Home Blog Page 257

U.S. and Europe’s Cyber Readiness Numbers Stall as Cyberattack Numbers Soar

cyber-attacks

A report released by Hiscox, a cyber insurance providing company, pointed that cyberattacks across several verticals in the U.S. and Europe have seen a sharp surge, whereas the cyber readiness of the organizations has come to a halt. The survey included nearly 5,400 private and public sector organizations from the U.S., UK, Belgium, France, Germany, Spain and the Netherlands.

The report highlighted that 61 percent of the firms experienced a cyber incident in the past year, up from 45 percent in 2018. Financial losses that accounted for US$ 1,67,000  have risen five times to nearly US$ 7,20,000.  Despite these alarming numbers, the cyber readiness of the firms seems to be moving at a snail’s pace, as only 10 percent of the surveyed companies achieved “expert” status and 74 percent were tagged as unprepared “novices”.

Here’s the country-wise report card as per Hiscox’s cyber readiness model:

Belgium:

  • Reported the greatest number of cyberattacks (71 percent) and most likely to report supply chain-related issues.
  • Topped the list for the frequency of cyberattacks (more than one-third of those targeted were attacked four times or more).
  • With 16 percent of the country’s large and enterprise-scale organizations ranked as “experts”, Belgium topped the cyber readiness chart for 2019.

France:

  • It Spent the most on cybersecurity (mean cost of US$ 2.1 million) and suffered the lowest number of cyberattacks.
  • 81 percent of the organizations ranked “novice,” whereas 6 percent qualified as “experts.”
  • The least likely country to have cyber insurance along with Germany.

Germany:

  • Cyber readiness of large and enterprise organizations qualifying as “experts” has come down from 20 percent in 2018 to 14 percent in 2019.
  • Faced the highest mean cost of cyber incidents of over US$900,000 – more than twice the average mean cost for all seven surveyed countries.
  • Among the study group, German organizations reported the highest cost for all cyberattack incidents (US$48 million).

Netherland:

  • Ranked as the best improver in the cyber readiness model, with the “novice” qualified group coming down from 82 percent in 2018 to 76 percent in 2019.
  • Recorded the highest number of DDoS attacks – 19 percent.
  • The largest number of cloud outages recorded – 27 percent.

Spain:

  • Largest spenders in cybersecurity technologies (18 percent spent on cyber incident detection, whereas 22 percent spent on cyber incident prevention technologies).
  • 72 percent of organizations reported a cyberattack.
  • 49 percent of organizations have cyber insurance.

UK:

  • Allocates the least cybersecurity budget – US$900,000.
  • The mean cost of all incidents was below US$243,000.
  • Most eligible to measure the business impact of a cyber incident.

U.S.:

  • The lowest mean cost of all cyber incidents – US$119,000.
  • Steep fall in the number of large enterprises qualifying as “experts” in cyber readiness – down from 26 percent to 11 percent in 2019.
  • 72 percent of the U.S. organizations plan to increase cybersecurity spending.

The proportion of organizations with no defined role for cybersecurity has halved in the past year – from 32 percent to 16 percent – and there has been a marked fall in the number of respondents saying that they changed nothing following a cyber incident (from 47 to 32 percent). The new regulation has led to prompted action, with 84 percent of Continental European organizations saying they have made changes following the advent of the General Data Protection Regulation (GDPR).

Rockwell Automation Acquires Avnet Data Security; Expands Cybersecurity Capabilities

Rockwell Automation, a digital transformation and industrial automation company, recently acquired cybersecurity firm Avnet Data Security. The acquisition deal integrates the extensive knowledge of Avnet with Rockwell Automation’s strategic objective, to jointly deliver cyber and network services globally.

Commenting on the acquisition, Frank Kulaszewicz, Senior Vice President at Rockwell Automation, said, “Avnet’s combination of service delivery, training, research, and managed services will enable us to service a much larger set of customers globally while also continuing to accelerate our portfolio development in this rapidly developing market.”

