Home Blog Page 250

Philippines Most Vulnerable to Cyberthreats, Two Years in a Row

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

The Philippines, for the second time in a row, has been crowned number one in South-East Asia (SEA) and ranked seventh globally, in terms of the most attacked country by cyberthreats.

An independent research by cybersecurity firm Kaspersky stated that Philippines registered a total of 3,906,410 cyberthreats in computers of Kaspersky users during Q4 of 2019, which is equivalent to 31.6% of the overall. Philippines closely follows Nepal (37.7%), Algeria (37.4%), Albania (37.3%), Belarus (35.0%), Moldova (33.4%), and Tunisia (33.4%). The data that was collected over a time frame of November 2018 to October 2019, included 203 countries from across the geography.

When it comes to cyberthreat detection, Philippines is placed at 64th position globally, with only 8,998,044 detections in the Q4 of 2019, which is a significant drop from its 74th rank in Q4 of 2018 with 11,757,863 detections. The negatives seemed to outnumber the positives, however, the report also highlighted that fewer local threat incidents (76,900 incidents) were recorded in the last quarter of 2019, as compared to the same period in 2018 (453,788 incidents).

Philippines also ranked third in the list of most Android mobile malware attacked country in SEA region during the first three quarters of 2019. A total of 134,556 Android malware attacks were recorded, which accounted for 12 percent of total attacks in SEA. Kaspersky data indicated that Android Filipino mobile users are being targeted with the Hiddapp mobile malware, which secretly downloads ads on an infected device and also displays them in the maximum number possible to the device user.

Earlier, a mysterious mobile malware, named Xhelper, infected over 45,000 Android mobiles that hid itself, downloaded other threats, displayed ads on the infected devices, and reinstalled itself even after users deleted it from their devices. This malicious app mainly targeted mobile users in India, the U.S., and Russia.

Japan Designs Emergency Proposal on Cybersecurity Ahead of the 2020 Olympic Games

Tokyo Olympics 2020

Japan is gearing up for the Tokyo 2020 Olympic and Paralympic Games this summer,  however, the website for Olympics and Paralympic Games might be vulnerable to cyberthreats, such as ransomware, fake entry passes, and leaks of personal information.  Owing to the high volume of tourists and possible threat analysis conducted by the governing authorities, Japan’s Communication Ministry has tabled a set of an emergency proposal that includes guidelines to mitigate risks and incidence response for cyberattacks.

The Communication Ministry panel identified certain devices and technologies including IoT (Internet of Things) devices that are vulnerable to cyberattacks. The emergency package says that, “it is desirable to consider publishing information on cyberattacks swiftly at the point in which leaks of personal information are suspected,” calling for information-sharing with relevant organizations.

Modern digital cameras with sensors and professional automated cameras and video recorders are remotely controlled over a networking system. These networks are soft targets for hackers as they are often handled by camera technicians who may be unaware about advanced cybersecurity concepts. More often, users forget to change their default device password or initial settings. Thus, the panel proposed that checkpoints are set up and thorough checks be conducted on gadgets and devices that are susceptible to cyberattacks, urging users to make changes if problems are found.

The panel has also recommended cybersecurity training to local government municipalities as nearly half of its staff is unaware of basic cyberattack precautionary and response measures.

Japan has been on its heels with respect to cybersecurity since 2018, when the Japanese government introduced a new cybersecurity strategy in a meeting held at the government’s Cyber Security Strategy Headquarters. As a part of the strategy, the government created a new body to ensure effective coordination among government agencies, the Olympic organizing committee, municipalities, and business operators, to respond to cyberthreats. The government also introduced a five-level scale to classify the severity of cyberattacks that included: Level 0 (lowest) indicating “No Impact” while Level 4 (highest) indicating “Extremely Grave Impact.”

Earlier in December 2019, the authorities of the Tokyo 2020 Olympic Games issued a warning about an ongoing phishing campaign. It’s said that the suspicious emails are designed to look like they’re coming from the Tokyo Organizing Committee of the Olympic and Paralympic Games 2020.

