Home Blog Page 26

Automating Cyber Hygiene Will Become Increasingly Important

cybersecurity predictions, cyber hygiene

What will Cybersecurity be like in 2022? It is that time of the year when we think about the year gone by and wonder what is in store for us in the new year. In the first of a series of predictions from global experts that CISO MAG contacted, Daniel Spicer, CSO, Ivanti, offers eight key trends. Of these, we think the most interesting one is cyber hygiene. Spicer says finding ways to automate cyber hygiene will become increasingly important, especially as environments continue to get more complicated.

1. Nation-State Threat Actors Will be Quieter in 2022

cyber hygiene, Daniel Spicer, CSO, Ivanti
Daniel Spicer, CSO, Ivanti

Nation-state-led cyberattacks dominated a large portion of the cyber-related news cycle at the end of 2020 and throughout most of 2021. Many espionage organizations that prefer to remain quiet and in the shadows were brought into the spotlight. While nation-state-backed threat actors won’t stop their operations, we should expect 2022 to be a quieter year. Many and techniques have been exposed in the past year, so nation-state threat actors will spend additional time updating kits and refining techniques. Changes in cybersecurity policies and requirements will require nation-state operators to adjust their toolkits further to evade new minimum requirements. Plus, most of the world does not have a major election cycle next year. However, by the end of 2022 or early in 2023, we should expect to see a continuation of larger-scale operations targeting the weakest links in the chain. And we are likely will see more attacks targeting managed service providers (who provide IT and security services to companies) instead of going after companies directly.

2. Automating Cyber Hygiene Will Become Increasingly Important as Environments Continue to Get More Complicated

Ultimately, most attacks are the result of poor cyber hygiene. Even an advanced attack, such as a supply chain or ransomware attack, often starts with basic tactics like social engineering, phishing, or exploiting vulnerabilities in unpatched software to infiltrate environments and deploy malware. Finding ways to automate cyber hygiene will become increasingly important, especially as environments become more complicated. This includes leveraging a combination of risk-based vulnerability prioritization and automated patch intelligence to identify and prioritize vulnerability weaknesses and then accelerate remediation. The White House recently released a memo encouraging organizations to use a risk-based assessment strategy to drive patch management and bolster cybersecurity against ransomware attacks. If an organization can automate all the processes that constitute cyber hygiene, the security team can deal with bigger issues.

3. Phishing Attacks Will Continue to Plague Organizations

Phishing should have been solved long ago, but as an industry, we failed. According to a recent survey by Ivanti, 74% of respondents said their organizations had fallen victim to a phishing attack in the last year. SMS phishing is the latest variant to gain traction. It works much like an email phishing scam but instead sends deceptive or malicious links through text messages. In 2022, we can expect to see more sophisticated phishing scams. For example, we may see threat actors targeting marketing firms and tools used by email marketers to achieve maximum impact. Since marketing emails come from trusted domains, end users are likely to trust them and click on links, increasing the success rate of attacks.

4. Ransomware Attackers Will Include More Data Theft

Ransomware is a universal problem that is not going away. Following the rapid shift to remote work, remote access services became easy and primary targets, with phishing often used as the attack vector. Ransomware has continued to evolve, with attackers increasingly leveraging known vulnerabilities with remote code execution and privilege escalation capabilities. In 2022, we can expect ransomware attackers to continue to mature their tactics, expand their attack arsenals, and target unpatched vulnerabilities across enterprise attack surfaces. However, as more organizations backup their data, threat actors will likely skip the deployment of ransomware and go straight to stealing the data and blackmailing organizations. In terms of industries to watch, in 2022, as the pandemic calms down, the health care industry will be targeted more aggressively.  We will continue to see more attacks for critical infrastructure industries such as food supply chains and energy because they are not as secure as other industries. Hopefully, this will spur bigger budgets and increased spending on the right security controls for these industries.

5. RIP Antivirus and Vulnerability Scanners

Traditional antivirus software doesn’t work, and traditional vulnerability scanners aren’t as valuable as they used to be. Both are already on their way out, and I think both will be completely eradicated in 2022. Looking ahead, it’s about endpoint detection and response (EDR). EDR will be the next generation of antivirus software. We may also see a revival of tools in the identity and user behavior analytics space. User behavior analytics originally came out too early. I expect new technologies to come out in rebranded forms, but they will look the same under the hood. We likely will not see this at the beginning of 2022, but more likely later in the year.

6. Centralized Identity Management Will Become Increasingly Important

It is not easy to secure the home office. The biggest challenge for security teams is that it’s hard to control the work-from-home environment when you lack control over all the devices that sit on a home network. And there are more and more devices connecting to home networks, given the rise in consumer IoT devices. A second issue, which touches upon the Great Resignation, is remote offboarding. It’s not as simple as having an employee send their work laptop back to the employer. We don’t know to what extent they had access to resources in the cloud. Securing identities through Zero Trust becomes increasingly important.

7. The Great Resignation Will Hit the Security Industry Hard

Globally, the shortage of cybersecurity professionals is estimated to be 3.12 million. It is challenging to fill all roles right now, and there is a bit of a bubble on the value of security professionals. In five years from now, we can expect to see more security professionals entering the workforce with more degrees and more education. And with more degrees and education, the industry should expect some compensation bubbles. Looking ahead, company culture and mission will also  be of increasing importance to future security professionals. There is been an upward trend among security professionals who are changing jobs based on the mission of a company and their contribution to society We can expect this to continue in 2022 and beyond; it will not be about compensation anymore but the company’s mission.