Igal Cohen, CEO of Avnet, said, “We are excited to join Rockwell Automation to further expand their already robust cyber offering. We are continuing to serve our existing clients while expanding our reach to service a much broader range of customers. Our passion and mission have always been to help as many organizations as possible to secure their data from internal and external threats.”

Cloudflare Acquires S2 Systems for “Cloudflare for Teams”

Acquisition

Cloudflare, a cloud security provider established in 2009, has recently acquired browser security provider startup S2 Systems. The acquisition aims at integrating S2 Systems’ browser isolation technology that combines speed, reliability, and protection to prevent browser-based attacks with Cloudflare’s new product offering, “Cloudflare for Teams”.

The acquisition was closed for an undisclosed amount on December 31, 2019. S2’s team of 10 members from Kirkland, Seattle, is now officially a part of Cloudflare team. Cloudflare, who already has 200 plus centers across the globe, will now expand services in Seattle to accommodate its new employees.

Matthew Prince, co-founder and CEO at Cloudflare, said, “People and the teams within an organization can now access the tools they need to do their daily job and are safe from malware and other online threats.   The browser isolation technology will run across Cloudflare’s entire global network, bringing it within milliseconds of virtually every Internet user.”

Cloudflare for Teams will be further segmented into two parts, Cloudflare Access and Cloudflare Gateway. They will offer services as per organizational and user requirements. Cloudflare Access is a Zero Trust identity and access management tool designed to help companies ensure that their employees are using the most up-to-date software on their devices. Whereas, the Cloudflare Gateway protects organizations and its people from internet threats.  Cloudflare Gateway has three versions: Gateway, Gateway Pro, and Gateway Enterprise.

Cloudflare for Teams has been built with a view to helping build a better, faster and safer internet for the future. It will also help secure mobile and cloud-enabled internet in a better way

City of Las Vegas Confirms Cyberattack

Compromised Email Accounts

The City of Las Vegas has confirmed a cyberattack that compromised its entire computer network systems.  The officials stated that citizens may face brief interruptions in online services.

A Twitter post from these officials stated, “We experienced a cyber compromise at 4:30 AM Tuesday. Our IT team is assessing the extent of the compromise. When aware of the attempt, we immediately took steps to protect our data systems. We will have a clearer picture of the extent of the compromise over the next 24 hours.”

According to David Riggleman, the communications director of the City of Las Vegas, the IT department is assessing the impact of the attack and is taking necessary actions to protect their data systems.

In a similar incident that occurred in 2019, the Louisiana state government fell victim to a ransomware attack.  John Bel Edwards, the Governor of Louisiana, revealed that the ransomware attack impacted the public state government’s email, website, and other online applications.

“Today, we activated the state’s cybersecurity team in response to an attempted ransomware attack that is affecting some state servers. The Office of Technology Services identified a cybersecurity threat that affected some, but not all state servers,” Edwards said in a Twitter post.

Ukraine Cyber Police Nab Card Fraudsters

Ukraine

Just before the new year, the Ukraine Cyber Police department arrested a cybercriminal hacker group (including three Ukrainians and one foreign national) from the Kharkiv region that was responsible for hacking more than 20,000 servers of private organizations around the globe. This was just the beginning of things to come.

As per preliminary investigation of the Ukraine Cyber Police department, the cybercriminal hacker group that has been active since 2014 targeted organizations mainly from Ukraine, Europe, and U.S. regions. From the hardware and other physical and virtual property confiscated during the raid, the officials learned that hackers sold the hacked server credentials and access points to various customers around the world. These servers were also used to create botnets for mining, DDoS attacks, installing software command centers with viruses and turning them into weapons for brute-force attacks.

Cyber forensics and cybersecurity experts later discovered that the same group was responsible for a much bigger fraudulent financial auction scam. The hackers established multiple fake call centers in the Kiev province to carry out trading in various international stock markets. They asked their victims to invest money through a fake trading environment (website), which was then getting credited to the hackers’ offshore accounts.

