. .exe).

  • Phase 3 – Chrome 83 (June 2020 release):

Chrome will block mixed content executables and display a warning on download of mixed content archives (.zip) and disk images (.iso).

  • Phase 4 – Chrome 84 (August 2020 release):

Chrome will block mixed content executables, archives and disk images. In this version, Chrome will display a warning on all other mixed content downloads except image, audio, video and text formats.

  • Phase 5 –Chrome 85 (released September 2020):

Chrome will continue displaying a warning on mixed content downloads of images, audio, video, and text and will block all other (mixed content) downloads.

  • Phase 6 – Chrome 86 (October 2020 release) and beyond:

Chrome will block all mixed content downloads.

Google also studied the implications these changes might have on its enterprise and education customers, and thus gave an option to the webmasters for disabling the blocking on a per-site basis via the existing Google policy, InsecureContentAllowedForUrls. It can be done by adding a pattern matching the page requesting the download.

Developers/webmasters can also test the warning message functionality for mixed content download in the current version of Chrome Canary, or in Chrome 81 once released. To do so, they simply need to activate the mixed content flag at, chrome://flags/#treat-unsafe-downloads-as-active-content.

Pentagon Rolls Out New Cybersecurity Standards for Defense Industry

The U.S. Department of Defense (DoD) recently published a new set of cybersecurity standards, known as the Cybersecurity Maturity Model Certification (CMMC) version 1.0. The new standards will require defense companies to adhere to a set of rules and mandates if they want to do business with the Pentagon procurement programs. According to DoD, any company that does business with the Pentagon will have to get some level of certification and their defense acquisition workforce will need to be trained on how to apply the model to their contracts.

CMCC’s Cybersecurity Levels

CMMC specifies five different cybersecurity levels ranging from basic cyber hygiene requirements to detailed lists of security controls. Level one will be the least rigorous and focuses on basic cyber hygiene. Second and third levels focus on intermediate cyber hygiene. Finally, the fourth and fifth will apply to technology companies that are working on critical programs.

CMMC is also intended to prepare the defense sector to protect its networks and unclassified information against cyberattacks by foreign adversaries.

Ellen Lord, the Under Secretary of Defense for acquisition and sustainment, said, “Obviously this is a complicated rollout for industry, and we’re being realistic in terms of making sure we have pathfinder projects that we’ll implement, and then learn, get the feedback and go on. This is a critical cornerstone of the department’s overall cybersecurity effort, and we believe we are doing this with what I would call irreversible momentum. We want to make sure that this works and that it is sustained.”

Lord also highlighted, “Adversaries know that in today’s great power competition environment, information and technology are both key cornerstones [of national security] and attacking a sub-tier supplier is far more appealing than a prime.”

Earlier, Lord released a “Do Not Buy” list of software from vendors whose code originates from Russia and China. He informed that the list was intended to assist the DoD acquisitions staff and partners to avoid buying problematic codes from unreliable sources.

Darktrace Partners with McLaren to Defend the Latter Against Cyberattacks

McLaren

This might be a piece of great news for purists and enthusiasts of both worlds—cybersecurity and automotive. British automaker McLaren, credited with gifting the world the likes of F1, P1 and the Senna, signed a multi-year partnership with AI cybersecurity firm Darktrace.

With the partnership, Darktrace will be the official AI cybersecurity partner for McLaren beginning from the 2020 Formula One season.  The cybersecurity firm will be tasked with technical integration of its cyber artificial intelligence across the McLaren Group as well as McLaren Racing division, where Darktrace will protect the McLaren racing team against cyberattacks. For the race enthusiasts, Darktrace brand will appear on the rear wing of the McLaren MCL35 race car, as well as the race suits of drivers Carlos Sainz and Lando Norris.

“Data is the lifeblood of our racing strategy and so strong cyber resilience is key to our success on the tracks,” Zak Brown, Chief Executive Officer of McLaren Racing, said in a release. “We look forward to starting our partnership together this season as Darktrace’s Cyber AI will, for the first time, allow our infrastructure to be self-defending.”

From a technological standpoint, the Darktrace’s AI will be leveraged to gain complete visibility across the digital infrastructure of McLaren F1 cars, starting with its IoT sensors to the cloud-based software, where threats would be identified and mitigated by AI. Darktrace has been very keen on assuring that its AI technology can prevent cyberattacks at a “speed and scale beyond human capabilities”.

Poppy Gustafsson, Chief Executive Officer of Darktrace, said, “Cyber-attacks that seek to cause disruption to global events, as well as attacks that subtly steal coveted IP, are on the rise. We are proud that our technology is being trusted to automatically protect the McLaren team, enabling them to race to the finish line in the knowledge that their systems are secured by world-leading Cyber AI.”

With cars becoming more and more technologically advanced, cyberattacks on events like the Formula One races may result in massive catastrophes. A partnership like Darktrace-McLaren’s is literally the need of the hour.

Cyberattacks on Federal Bodies

Sports tournaments have of late been at the epicenter of cyberattacks. Nearly eight million people visited Russia for the 2018 World Cup, and much ahead of the inauguration of the tournament, the event witnessed a slew of cyberattacks targeted at the federal bodiesfans, and even soldiers sitting and watching the game from another part of the globe.