8. Biden’s Focus on Cyber Means There is Zero Option for Anything but Zero Trust in the Public Sector

The President’s Order on security has created a lot of pressure and work for public sector organizations – it is something that hasn’t historically been prioritized. There will be a lot of scrambling in 2022 to ensure the right strategies are in place as there are many leaders still figuring out the cloud, Zero Trust, and work from anywhere. Increasing and enhancing an agency’s cybersecurity posture will be an absolute mandate vs. a nice to have because of the increased need to focus on cybersecurity following a steady drumbeat of attacks that have directly impacted Americans and hampered logistics and services across the United States.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Chinese Linked Cyberespionage APT Spreads Flagpro Malware

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Security experts uncovered a new malware campaign from BlackTeck, a Chinese cyberespionage APT group. According to a report from NTT Security, the group targeted Japan-based companies via a novel malware variant dubbed Flagpro.

“We have observed attack cases using Flagpro against multiple companies (Defense, Media, Communications) several times. In October 2020, a sample related to Flagpro was submitted to an online service. Therefore, Flagpro may have already been used for attacking cases at that point,” the report said.

Flagpro Malware Attack Chain

Researchers stated that attackers leveraged Flagpro malware in the initial stage of infection to compromise the targeted network, download a second-stage malware, and then execute. The Flagpro infection starts with a spearphishing email with an attached password-protected archived file (ZIP or RAR).

Also Read: Researchers Uncover New Malware Campaign Spreading ‘Blister’ Payload

The archived file includes an .xlsm format file (Excel macro) containing a malicious macro. Once the user activates the macro, the malware automatically downloads and creates an EXE file (containing Flagpro) in the startup directory. Once installed, Flagpro malware communicates with the hacker-operated C&C server and executes the received commands.

Flagpro’s main activities include:

  • Download and execute a tool
  • Execute OS commands and send the results
  • Collect and send Windows authentication information

Indicators of Compromise (IoC)

  • 54e6ea47eb04634d3e87fd7787e2136ccfbcc80ade34f246a12cf93bab527f6b
  • e197c583f57e6c560b576278233e3ab050e38aa9424a5d95b172de66f9cfe970
  • 655ca39beb2413803af099879401e6d634942a169d2f57eb30f96154a78b2ad5
  • 840ce62f92fc519cd1a33b62f4b9f92a962b7fb28c12d2f607dec0b520e6a4b2
  • ba27ae12e6f3c2c87fd2478072dfa2747d368a507c69cd90b653c9e707254a1d
  • 77680fb906476f0d84e15d5032f09108fdef8933bcad0b941c9f375fedd0b2c9
  • e81255ff6e0ed937603748c1442ce9d6588decf6922537037cf3f1a7369a8876
  • 45[.]76.184.227
  • 45[.]32.23.140
  • 139[.]162.87.180
  • 107[.]191.61.40
  • 172[.]104.109.217
  • misecure[.]com
  • centosupdates[.]com

“We have observed attack cases using Flagpro against Japan since October 2020. The attack techniques have not changed a lot, but BlackTech uses more evading techniques. For example, they adjust decoy files and file names to their target and check the target’s environment carefully. Recently, they have started using other new malware called SelfMake Loader and Spider RAT. It means that they are actively developing new malware. Therefore, you need to pay attention to the attacks from BlackTech,” the report added.

How Blockchain And IoT Is Making Our Future Smarter?

PSTI IoT Bill, Common IoT Attacks

Blockchain’s most significant benefit is that no authority has control over it. The advent of IoT (Internet of Things) has sped up its decentralized ledgers for conducting financial transactions. One of the critical challenges of the IoT world is data security, where Blockchain offers its benefits.

By Harmanpreet Kaur, Security Consultant at EY

Blockchain uses immutable records for storing sensitive information, and every record is distributed in the form of tamper-proof nodes. Strong cryptographic encryption and hashes are used to protect the information, and if a block must be accessed, all the previous blocks need to be validated and edited. Due to the ‘chain of blocks’ and the nature of accessing data sequentially, Blockchain networks cannot be hacked by cyber adversaries. Blockchain is used with IoT networks to create secure “mesh networks” that are not prone to vulnerabilities such as spoofing and impersonation. Companies looking to add transparency and trust to their products/services are leveraging Blockchain with IoT, and there are roughly 9 billion smart devices online today.

IoT networks send huge volumes of data between multiple devices, and Blockchain uses decentralized peer-to-peer ledgers to transmit it. Only authorized users can approve changes/edits made to nodes over networks, and third parties or hackers cannot make edits to these ledgers nor access them unless all other users in these networks approve them. This is what makes Blockchain so powerful, and when it is integrated with IoT, transactions or the transmission of billions of data essentially becomes completely secure.

How do Blockchain and IoT complement each other?

IoT networks have an administrator who acts as the central authority for controlling and monitoring processes over these networks. Hackers know that the administrator has access to data and is the main vulnerability when it comes to managing IoT devices.

Social engineering strategies are commonly employed to fool the administrator in leaking login credentials, and sometimes hackers can use brute force methods to crack administrator accounts. Blockchain can complement IoT by putting data into blocks and creating immutable chains that outsiders cannot alter. Users can enjoy additional security by selecting data and customizing access permissions, thus making it convenient to share among clients and partners without compromising on security.

Decentralized ledgers are designed to be interoperable and integrated with multi-cloud environments, and Blockchain can streamline business processes by drawing on data shared by sensors and IoT devices. Freight transportation is an emerging field where this merger technology is being applied. IoT-enabled blockchain networks are being used to track shipment status, move goods from locations, and garner trust in sharing data amongst parties. Compliance audits and component tracking in aircraft cargo containers are other areas where Blockchain networks and IoT are used. It’s helping manufacturers cut down on costs and ensure goods follow the standards laid down by regulatory authorities when transporting them via air.

IoT is used in critical machine maintenance, and operators use Blockchain networks to check what industrial processes require preventive maintenance by getting automatic alerts and notifications and recording their work using ledgers. Operational records can be shared with the government to verify the state of repairs done and ensure legal compliance.