“We have recently detected emails disguised to look like they are coming from a Tokyo 2020 staff member. Although the email may look official and legitimate, if you have no reason to receive such an email or if the content is questionable, you should not click on the link or open any attached files. It is highly likely that you would be directed to a phishing site or your computer would be exposed to a virus,” the authorities said in an official statement.

Magecart Hacking Group Arrested in Indonesia

New Programming Language

Indonesian Police and Interpol recently arrested three men who belong to Magecart hacking group for involvement in Magecart attacks. The police officials stated that it’s the first arrest of Magecart gang members.

The suspects, identified by initials ANF (27 years), K (35 years), and N (23 years), were accused of injecting JavaScript sniffers into websites to capture information entered by the site visitors. It’s said that the suspects allegedly used the stolen payment card data to purchase electronic and luxury goods.

“The three of them have carried out their actions since 2017 until now, and each has similar hacking abilities. The arrest of the hacking suspects began with the collaboration of Subdit II Dittipidsiber Bareskrim Police, Interpol, ASEAN Desk and IB-Group in the Night Fury Operation activities, which are joint operations with several communities both nationally and internationally in order to combat Malware used by hackers,” the officials said in a media statement. 

Macy’s Magecart Attack

In October 2019, Macy’s, an American department store chain, stated that its customers have been hit by an attack that affected countless numbers of credit cards. The retailer stated that unknown intruders planted a card-stealing malware script on its payment site and collected customer details.

According to an official statement, the attackers installed a Magecart script on the checkout page of its website and siphoned off customers’ payment card details between October 7 and October 15,  this year.

The compromised data included customers’ names, addresses, phone numbers, credit card numbers, card verification codes, and expiration dates.

What is Magecart Attack?

Magecart attack, also known as web skimming or e-skimming, is a form of cybercrime where attackers plant malicious JavaScript code on online stores.

In a Magecart attack, hackers gain access to a company’s online store website by compromising and hiding malicious code in it. The malicious code then collects the payment card information from users while making purchases on the infected site. It’s said that hackers either sell the stolen card data on the darknet or uses it to make fraudulent purchases.

JhoneRAT Malware Attacks Middle East Countries

RAT, Trojan, Remote Access Trojan

Security researchers from Cisco Talos recently discovered a new version of remote access trojan (RAT), which attacks a victim’s device via malicious Microsoft Office documents. The RAT malware, tracked as “JhoneRAT”, was developed using Python and targeted a set of Middle East countries by checking keyboard layouts of the infected devices.

The researchers identified three malicious MS Office documents that were used to infect the device.  The first document “Urgent.docx”, discovered in November 2019, asks the victim to enable English and Arabic-language editing.  The second document named “fb.docx”, discovered in January 2020, claims to contain data on leaked Facebook accounts from 2019. The third document, found at the end of January 2020, contains blurred content and is alleged to be from a legitimate United Arab Emirates organization. 

How JhoneRAT Works

Attackers trick the victims to click and download a malicious document from the internet. The malware then gets divided into multiple layers and each layer downloads a new malware payload. Once JhoneRAT is deployed, it gathers information from the victim’s cloud services like Google Drive, Twitter, ImgBB, and Google Forms.

Countries Attacked

According to the researchers, JhoneRAT targeted UAE, Saudi Arabia, Iraq, Libya, Algeria, Egypt, Morocco, Tunisia, Oman, Yemen, Syria, Kuwait, Bahrain, and Lebanon.

How to Prevent JhoneRAT

Hackers try to lure their victims into opening malicious documents by labeling it as “Urgent.docx” or “fb.docx” or other strange image files. It’s advised to avoid clicking such file extensions from unknown sources.

“The fact that this attacker decided to leverage cloud services and four different services—and not their own infrastructure—is smart from an opsec point of view. It is hard for the targets to identify legitimate and malicious traffic to cloud provider infrastructure. Moreover, this kind of infrastructure uses HTTPS and the flow is encrypted that makes man-in-the-middle interception more complicated for the defender. It is not the first time an attacker used only cloud providers,” the researchers said.