Astoundingly, the hackers managed to collect on an average US$100,000 every month by scamming the victims. Later when they inquired for cash withdrawal, the hackers carried out certain maneuvers, which led to the victims’ complete loss of capital.

As per a blog post, “Card Fraud in Ukraine,” the number of fraudulent operations with payment cards amounted to over 77,600 cases in 2018.  The rate of fraudulent online transactions has since increased significantly. Experts suggest that the fraudsters are now switching from technological methods like social engineering for managing human actions, that includes features of human psychology. The easiest and the most effective way is by creating a fake online store or URL hijacking.

Recently, Venafi – a cybersecurity software provider that secures and protects cryptographic keys and digital certificates, said it has uncovered nearly 100,000 typosquatted/fake domains with valid TLS certificates impersonating as major retailers.

According to the analysis by Venafi, the top 20 online retailers were being targeted by 109,045 fake domains using valid TLS certificates. Of the 109,000 typosquatted domains, nearly 84,000 target retailers were from the U.S. Similarly, in the U.K., nearly 14,000 certificates were issued for targeting fake retailer domains, 7,000 certificates were issued in Germany, 3,500 in Australia, and 1,500 in France.

Data Breach Affects Around 50,000 Patients at Minnesota Hospital

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Alomere Health, a Minnesota-based hospital operator, is the latest victim of a data breach that affected 49,351 individuals, scmagazine reported.

In an official report, the health care provider revealed that an unknown intruder gained access to two employee email accounts multiple times between October 31, 2019, and November 1, 2019, and also on November 6, 2019.

The compromised data includes names, dates of birth, addresses, medical record numbers, health insurance information, and diagnosis information. Alomere Health stated that a few numbers of patients had their social security numbers and driver’s license numbers exposed in the incident. It’s unclear if attackers actually misused any of the compromised data.

“The investigation was unable to determine whether the unauthorized person actually viewed any email or attachment in either account. In an abundance of caution, we reviewed the emails and attachments in the accounts to identify patients whose information may have been accessible to the unauthorized person,” Alomere Health said in a statement.

The company notified the patients whose information was left vulnerable and offered them free credit monitoring and identity protection services.

“Even though we have no confirmation that patient information was actually viewed by the unauthorized person, or that it has been misused, we mailed letters to patients whose information was found in the accounts,” the statement added.

Cybersecurity experts said hackers are increasingly targeting the Health care industry to steal sensitive medical information and sell it on the black market. A survey from cybersecurity company Carbon Black revealed the rate of cyber-attacks on the healthcare industry appears to be increasing exponentially.

In its survey report, Healthcare Cyber Heists in 2019, Carbon Black disclosed what is happening to Personal Health Information (PHI) that was stolen by cybercriminals. The survey, which involved 20 of the Health care industry’s Chief Information Security Officers (CISOs), found the Health care sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that PHI is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.

Accenture to Acquire Symantec’s Cyber Security Services Business from Broadcom

Symantec

Coming a few months after Broadcom’s acquisition of Symantec’s enterprise security business, Accenture has now agreed to acquire Symantec’s Cyber Security Services business from Broadcom, Inc. Financial terms of the deal were not disclosed.

The acquisition will make Accenture Security one of the leading providers of managed security services, further enhancing its ability to help companies rapidly anticipate, detect and respond to cyber threats.

Symantec’s portfolio of Cyber Security Services includes global threat monitoring and analysis through a network of security operation centers (SOCs), real-time adversary and industry-specific threat intelligence and incident response services. The six security operations centers are located in the U.S., the United Kingdom, India, Australia, Singapore and Japan. Its managed security services business is supported by a proprietary cloud-based platform that delivers a steady stream of technical and cyber adversary threat intelligence through a customizable portal.