Blockchain systems safeguard third parties from a single point of failures experienced by IoT devices, and decentralized ledgers can be used for optimizing computational processing efficiency. Blockchain and IoT combined also address the issue of high concurrency rates by using cryptographic security protocols and can improve bandwidth limitations faced from streaming huge volumes of data continuously across IoT networks, sensors, and devices.

According to a study by Gartner, it is estimated that Blockchain would add $3.1 trillion in business value by 2030. The global IoT market is expected to grow from $157B in 2016 to $457B by 2020.

Though IoT has various advantages, it has its drawbacks when it comes to authentication standards. Authentication is crucial concerning security aspects. It is necessary that the data stored and transmitted are safe, secure, and protected from external attacks such as hacking of data, unauthenticated access, etc. With the integration of Blockchain and IoT technology, authentication issues and privacy concerns are tackled. Every participant in Blockchain networks has a copy of the data. The secure nature of Blockchain nodes assures that transactions cannot be modified, thus promoting security and letting them be available for viewing by the public.

Benefits of Blockchain and IoT Combined

Currently, the IoT ecosystem uses a client-server architecture that is non-distributed, and IoT models are not scalable, which puts severe limitations when it comes to meeting the demand of global consumers.

Blockchain technology can be used to track all the sensor data measurements, preventing any duplications of other malicious data. The implementation of IoT devices is usually intricate, and security concerns can be easily solved by taking advantage of IoT device authentication, identification, and cryptographic encryption features.

IoT sensors can be exchanged via Blockchains to reduce threats with third-party services, and Blockchain can secure the IoT devices from being altered. Smart contracts are now possible with blockchains, and agreements are executed automatically as soon as predefined conditions are met, thus involving no human intervention or third-party interferences.

Blockchain integrations with IoT are proving to provide significant benefits to the telecom industry. Given that IoT devices are connected to a centralized server, the security procedures to authorize and authenticate transactions are expected to be slower with the increase in IoT devices.

This is overcome by the Blockchain’s Self-sovereign identity (SSI), which acts as a cover for the IoT devices. The SSI possesses key encryption methodologies and promotes low-cost compliance with GDPR, CCPA, etc.

Blockchain and IoT for different areas

Smart Homes

Integration IoT technology on a blockchain platform can provide a high-security system for homes that can all be accessed by a smartphone remotely. Blockchain can enhance the IoT-based devices for a smart home by providing solutions for security problems and removing any intermediary through its decentralized infrastructure. One such company that offers blockchain-based smart home solutions is an Australian telecommunication and media company called Telstra. The company is dedicated to incorporate blockchain technology through biometric security to ensure highly secure smart devices. Blockchain’s immutable and practically un-hackable nature allows the storage of personal data for security purposes of the IoT devices such as biometrics, facial recognition, etc. Blockchain integration with IoT allows only the owner to access the data through their private key.

Pharmacy

There is a day-by-day increase in the fabrication of pharmaceutical medicines and disrupting the pharmacy industry’s functions, such as developing and distributing drugs. Thereby, blockchain technology is used to track and trace pharmaceutical medication and monitor the shipping process. Mediledger is a blockchain-based IoT use case that helps in monitoring the prescribed medicines and their legal changes. The tracking can be accomplished through intelligent devices that use sensors to store the information on the blockchain network to help process payments and monitor the supply chain process to avoid fabrication. The blockchain network can be shared between the manufacturers, clients, sellers, and dispensers to enable transparency.

Agriculture

Ensuring enough produce for the entire population while reducing the carbon footprint is a big challenge in the agriculture sector. The agriculture industry faces problems maintaining the transparency of supply chain management, farmers, and whole sellers. However, with combined solutions of IoT and Blockchain, the industry is set to experience revolutionary changes. One such solution is installing sensors in farms while storing and processing data on blockchain networks to accelerate supply chain management, maintain enhanced security, and ensure no tampering.

Pavo, a recent innovation, is determined to bring transparency to the supply chain and collect the information through a sensor-based hardware device that transmits data to Blockchain networks and provides secure storage. Farmers can change their operations according to the analysis of stored data and increase productivity. Pavo even allows farmers to presell their harvest through smart contracts and receive secure payments while waiting for crops to grow and harvest.

Blockchain & IoT – Use Cases

Use Case 1 – Self-driving cars (IoT) and Blockchain.

One of the best examples of Blockchain and IoT mergers is the evolution of self-driving cars connected and operated through IoT networks. Self-driving cars are sustainable and reduce carbon footprints, thereby proving a better alternative in protecting the environment. IoT successfully converts cars into smart devices and uses advanced technologies to operate in real-time, capturing accurate surroundings.

IoT-based self-driving cars can generate route information, predict travel time and notify alerts by collecting data from sensors. However, the biggest downside of IoT-based vehicles is the lack of data security in connected cars, which is the primary reason why the automotive sector is looking to combine IoT and blockchain features. The collaboration of IoT and Blockchain frameworks will ensure high-security standards for storing and transmitting data between connected cars and IoT platforms.

According to a report, it is estimated by 2025, around 10-15% of transactions on connected vehicles will likely be done using blockchain technology. Blockchain infrastructures can certify adequate data storing and minimizing and protect against data breaches and leaks. Attackers will not tamper with data stored on the blockchain network as encrypted through cryptographic hashes and timestamps. Incorporating blockchain technology with IoT automotive devices will also enhance the acceptance of self-driving cars and become a boon for the automotive market.

Use Case 2 – IoT + Blockchain to track vaccines 

With the world moving on despite the COVID-19 pandemic and its varied traits, one of the most significant breakthroughs was inventing a vaccine effective against the Coronavirus. Since the invention of the vaccine, all countries have exercised vaccination drives and getting as many people vaccinated as possible every day. However, increased demand for vaccines was not being fulfilled due to inadequate stocks and outdated vaccines. It was difficult for medical companies to keep inventory records, supply chain, and distribution data.