Singapore Blocks Malaysian Website Under Falsehoods Law

network and ransomware attacks in Singapore, Singapore Ranks Most Prepared in Cybersecurity Readiness: Deloitte

The Singapore government issued directives to local ISPs for blocking a Malaysian website, Lawyers for Liberty (LFL). These measures were taken because Lawyers for Liberty failed to comply to the correction directives issued by the Singapore government under the Protection from Online Falsehoods and Manipulation Act (POFMA) guidelines.

What is POFMA?

POFMA was passed in the Parliament on May 9, 2019, and came into effect from October 2, 2019. In the lead up to this act, public consultations were being conducted including eight days of Select Committee hearing.

Under POFMA, which is aimed at protecting society from fake news that harms the public interest, a falsehood is defined as, “A statement of fact that is false or misleading.” It doesn’t cover opinions or criticisms. Falsehoods that may harm a person, organization or group’s public interest, may have to be updated with a correction. The real facts should be placed alongside the falsehoods so that people can always check the truth for themselves. In certain serious cases though, the post may have to be taken down.  

What is Lawyers for Liberty Case?

On January 16, 2020, Lawyers for Liberty published a post which the Ministry of Home Affairs for Singapore found factually untrue and spreading online falsehood directed towards them. The ministry further requested the POFMA office for issuance of correction directives to LFL as per the guidelines laid in the Falsehoods law. LFL, however, did not pay heed to this notice. It failed to comply with the directive, which prompted the Singapore government to order its industry regulator Infocomm Media Development Authority (IMDA) to issue the access blocking orders. These blocking orders given to all local ISPs will be lifted only when LFL complies with the original correction directives.

Lawyers for Liberty, on the other hand, has filed a motion in the Kuala Lumpur High Court in Malaysia against Singapore’s Home Affairs Minister, K Shanmugam, stating that POFMA cannot be constitutionally imposed on Malaysians. LFL adviser N Surendran said, “The reason for the lawsuit is because this is an attempt by Singapore to encroach upon or crackdown on freedom of speech in Malaysia.”

Ryuk Ransomware Strikes Again, Affects Tampa Bay Times

Ransomware, supply chain and ransomware

The Tampa Bay Times is the latest victim of a ransomware attack. The popular U.S.-based news organization reported that attackers infiltrated its computer systems with Ryuk ransomware. The exact number of devices affected in the incident is unknown. However, the company clarified that the attack didn’t compromise any of its or its customers’ information.

According to a report from Malwarebytes Labs, the Tampa Bay Times did not respond to the attackers and refused to pay any ransom. The company stated that it is in the process of removing the ransomware and restoring its affected systems via backup files.

Ransomware Attacks on News Agencies

Ryuk ransomware affected several newspapers/news agencies in the U.S.last year. In Los Angeles, San Diego Union-Tribune, The Wall Street Journal, Los Angeles Times, The New York Times (West Coast Editions), and several Tribune Publishing newspapers faced printing and delivery issues after they suffered a ransomware attack.

The Chicago Tribune reported that its publishing and printing systems were affected in the attack. The publisher stated that its print edition was published without paid classified ads and death notices, due to the attack. However, the company clarified that no customer and financial information was leaked.

Tribune Publishing spokeswoman, Marisa Kollias, said, “This issue has affected the timeliness and, in some cases, the completeness of our printed newspapers. Our websites and mobile applications, however, have not been impacted. There is no evidence that customer credit card information or personally identifiable information has been compromised.”

Ryuk in the News

In a related development, the officials of the U.S. Coast Guard (USCG) recently disclosed a Ryuk ransomware infection that had taken down the entire corporate IT network of a Maritime Transportation Security Act (MTSA) regulated facility for more than 30 hours. According to the USCG officials, the ransomware interrupted the camera and physical access control systems. It’s believed that a malicious email sent to one of the maritime facility’s employees was the entry point for the ransomware infection.

The ransomware corrupted the enterprise IT network files, encrypted them, and prevented the facility’s access to critical files. The officials stated that the incident affected the facility’s IT network and industrial control systems that monitor and control cargo transfer operations.