“Cybersecurity has become one of the most critical business imperatives for all organizations regardless of industry or geographic location,” said Julie Sweet, Accenture’s Chief Executive Officer. “With the addition of Symantec’s Cyber Security Services business, Accenture Security will offer one of the most comprehensive managed services for global businesses to detect and manage cybersecurity threats aimed at their companies.”

Kelly Bissell, senior managing director of Accenture Security said, “Companies are facing an unprecedented volume of cyber threats that are highly-sophisticated and targeted to their businesses, and they can no longer rely solely on generic solutions. This acquisition is a game-changer and will help Accenture provide flexibility rather than a ‘one size fits all’ approach to managed security services. With Symantec’s Cyber Security Services business, we can now bring clients our combined expertise fine-tuned to their industry with tailored global threat intelligence powered by advanced analytics, automation and machine learning.”

In September 2019, Broadcom acquired Symantec’s enterprise security unit for US$10.7 billion in cash. Symantec’s Enterprise Security business, now a division of Broadcom, is headquartered in Mountain View, California and its Cyber Security Services business includes more than 300 employees around the world who serve top-tier organizations across a diverse range of industries, including financial services, utilities, health, government, communications, media, technology and retail.

“Becoming part of Accenture Security is a tremendous opportunity for our clients and our cyber warriors around the globe, enabling us to fuse the unique services, capabilities and solutions of two well-established companies to deliver the next generation of cybersecurity services,” said John Lionato, vice president and general manager of Symantec’s Cyber Security Services business.

Accenture Security has a global network of cybersecurity labs, deep industry understanding across client value chains and services that span the security lifecycle. It offers services that include strategy and risk management, cyber defense, digital identity, application security and managed security.

Symantec’s Cyber Security Services business will be the latest in a series of acquisitions—including those of Deja vu Security, iDefense, Maglan, Redcore, Arismore and FusionX—that demonstrate Accenture Security’s commitment to investing in and innovating advanced threat intelligence and cybersecurity solutions.

In its 2019 fiscal year, Accenture invested nearly US$1.2 billion globally on 33 acquisitions to acquire critical skills and capabilities in strategic, high-growth areas of the market.

Completion of the acquisition is subject to customary closing conditions and is expected to close in March 2020.

 

Pam Murphy is Imperva’s New CEO

Pam Murphy

Cybersecurity firm Imperva recently announced the appointment of Pam Murphy as the new CEO, effective immediately. Interim CEO Charles Goodman will continue as chairman of the board.

Previously, Pam Murphy served as COO of enterprise software company Infor. Prior to Infor, Murphy served multiple leadership positions at Oracle Corp. and Andersen Consulting. Her background includes experience in field sales, professional services operations, and deep operational experience in running global organizations. Murphy also held a variety of roles across North America, Europe, and APAC.

Imperva develops and sells information security software for databases and web applications, on-premises, in the cloud, and across hybrid environments.

“We’re excited to have Pam join us on our mission to protect critical assets from cybercriminals’ ever-changing attacks,” said Charles Goodman. “As an accomplished executive who has led operations for some of the world’s largest software companies and demonstrated ability to deliver customer value on a massive scale, she is perfectly positioned to lead Imperva through our next phase of growth.”

Commenting on her new role, Pam Murphy said, “I’m looking forward to building on the foundation laid by our outstanding leadership team and capitalizing on Imperva’s market-leading products. Our relentless focus on our customers and their needs will always come first as we seize the many opportunities that lie ahead and significantly grow the business both domestically and internationally.”

Chris Hylen, Imperva’s former CEO, resigned from the company last year after a data breach that affected customers of Imperva’s Cloud Web Application Firewall (WAF). The breach occurred due to errors that happened when the company was migrating to a cloud-based database service, according to Imperva’s CTO Kunal Anand.