Indian IT firm Tech Mahindra came up with a solution to track the vaccine supply chains worldwide and became a leading pioneer in this field. Their solution was a blockchain-based open-source platform to maintain supply chain transparency at all times. The vaccine manufacturers use the blockchain-based inventory tracking system and vendor payments through Internet-of-Things (IoT) and smart contracts. Integrating IoT with the blockchain-based tracking application made it easier for vaccine manufacturers to transfer amounts to vendors.

To understand and integrate steps of a supply chain system, the IT firm plans to work with vaccine researchers, governments, pharmaceutical companies, distributors, and healthcare workers.

Blockchain and IoT-based solutions are expected to ensure the validity and safety of these vaccines. Tech Mahindra aims to implement a Vaccine Ledger globally soon.

The traceability solution will also predict and prevent failures in the supply chain, including expired vaccines, fabrication, and inadequate stock. The company is set to develop mobile and web-based applications to support manufacturing and government requirements. Their innovative solution is to build a peer-to-peer network that supports real-time data sharing, traceability, and validation to ensure authenticity and information security. The data on the ledger can be used to trace IoT integration and inventory management and can be integrated easily into the existing systems. The IT tech firm claims it will establish a worldwide supply chain, and those countries can view immediate results when it’s finally deployed.

Conclusion 

Blockchain and IoT Technology are some of the booming and increasingly used technologies in today’s life. Many people have turned towards these technologies for various uses, such as smart homes, cryptocurrencies, etc. Multiple organizations have now turned towards Blockchain integrated with IoT, which is beneficial and provides a stable function that is secure and ready. Various renowned organizations have supported and started utilizing Blockchain + IoT like the Hyundai supported a start-up project wholly based on blockchain technology, known as the HDAC, and raised nearly 40 million dollars to integrate with the IoT devices produced by the organization (Hyundai). Another organization, Filament, is developing an industrial IoT chip responsible for automatically encoding sensor data while simultaneously adopting Blockchain technology. And the most renowned project, IOTA, showcases Tangle, a blockchain specially created and designed for IoT devices. Various organizations and sectors are now incorporating blockchain technology integrated with IoT technology based on the benefits they offer when integrated, based on the results of available projects. Experts and professionals agree that when the two technologies are combined, it results in an infinite potential that can overcome various drawbacks while still maintaining their available features.

About the Author

Harmanpreet KaurHarmanpreet Kaur is currently work as Security Consultant at EY GDS. She has over 3+ years of experience in Privileged Access Management solution CyberArk where she worked on CyberArk Implementation and Support Projects for various clients. She has completed her CyberArk CDE, Sentry, Defender and Trustee certification and also has experience and knowledge in creating technical and non-technical documents for her clients.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Reference:

  1. http://aitos.io/en/developers.html#undefined1
  2. https://www.brighttalk.com/webcast/679/449443
  3. https://www.psacertified.org/products/boat-blockchain-framework/
  4. https://www.mindtree.com/insights/resources/blockchain-could-ease-iot-implementation-for-telcos
  5. https://www.sciencedirect.com/science/article/pii/S0167739X17329205
  6. https://www.ibm.com/blogs/blockchain/2018/01/why-blockchain-and-iot-are-best-friends/
  7. https://www.blocksmartsol.com/home/blog/blockchain-and-the-internet-of-things/
  8. https://www.devteam.space/blog/how-to-secure-the-internet-of-things-iot-with-blockchain/

Hackers Exploit Log4j Flaw to Hijack Crypto Platform ONUS

ONUS Log4j, Cryptocurrency Wallet Security

Recently, the popular Vietnamese  crypto trading platform ONUS sustained a large-scale cyberattack after threat actors exploited its payment system running on a vulnerable Log4j version. ONUS provides multiple applications for buying, selling, and managing cryptocurrencies. In an official release, the company stated unknown hackers illicitly accessed and stole certain critical corporate data.

“Through a security hole, a third party was able to gain unauthorized access to and steal certain critical ONUS data,” ONUS said.

Log4j or Log4Shell is a critical vulnerability found in the widely used Apache Log4j Library. The flaw allows hackers to run any code on vulnerable machines or hack into any application directly using the Log4j framework.

Log4j Flaw Exploited

The intrusion allegedly exploited the infamous vulnerability in a set of libraries on the ONUS system to penetrate the sandbox server, which contains the organization’s critical data. The flaw enabled attackers to access the data storage system (Amazon S3) and steal some essential data, exposing many users’ data to security risks. The compromised information includes user names, email addresses, phone numbers, addresses, KYC information, encrypted passwords, transaction history, and other encrypted information.

Also Read: Log4j Explained: How It Is Exploited and How to Fix It

Mitigation

While the actors behind the attack are unknown, ONUS stated it had engaged a  cybersecurity experts team to investigate the security incident. The company urged its customers to update their account credentials to prevent further damage immediately.

“To ensure our users’ safety, the ONUS team has actively worked with security experts to find vulnerabilities, thoroughly fix them, and implement additional methods to improve the whole system’s security. We also carried out an upgrade to the asset management and storage system (ONUS Custody). In addition, to limit the risks that may be encountered in the future, please change your ONUS application password,” ONUS added.

Also Read: Scammers Force Victims to Use Crypto ATMs and QR Codes

Crypto Platforms on Hackers’ Radar

Cryptocurrency exchanges and hot wallets continue to become a primary target for threat actors.  Recently, the cryptocurrency trading platform BitMart stated that it had sustained a large-scale security breach that affected its hot wallets on the Ethereum (ETH) blockchain and the Binance smart chain (BSC). The attackers reportedly stole cryptocurrencies worth over $150 Mn. Blockchain security and data analytics firm PeckShield claimed that the estimated loss would be around $200 Mn.

T-Mobile Reports Data Breach for the Third Time in 2021

T-Mobile data breach

It looks like T-Mobile is cursed to encounter frequent security incidents, affecting its customers’ sensitive information. After reporting a security intrusion in August 2021, the American telco giant reportedly again sustained a cyberattack that exposed users’ data and SIM details.