SecureLink Partners with ShiftLeft to Cater GCC and African Businesses

Thoma Bravo Acquires Sophos for US$3.9 Billion

Dubai-based risk advisory firm SecureLink has entered into a partnership with ShiftLeft, an application security testing provider, to specifically cater to businesses in the Gulf Cooperation Council (GCC) region and Egypt. This is a strategic alliance as ShiftLeft has a real-time application security product suite and SecureLink is a well-established firm assisting its customers to identify, mitigate and manage their cybersecurity risks in GCC and certain African countries including Egypt.

ShiftLeft provides a continuous application security platform, built for the modern software development life cycle (SDLC). It combines static code analysis to quickly and accurately identify vulnerabilities and protect the application in an automated workflow. It integrates directly into DevOps pipelines via pull request or build and analyzes over 500,000 lines of code in under ten minutes. This enables AppSec teams to insert security into DevOps without slowing down innovation. This combination of runtime code analysis and runtime protection makes ShiftLeft’s product suite, a comprehensive application security solution.

The partnership means that SecureLink will now have distribution rights for the entire ShiftLeft product suite which includes ShiftLeft Inspect, ShiftLeft Ocular and ShiftLeft Protect.

Reghu Mohandas, Director of SecureLink said, “Adoption of DevOps requires organizations to be agile and secure at the same time. Using platforms like ShiftLeft, we believe our customers can ensure that their applications are secure, both during build-time and run-time. Under this partnership, we will jointly focus on engaging with customers who require advisory services around application security and leverage the ShiftLeft platform in providing continuous assessment and protection.”

“The GCC and Africa is one of the fastest-growing, and most dynamic, regions powering the global economy,” said Manish Gupta, CEO, and Founder of ShiftLeft. “Combining our fastest and most accurate code analysis with the top application security advisory will provide our customers with the most advanced application security solution.”

Data Privacy Day 2020: Five Learnings from the Past

Data Privacy Day 2020

This Data Privacy Day 2020, we urge individuals and organizations around the world to learn from the fallout of the mega-breaches of the recent past. We provide five positive steps that companies around the world can take to better protect consumers, employees and more.

Until recently, data privacy was only considered critical in the digital world. But as the digital and physical worlds intersect, it is now integral not only to secure an individual or a corporation’s digital identity but also to avoid the safety of citizens being compromised. Data privacy considerations should underpin all company decisions, whether on the board level or on the shop floor and, this Data Privacy Day, organizations should encourage their entire workforce–not just IT teams–to re-evaluate how they secure and manage data.

By David Higgins, Technical Director, CyberArk

It’s now well-established that data is the world’s most valuable asset and a tempting target for malevolent hackers with varying motivations. More often than not, they are pursuing credentials that they can use to infiltrate businesses and target sensitive and valuable data. Attackers seek ways to cause irreparable damage across a whole range of industries, from seizing companies’ administration logins to hacking into medical data so as to hold individuals to ransom over the disclosure of sensitive personal information. As a tragic, but potentially realistic scenario, this could even result in a doctor being unable to perform a life-saving operation due to a lack of availability of the patient’s records, for example.

Hackers will inevitably be successful from time to time. Addressing this threat, and limiting how far they can infiltrate a network after a successful breach, is imperative in order to safeguard national security. Infiltration or compromise of CNI, for instance, could plausibly result in the loss of control of public services such as utilities, healthcare and government, posing a severe risk to public safety. This Data Privacy Day, we need to take a step back to not only understand the value in the data we hold but also the importance of only allowing individuals and systems that need it to access it.

Lesson #1: Equifax Breach
(reported in 2017)

Several tech failures in tandem–including a misconfigured device scanning encrypted traffic, and an automatic scan that failed to identify a vulnerable version of Apache Struts–ultimately led to the breach which impacted 145 million customers in the U.S. and 10 million U.K. citizens.

Data Privacy Day Learning – get security basics right. Cyberattacks are growing more targeted and damaging but a good industry reminder from the Equifax breach is that standard security basics should never be ignored. Patches should be applied promptly, security certificates should be maintained, and so on. This breach also inspired elected officials to push for stronger legislation to tighten regulations on required protection for consumer data. 