Anti-Virus Providers Finally Patch a 10-Year-Old Bug

Bug, vulnerability, zero-day

Reported in 2009, a bug residing in compressed archives let users exploit it but went undetected from multiple anti-virus providers. The severity of the bug was not taken seriously until November last year when attackers began exploiting this bug for spreading malware via emails. Top anti-virus providers have finally taken note and fixed it.

Thierry Zoller, Sr. Information Security and Privacy Risk Manager HSBC and Board Member of EC-Council Global Advisory reported this flaw. He explains, this bug is not archive format specific. Multiple archive formats including ISO, ZIP, and Bz2 can be used. “It depends on the user’s ability to alter a compressed archive in such a manner that it becomes inaccessible to the AV (anti-virus) software,” he said.

As per Zoller, it has a low impact on the client side as the engine is only evaded/bypassed on scan time (e.g. scheduled hard disk scan) but not on runtime, when the user extracts the payload. But when it comes to the server side, the impact is high. The anti-virus gateway products (e.g. emails, payment gateways, websites, cloud services) are at a high risk as there is no user that extracts the file, it is impossible for the gateway to inspect the code and the engine is completely bypassed.

Zoller further added that the bug impacts many products from multiple vendors, including Avira, Bitdefender, ESET and Kaspersky, which he contacted in October 2019 to report the flaw and provide proof-of-concept code, so that patches would be released.

The issue was finally addressed by ESET in version 1294 of the archive unpacker module. Similarly, Kaspersky with the release of patch E for four of its products, namely Kaspersky Secure Connection 4.0 (2020), Internet Security 2020, Total Security 2020, and Security Cloud 2020 has also fixed this bug.

Kaspersky said, “We have fixed three bugs in one of the anti-virus engine components that is responsible for work with ZIP archives. The fix for this component corrects its behavior in a situation of the antivirus scanning specially crafted ZIP archives. These malformed archives could be used to circumvent our antivirus scan process. The bugs affected Kaspersky products with antivirus databases.”

On contacting the second time around for this bug, both ESET and Kaspersky quickly patched the flaws in their respective products and credited Zoller for reporting them.

Hackers Exploit Android Vulnerability Via Malicious Apps

BotenaGo, malware over encrypted connections

Researchers from cybersecurity firm Trend Micro revealed that they’ve discovered three malicious apps on Google Play, which are designed to compromise victim’s devices and steal information.

The three malicious apps, Camero, FileCryptManager, and CallCam, were masked as photography and file manager tools, according to researchers. It’s also observed that the Camero app exploits use-after-free vulnerability CVE-2019-2215 that exists in Binder, an inter-process communication system in Android. By exploiting the CVE-2019-2215 vulnerability, attackers can inject malicious codes and steal information without user knowledge.

The researchers also found that the three apps likely belong to a hacking group “SideWinder.” It’s believed that the SideWinder group has been active since 2012, and reportedly targeted military entities’ Windows machines.

“We speculate that these apps have been active since March 2019 based on the certificate information on one of the apps. The apps have since been removed from Google Play,” the researchers said.

Malware Distribution

According to researchers, SideWinder group deploys malware payload in two steps:

  • It downloads the DEX file from the attacker’s C&C server.
  • The downloaded DEX file installs an APK after exploiting the device, while Camero and FileCrypt Manger apps act as droppers.

“After downloading the extra DEX file from the C&C server, the second-layer droppers invoke extra code to download, install, and launch the callCam app on the device,” the researchers said.

To deploy the callCam app on the device, SideWinder uses techniques like obfuscation, data encryption, and invoking dynamic code to avoid detection.

Once downloaded, the callCam app hides its icon on the device and collects users’ information and sends it to the C&C server. The compromised information includes user location, battery status, files on the device, installed app list, device information, sensor information, camera information, screenshot account, and Wi-Fi information. It also captures data from applications like Twitter, Yahoo Mail, WeChat Facebook, Gmail, and other social media apps.

The three malicious applications were found to be active since March 2019 and they have now been removed from the Google Play store.