According to a report, unknown hackers accessed customer accounts to view customer proprietary network information (CPNI) or launch SIM swapping attacks.

Data Breach or SIM Swap  

The report stated T-Mobile customers either had their CPNI exposed or fell victim to a SIM swapping attack, or both. The CPNI information includes customers’ billing account names, phone numbers, number of lines on the account, account numbers, and mobile plan details.

What is SIM Swapping?

In a SIM swapping attack, cybercriminals call service providers and trick them into changing a victim’s phone number to an attacker-controlled SIM card. This allows the attacker to reset passwords and access victims’ sensitive data via bypassing users’ 2FA protection.

Customers Data at Risk

While there is no information on how many customers were affected by the incident, T-Mobile stated it had notified the impacted users.

“We informed a very small number of customers that the SIM card assigned to a mobile number on their account may have been illegally reassigned or limited account information was viewed. Unauthorized SIM swaps are unfortunately a common industry-wide occurrence. However, this issue was quickly corrected by our team, using our in-place safeguards, and we proactively took additional protective measures on their behalf,” T-Mobile said in a media statement.

One Telecom – Multiple Data Breaches

Unfortunately, this is not the first security incident for T-Mobile  this year. Recently, in August, that company confirmed an unauthorized intrusion that affected customers’ sensitive data. T-Mobile also suffered data breach incidents in February and March that exposed users’ data to various security risks. While T-Mobile did not reveal the details about the kind of data breached or the number of affected users, a report claimed that attackers obtained sensitive information related to over 100 million users from T-Mobile servers.

Earlier, the company also recommended a few mitigation tips to its customers, who are concerned about their private data being vulnerable; these include:

  • Monitor all your accounts to find any unauthorized/fraudulent activity. Don’t forget to report if you find any suspicious activity.
  • Use a credit monitoring service to ensure data privacy.
  • Do not respond to suspicious emails/messages received from unknown sources.
  • Change passwords of all your online accounts.

Constant security incidents could bring multiple and severe repercussions to organizations, such as losing customers’ trust and impacting brand value. Therefore, organizations must implement robust and continuous cybersecurity measures to mitigate security incidents.

How AL/ML is Driving Growth and Innovation in Cloud Forensics

Cloud Forensics

Enterprises are leveraging cloud infrastructure to modernize their processes, connect disparate services, and improve customer satisfaction rates. Up to 90% of the IT work can be automated using a Cloud platform, and with the inclusion of AI and ML, Cloud automation and forensics becomes increasingly efficient, reliable, and cheaper.

By Rakesh Sharma, VP – Cloud and Container Security at Standard Chartered Bank 

Enterprises relied on traditional IT systems before, but the Covid-19 pandemic ushered in an era of intensive digital transformation. Companies can no longer afford to stay behind when it comes to cloud technology adoption. But with an unprecedented move to cloud migration has exposed organizations to increased and new cyber threats. As the complexity of an enterprise grows due to its Cloud infrastructure business owners have to invest in additional hardware, software, power backup tools, and security solutions to ensure optimal business performance and continuity.

Banks, insurance companies, and hospitals rely on cloud computing to provide better services, and increase pace of their digital transformation. A distributed cluster of data centers that minimizes downtime ensures security and compliance and has military grade security infrastructure – this lays the foundation of Cloud computing systems.

How Cloud Computing Is Accelerating Innovation 

Cloud computing is changing the way data-driven management works in industry verticals and revolutionizes several sectors. Companies adopting Cloud are scaling more efficiently, growing in revenue, and experiencing tremendous success while reducing technology risks. Real-time capture of data and its analysis was not possible with traditional models. Still, cloud services can process vast volumes of data in real-time, which defines new opportunities for siloed business initiatives. Investors are seeing promising results with Cloud, and companies are generating up to triple-digit revenues. Snowflake’s IPO shares more than doubled from its initial public offering, and the company made an impressive $3.4 billion on the big day, which is a 112% colossal profit.

New Enterprise Cloud Priorities in 2021

COVID-19 shocked the world with significant disruptions, and as businesses prepared shift to cloud vendors, they failed to address how they’d adapt to future disruptions better than other players.

Cloud has enabled companies to be more Agile and play a significant role in shaping future technology trends in 2021 and beyond. The most relevant enterprise cloud priorities from this year onwards, as described by Gartner, are as follows:

Distributed Cloud Services – Big tech players open new data centers every year in different locations, and enterprises will be sourcing multiple cloud services from them. As we progress to the future, we will see increased adoption in numerous public cloud platforms and move to address critical issues faced regarding data latency, privacy, and security.

Hyper automation- Hyper automation connects multiple enterprises, disparate systems, and processes with the intent to automate all workflows. It improves uptimes and makes it easier to run cloud services faster. Business owners adopt Hyper automation to ensure that their systems comply with international standards, perform accurately, and stay error-free. With hyper-automation, edge computing fosters operational excellence, and UI automation is making it effortless for organizations to collate data, speed up transactions, and improve customer service response times.

Anywhere Services – Enterprises will make significant investments in designing anywhere data infrastructures so that they can access data real-time, anytime, and anywhere. Organizations are slated to lower long-term operational costs this way, become efficient, and improve business productivity as a whole.

AI and the Internet of Things (IoT) – Datapost, DevOps, and MLOps will work together to provide data resilience, scalability, and agility for SMEs and large-scale organizations. Tremendous innovation is being witnessed in application of AI over Hybrid cloud environment, where incident analysis and remediation are the top priorities for forensics analysts. IoT is disrupting various industry domains such as healthcare, manufacturing, supply chain, education, etc., and many industry players are building applications for both the IoT and Cloud. The combination of IoT and Cloud provides increased connectivity for businesses, expanded data storage possibilities, increased processing limits, and better cloud security. AI integrations with cloud platforms alleviate privacy concerns and ensure data is protected against several cyber threats.