Lesson #2: Uber Breach
(reported in 2017)

In 2017 Uber revealed it had suffered a year-old breach that exposed personal information belonging to 57 million drivers and customers.

Data Privacy Day Learning – don’t store code in a publicly accessible database. Uber data was exposed because the AWS access keys were embedded in code that was stored in an enterprise code repository by a third-party contractor. A clear takeaway is that no code repository is a safe storage place for credentials.

Lesson #3: Facebook’s Cambridge Analytica Breach
(reported in 2018)

Cambridge Analytica harvested the personal data of millions of peoples’ Facebook profiles without their consent and used it for political advertising purposes. The scandal finally erupted in March 2018 with the emergence of a whistle-blower and Facebook was fined £500,000 (US$663,000), which was the maximum fine allowed at the time of the breach.

Data Privacy Day Learning – protect user data (or pay up). Lawmakers claim Facebook “contravened the law by failing to safeguard people’s information” – and suffered the consequences. Now the U.S. government is placing additional pressure on Facebook to stop the spread of fake news, foreign interference in elections and hate speech (or risk additional, larger fines). 

Lesson #4: Ecuadorian Breach
(reported in 2019)

Data on approximately 17 million Ecuadorian citizens, including 6.7 million children, was breached due to a vulnerability on an unsecured AWS Elasticsearch server where Ecuador stores some of its data. A similar Elasticsearch server exposed the voter records of approximately 14.3 million people in Chile, around 80 percent of its population.

Data Privacy Day Learning – adhere to the shared responsibility model. Most cloud providers operate under a shared responsibility model, where the provider handles security up to a point and, beyond that, it becomes the responsibility of those using the service. As more and more government agencies look to the cloud to help them become more agile and better serve their citizens, it’s vital they continue to evolve their cloud security strategies to proactively protect against emerging threats – and reinforce trust among the citizens who rely on their services. 

Lesson #5: Desjardins Breach
(reported in 2019)

The data breach that leaked info on 2.9 million members wasn’t the result of an outside cyber attacker, but a malicious insider–someone within the company’s IT department who decided to go rogue and steal protected personal information from his employer.

Data Privacy Day 2020 Learning – be proactive in identifying unusual/unauthorized behavior. While insider threats can be more difficult to identify, especially in a case where the user had privileged access rights, having a solution in place to monitor for unusual and unauthorized activities that can take automated remediation steps as needed can help reduce the amount of time it takes to stop an attack and minimize data exposure. This breach shows that a defense in depth security strategy that includes privileged access security, multi-factor authentication, and the detection of anomalous behavior with tools such as database activity monitoring has never been more crucial.

 About the Author

David Higgins is EMEA Technical Director at CyberArk. Data Privacy Day 2020David Higgins is EMEA Technical Director at CyberArk. Since joining CyberArk in 2010, David has worked to help the world’s leading – and most complex – organizations secure and protect their privileged access. Today David works with clients to advise on threats associated with privileged escalation, lateral movement and credential theft as well as discussing best practices and driving innovation around privileged management processes. David is a frequent speaker at events as well as with media. He holds a BSc. in Computer Systems and Information Systems.

Disclaimer: CISO MAG does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views are personal.

FIFA World Cup 2022: Too much at stake for Qatar

FIFA World Cup 2022

If there is a thing or two that can be learnt from the previous editions of all major sports tournaments, it is the fact that literally all the beloved tournaments will be the hot favorites for hackers. Nearly eight million people visited Russia for the 2018 World Cup, and much ahead of the inauguration of the tournament, the event witnessed a slew of cyberattacks targeted at the federal bodiesfans, and even soldiers sitting and watching the game from another part of the globe. Even Russian President Vladimir Putin declared that during the World Cup period the nation was a target for almost 25 million cyberattacks. With such limelight on the previous edition of the World Cup, the stakes for the upcoming FIFA World Cup 2022 are raised and it is imperative for Qatar to ensure the safety of its infrastructure as well as the Football World Cup.

How prepared is Qatar?