Advantages of Adopting Cloud for Enterprises

Business surveys showed that the number of respondents adopting enterprise cloud solutions jumped to 92% in 2018. This figure has continued to grow over time meaning the total number of respondents in the population using public or private clouds is now 96%. Cloud technology is a great way to run business operations because of the various benefits it brings. Below is a list of the top benefits offered through the adoption of cloud platforms.

  • Faster deployments and reduced dependencies on on-site hardware
  • Seamless software updates, automatic integrations, and quicker service deliveries
  • Improved data security, reduced costs, and high-performance scalability
  • Unlimited storage capacity and seamless project collaborations
  • Excellent disaster recovery, mitigation, and backup planning

Challenges with Cloud Forensics

Cybercrime rates are on the rise, and while the increased adoption of cloud benefits businesses by providing infrastructures that are scalable, agile, and flexible, it also creates new attack surfaces for cybercriminals to take advantage of.

The following is a list of challenges professionals face with cloud forensics.

Vast volumes of data: Data is complex, and businesses are tasked with processing huge volumes when doing forensic analysis. Data can be ingested from multiple sources, and investigators have difficulty identifying, sorting through, and organizing enormous data record values.

Legal Compliance Issues: Legal systems and laws in many countries do not recognize forensic analysis as a legitimate source of cybercrime evidence. There is a lack of stronger data governance or regulations over cybercrime activities in several countries, making it a challenge to acquire justice.

Rise of anti-forensics techniques: Anti-forensics techniques work against forensics investigators and disrupt cyber crime scenes. It helps cyber criminals cover their tracks tracks, tampers evidence, and makes it challenging for professional investigators to uncover traces of the digital crime.

How AI Plays a Major Role in Cloud Forensics

Artificial Intelligence is the field where computer algorithms mimic human cognitive behavior and make intelligent decisions without needing any manual intervention. Machine Learning is a subset of AI and is routinely used in cloud platforms for automating various data management processes. Cloud forensics involves collecting and analyzing evidence needed to detect cybercrimes and make the collected information presentable to the court of law.

AI helps forensics professionals analyze evidence, reconstruct crime scenes, and ensure data integrity by providing no fakes or instances of duplication. Purdue researchers developed a cloud forensics model in 2019, which classified images and videos uploaded to cloud storage services like Google Drive and Dropbox. A StegnoCloud system used deep learning algorithms to report and flag illegal activities and collected evidence for forensics analysis. AI tools integrated with advanced technologies can automate various aspects of cloud forensics analysis and uncover data that is hard to acquire due to sophisticated data hiding techniques employed by cyber criminals. Businesses can now derive insights from their collected data, achieve innovations, and find out where they’re going wrong when it comes to securing the cloud, thanks to these advancements. Data needs to be managed and protected continuously; that means AI will play a vital role in ensuring information doesn’t stay underutilized and instead realizes its full potential. The top pioneer brands in the cloud forensics industry are FireEye, Paraben, Cisco Systems, Digital Detective, and Oxygen Forensics. With the increased demand for cloud computing, the global cloud forensics market is forecasted to grow at a CAGR of 13% from 2020 to 2027.

The market is further segmented according to user categories and forensics approaches such as mobile forensics, network forensics, and cyber forensics as cloud platforms are used by these tools and solutions. Financial institutions are already using digital forensics analysis techniques to study mobile devices, Smartphones, servers, and other endpoint devices to identify the risk of future data breaches. The Asia-Pacific region is growing fastest in this domain, and North America bought the most significant shares in 2020 throughout the world in cloud forensics industry.

Conclusion

Forbes predicted that there would be an 83% increase in cloud workloads by 2020, and it came to life. Modern enterprises have realized the benefits of cloud computing and are adopting it in a hybrid model by moving some workloads to cloud platforms and keeping the rest to their on-premises environment depending on business needs.

In the next few years, we will see some businesses will be born in cloud and others will migrate most of their infrastructure over cloud platforms to process massive volumes of data, which they couldn’t previously.

Cloud-based data mining will evolve due to advances in Artificial Intelligence and Machine Learning, which means customers can expect better insights from their data. As the technology landscape evolves, enterprise cloud computing will enhance security, ensures regulatory compliance, and bring better business outcomes, thus making AI and ML in Cloud Forensics all the more important.

About the Author

Rakesh SharmaRakesh Sharma is an experienced and excellent talented personnel in the cyber security & Fintech space by the Government and the Industry Bodies. He is a seasoned cyber security professional with comprehensive domain experience with the topmost security

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

References:

Researchers Uncover New Malware Campaign Spreading ‘Blister’ Payload

Malware and Vulnerability Trends Report, Mobile malware threats

Cybersecurity researchers from Elastic Security uncovered a new malware campaign exploiting valid code signing certificates to evade security defenses and deploy a novel malware loader dubbed Blister. The researchers stated the stealthy malware campaign leverages Blister payload to execute second stage malware payloads in memory and maintain persistence. In addition, the campaign also deploys Cobalt Strike and BitRAT payloads on the targeted networks. The identified malware samples have very low or no detections on VirusTotal.

“In one prevented attack, our malicious behavior prevention triggered multiple high-confidence alerts for Execution via Renamed Signed Binary Proxy, Windows Error Manager/Reporting Masquerading, and Suspicious PowerShell Execution via Windows Scripts. Further, our memory threat prevention identified and stopped BLISTER from injecting its embedded payload to target processes,” the researchers said.

Blister Malware

It’s found that the Blister malware campaign is using a valid code signing certificate issued by Sectigo. Threat actors can either steal legitimate code-signing certificates or purchase them from a certificate authority directly or through front companies. The researchers stated they’d notified the malware activity to Sectigo to take action and revoke the abused certificates.

Also Read: New Malware Discovered With Brazil’s Itaú Unibanco Bank App

“Executables with valid code signing certificates are often scrutinized to a lesser degree than unsigned executables. Their use allows attackers to remain under the radar and evade detection for a longer period of time. Once decrypted, the embedded payload is loaded into the current process or injected into a newly spawned WerFault.exe [Windows Error Reporting] process,” the researchers added.

Old Malware Variants Resurfaces

It has become common for malware authors to leverage old malware variants to create a new one. Recently, security experts from Pradeo uncovered a malicious mobile app available for download on Google Play, which more than 500,000 Android users installed. The malicious app, dubbed Color Message, reportedly infects the targeted devices with Joker malware. The application is suspected to be linked to  Russian servers.

The Joker malware, which first surfaced in 2017, is categorized as fleeceware. It was one of the most commonly infected types of Android malware used in carrying-out billing frauds and spying. It was extensively used in stealing SMS messages, contact lists, and device information. Since then, the Joker malware has been prevalent in several cybercriminal activities under various names.

Norwegian Media Company Amedia Exposed to a Serious Data Breach

Lapsus$ Impresa, Amedia data breach

Amedia, a leading Norwegian media company, was exposed to a serious data breach resulting in the disruption of its services.

In a news release, the company revealed that on the night of Tuesday, December 28, 2021, several of Amedia’s central computer systems were shut down. A significant data breach by third party threat actors impacted Amedia’s central computer systems. The extent of the damage is yet to be ascertained, and the company has taken measures to contain the attack.

“The production of online newspapers is going as normal, but no paper newspapers will be published on Wednesday, December 29, 2021. This is because systems for publishing paper newspapers, advertisements, and subscription management do not work as normal,” said Amedia.

Data Breach

The company, a victim of data breach, is still getting clarity on the attack. “We are in the process of gaining an overview of the situation, but do not yet know the full potential for damage. We have already implemented comprehensive measures to limit the damage and to restore normal operations as quickly as possible,” shared Executive Vice President of Technology, Pål Nedregotten.

Nedregoten further added that they had got their resources together to address the problem and assess the damage’s extent.

Per the release, the attack is limited to the systems managed by Amedia’s central IT company, Amedia Teknologi. Amedia’s other systems are working normally.

Adverse Consequence  

As the breach directly impacted the central systems, the company had to shut it down to contain the spread of the breach. Consequently, the publishing house, which publishes one of the leading newspapers, had to stop its print production.

“The situation means that no paper newspapers will be published on Wednesday and until the situation is resolved,” Nedregotten said.

This has had direct, acute impact on the business. Advertisers and subscribers have been affected, and Amedia is facing a loss of brand credibility in the industry. The company has not been able to provide clarify the extent of the breach. It is still unclear if subscribers’ and employees’ credentials and personal information have been compromised.

“So far, there is no reliable information that this has happened, but it cannot be ruled out that it has happened anyway. The subscription system that has been attacked contains the name, address, telephone number and subscription form, and history of the subscribers. Other data such as ID password, read history, and information about bank cards, etc. are not affected,” opined Nedregotten.

The nature of the attack is serious, and the company is taking cognizance of the attack and aims to resolve the breach with minimum data exposure.

Data-Rich Media Sector 

On June 3, 2021, American media company Cox Media Group (CMG) experienced a cyberattack in which the malicious threat actor encrypted the network servers and forced the systems to go offline.

Over 800 individuals were believed to have been impacted. Personal information exposed in the breach included names, addresses, Social Security numbers, financial account numbers, health insurance information, health insurance policy numbers, medical condition information, medical diagnosis information, and online user credentials. The attack also resulted in disruption of its live TV streaming and radio broadcasts streams. As a security measure, the company took down the systems to mitigate the further spread of the threat.

Per Darktrace, the volume of sensitive data in use in the media and entertainment industry has exploded in recent years. The amount of data generated in an hour today was similar to the amount of data created in a year during the 2000s, and the figures for streaming and virtual events only continue to rise. It reveals that the average cost of a data breach in the entertainment sector is $4.1 million. There has been an 800 % increase in ransomware attacks from 2019 to 2021 and a 630 % increase in cloud-based cyber-attacks between January and April 2020.

The numbers are startling and are only growing, both in terms of industry growth and cyberattacks.

Russian Court Slams Google And Meta with Hefty Fines

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

It seems that search engine giant Google and Meta, the parent company of Facebook and Instagram, will end 2021 on a bitter note after receiving hefty penalities from the Russian government. A Russian court reportedly penalized Google, 7.2 billion rubles (around $98.4 Mn), and Meta, 2 billion rubles ($27.2 Mn) for failing to remove banned content from its platforms.

The Tagansky District Court judged that Google repetitively neglected to delete content banned by local law. Russia’s privacy watchdog Roskomnadzor, also known as the Federal Service for Supervision of Communications, Information Technology, and Mass Media, stated that Google and Meta had violated data privacy laws by distributing banned content promoting extremist ideology and insulting religious beliefs. The agency revealed that Facebook and Instagram have failed to remove 2,000 data items, and Google has failed to delete 2,600 such items.

Restrictions on internet usage and other online products are quite common in Russia. According to a report, the country banned the Tor web anonymity services and six virtual private networks (VPN) operators for allowing citizens access to illegal content.

Multiple Fines on Google

Google encountered multiple penalties this year. Recently, the Italian Antitrust Authority fined Google Ireland Ltd. and Apple Distribution International Ltd. €10 million ($11.26 million) each, citing aggressive data practices. The agency stated that both companies had violated the Consumer Code practices during customers’ data acquisition and commercial use.

Google has been fined again for misusing the online advertising space. According to a report, the French Competition Authority (FCA) fined Google €220 million (approximately $268 million) for abusing its dominant position in the advertising market and favoring its services at the expense of its competitors. The penalty comes after three media groups, News Corp, French daily Le Figaro, and Belgium’s Groupe Rossel charged Google with an anti-trust lawsuit for misusing its position over ad sales for unfair digital advertising practices.