According to IDG Connect, the Arab nation has been heavily investing in digitization and is keen on positioning itself as a provider of a modern competition with its reputation at stake. “Both Qatar and FIFA are already up against it from a perception point of view and any sort of data breach that affects fans in the build-up or during the event could be catastrophic for the reputation of both parties,” Geoff Anderson, CEO of mobile security firm PixelPin told IDG Connect.

The Supreme Committee for Delivery & Legacy of Qatar also hosted global cybersecurity experts along with collaboration with Interpol’s Stadia–a special initiative to ensure the cybersecurity of sporting events, especially the 2022 World Cup–last year to understand the threats in the space and to be prepared against the attacks. The meeting also stressed on several vectors including IoT, industrial control systems, cybersecurity capabilities of the nation and the football federation, cybersecurity risk management as well as cybersecurity operations for venues.

According to Homeland Preparedness News, “Through Project Stadia, Interpol has created a ready network of specialists around the world to shape future efforts for securing major public events. Better understanding of the global threat environment and its implications is vital for nations hosting future major events.” Falah Al Dosari, the senior project manager of Project Stadia, said.

Support from other nations

In October, last year, Angelo Tofalo, Italian Undersecretary of the Minister of Defense also stated that Italy can provide Qatar with a full range of cyber and defense capabilities as well as expertise by leading Italian cybersecurity companies. According to Peninsula Qatar, Tofalo who opened the workshop on Italian Cyberprotection of the Defense Sector and of Critical Infrastructures during Qitcom 2019 suggested that Italy can help Qatar protect its infrastructures, including its transportation infrastructures, military boats, and borders. Italian businesses can also help provide security solutions for the stadiums which will be used for the upcoming FIFA World Cup 2022. “We have good relationship in defense with Qatar. We want to exchange experience and train together also in cybersecurity. We can offer greater assistance to Qatar in this field,” said Tofalo.

Apart from this, Qatar has been working parallelly with the U.K and has been exploring opportunities in co-operating cybersecurity efforts. Qatar and Singapore have also been working on enhancing their bilateral relations while focusing on expanding cooperation in the fields of security, fintech, and even cybersecurity.

The World Cup is still two years away. With several projects already being undertaken toward bettering the cybersecurity of the event and nations across the globe pledging to extend their support to Qatar, we can hope the Arab nation will be prepared for the worst that could emerge from the digital world.

U.K. Government to Strengthen Consumer IoT Security Standards

IoT attacks

The U.K. government recently introduced new legislation to improve security standards of the consumer Internet of Things. The law, launched by the Department for Digital, Culture, Media, and Sport (DCMS), will mandate that IoT devices sold in the country must adhere to advanced security standards.

The new regulations, jointly developed by DCMS and the National Cyber Security Centre, are intended for companies that manufacture and sell consumer IoT devices.

The legislation will make all IoT manufacturers in the country follow three critical security requirements:

  • All consumer internet-connected device passwords must be unique and not resettable to any universal factory setting.
  • Manufacturers of consumer IoT devices must provide a public point of contact so anyone can report a vulnerability and it will be acted on time.
  • Manufacturers must explicitly state the minimum length of time for which the device will receive security updates at the point of sale, either in store or online.

According to DCMS, the use of connected devices is on the rise. It’s estimated that there will be around 75 billion IoT devices in homes globally by the end of 2025.

Digital Minister Matt Warman said, “We want to make the U.K. safest place to be online with pro-innovation regulation that breeds confidence in modern technology. Our new law will hold firms manufacturing and selling internet-connected devices to account and stop hackers threatening people’s privacy and safety. It will mean robust security standards are built-in from the design stage and not bolted on as an afterthought.”

Recently, U.K.’s Ministry of Defense announced contracts to use AI-based technology in warships to help warship crews make quick decisions and process data efficiently.

According to a source, Defense and Security Accelerator (DASA) will fund £1 million (around US$1.3 million) for AI contracts as part of its “Intelligent Ship – The Next Generation” competition, which was aimed at using innovative approaches for Human-AI and AI-AI teaming for various defense platforms like warships, aircraft, and land vehicles.