How to Generate CISO Buy-In For Active Directory Protection

CEO, cybersecurity, CISO, Future of the CISO

Generating CISO buy-in for Active Directory Protection ranks high in a company’s success against ransomware attacks. Active Directory (AD) sits at the heart of almost every enterprise network, with more than 90% of businesses using it as their identity management system. It serves as the central repository for identity information, including credentials, user accounts, individual devices, applications, and more, making it incredibly important—and an obvious target for cybercriminals.

By Carolyn Crandall, Chief Security Advocate, Attivo Networks

Despite this, AD isn’t always front-of-mind for organizational decision-makers. AD isn’t something most executives consider a major concern—it’s something they expect to work. However, Microsoft once estimated that more than 95 million AD accounts come under attack every day—and that number has almost certainly grown. New research conducted by Enterprise Management Associates (EMA) further indicates that 50% of organizations studied experienced an attack on AD within the past one or two years. Attackers know that gaining control of AD is a kingpin; they can see that AD is vulnerable, targeting it with increased frequency. For organizations that wish to remain secure, it is time to elevate AD security to not only a CISO-level concern but one that executives review in the context of business continuity and company welfare.

Active Directory Protection Challenges

Because Active Directory is responsible for authentication throughout the enterprise, every identity within an organization needs to connect to AD somehow. AD needs to be accessible—which is a significant reason it is intrinsically insecure. Credential theft is an increasingly common attack tactic among today’s attackers, and just one stolen, exposed, or weak password can open the door to exploiting Active Directory. This year’s Verizon Data Breach Investigations Report (DBIR) indicates that 61% of all breaches now involve credential data, and attackers often use those valid credentials to circumvent perimeter defenses.

Using valid credentials helps attackers avoid setting off the usual alarm bells. They will almost always leverage that advantage to move laterally throughout the network to identify valuable data to steal or encrypt. They will almost always target AD to acquire additional admin-level credentials that will allow them to escalate their privileges and expand the scope of their attacks. And unfortunately, once an attacker has compromised AD, they can erase their tracks and become extremely difficult to remove from the system. They will essentially have the keys to the castle.

The consequences that stem from the exploitation of Active Directory are broader than many realize. A major breach or loss of domain control can have substantial downstream effects, whether the attacker is a cybercriminal running a ransomware attack, a nation-state threat actor conducting espionage, or an activist interfering with business. Think of it this way—if an attack disrupts a manufacturing line, it may be bad, but it’s fixable. That same attack might also disrupt shipping, purchasing, and other areas that can grind business to a halt, not just for one enterprise but also for the partners and customers that rely on it.

Think about the implications of one component shortage and how it could stop the assembly line on a car, a refrigerator, or computer. Worse still, in areas like utilities and critical infrastructure, security failures can and have put lives at risk. For proof, look no further than the Oldsmar, FL water system attack or recent Ponemon research indicating that ransomware-related shutdowns in the health care industry directly impact patient safety, data, and overall care availability.

The Cost of Poor Active Directory Protection

The threat of a breach concerns every organization, and most have made strides in improving their preparedness related to security hygiene and posture management. However, given the implications, the relative lack of focus on AD is a problem that needs addressing. Regulatory and compliance standards are undoubtedly moving in this direction, but they are currently vague about what it means to “protect data and personal information.” Other advisory bodies have been much more direct in their recommendations, like the National Institute for Standards and Technology (NIST) and MITRE.  Both have issued guidance for organizations to help them specifically protect AD—and no one should be surprised when governments begin to follow suit.

Cyber insurance is another fast-growing industry, and insurers closely monitor developments within the threat landscape. Cyber insurers want to ensure that their clients take reasonable precautions to protect themselves from risk, as with any insurance company. With 61% of attacks involving credential data, they will be reticent to issue payouts to organizations that have not taken the appropriate steps to protect themselves. Insurers today almost always mandate using multi-factor authentication (MFA), but it is not enough. With credential-based attacks continuing to rise, cyber hygiene and posture management will need to expand identity security to defend against credential misuse or privilege escalation and protect directory services management systems like Active Directory.

These factors can significantly impact an enterprise’s risk profile and, ultimately, their coverage. Cyber insurance is a must in today’s threat environment, and the potential for regulatory action will only loom larger as the issue of credential-based attacks continues to grow. With Active Directory now a priority target for attackers, organizations that do not prioritize the visibility needed to assess and measure AD vulnerabilities accurately could find themselves in hot water. The days of periodic audits and log monitoring are over—they are no longer enough. Today’s organizations need to identify exposures and misconfigurations related to credentials and AD continuously and in real-time—anything less, risks the enterprise being dangerously exposed to attackers and regulatory and liability concerns. Thus, making Active Directory Protection an area of interest for businesses and threat actors alike.

CISO Support Is Critical

Now more than ever, organizational leaders need to elevate cybersecurity to a Board-level discussion.  This conversation must go beyond user and device hygiene and expand into protecting credentials, privileges, and the Active Directory systems that manage them. Ransomware is clearly on every company’s list of top concerns, and they need to understand that its continued success is a result of Active Directory-related exposures. CISOs can help connect the dots by improving cyber hygiene and reducing risks, taking steps including controlling privileged credentials, gaining visibility into when privileged accounts get used, and ensuring that detection for live attacks on Active Directory is in place.

About the Author

Carolyn CrandallCarolyn Crandall is the Chief Security Advocate at Attivo Networks, the leader in preventing identity privilege escalation and detecting lateral movement attacks. She has worked in high-tech for over 30 years and has been recognized as a top 100 women in cybersecurity, a guest on Fox News, and profiled in the Mercury News. Carolyn also co-authored the book Deception-Based Threat Detection: Shifting Power to the Defenders. She is an active speaker on security innovation at CISO forums, industry events, and technology education webinars.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.