Home Blog Page 263

NATO – EU Top Brass Meets, Reviews Joint Cyber Defense Strategies

NATO-EU-Cyber-Defense

The top brass from NATO and the European Union met in Brussels at the NATO-EU Alliance headquarters to review and discuss its joint cyber defense strategies. Back in February 2016, NATO and the European Union (EU) signed a Technical Arrangement of cooperation on Cyber defense. Cyber defense is an integral part of NATOs core defense strategy and this agreement strengthens the cooperation of all Allies (29 countries) in areas covering cyber defense through information exchange, training, research and exercises.

By Mihir Bagwe, Tech Writer, CISO MAG

In July 2016, the Allies gave a thumbs-up to NATO’s defensive mandate and took a Cyber Defense Pledge. It now recognizes the cyberspace as a domain of operations in which NATO Allies should actively defend itself as it does in the air, land and sea. All Allies echoed a response by upgrading their cyber defenses and sharing information to prevent, mitigate and recover from cyber-attacks.

Since then, NATO’s Allies have benefited immensely from a norms-based, predictable and secure cyberspace. “Over the last (few) years NATO and the EU have intensified their engagement on cyber. We exchange real-time information between incident response teams, participate in each other’s exercises, and work on training and research,” said Dr. Antonio Missiroli, NATO’s Assistant Secretary General for Emerging Security Challenges.

The recent meeting that concluded in Brussels saw the security heads of the Allies have a healthy discussion and exchange of thoughts in matters related to the security of next-gen networks and system infrastructures. The other agenda included ways to enhance cyber defense and incidence response strategies in times of emergency.

“The EU welcomes the overall progress we have achieved on the implementation of the common actions in cyber security and defense. We must keep the tempo, while further deepening our cooperation in the framework of the two Joint Declarations. Coordination on cyber security and defense is at the heart of this strategic partnership,” said Pawel Herczynski, Managing Director for Common Security and Defence Policy and Crisis Response at the European External Action Service.

A Technical Arrangement on Cyber Defense was concluded between the NATO Computer Incident Response Capability (NCIRC) and the Computer Emergency Response Team for the EU Institutions, bodies and agencies (CERT-EU).

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

U.S. Senators Introduce an Act to Safeguard K-12 Schools

California Consumer Privacy Act

K-12 district schools have been a soft target for cybercriminals in the year gone by. To address the rising threat prospective, two U.S. Senators, Gary Peters (D-Mich.) and Rick Scott (R-Fla.), both members of the Senate’s National Security and Government Affairs Committee have tabled a new bill called the “K-12 Cybersecurity Act”.

As per a report shared on the K-12 Cybersecurity Resource Center, 119 cybersecurity incidents were recorded in U.S. K-12 schools. The findings also suggest that ransomware attacks have been a hot favorite. Another independent study from Kaspersky indicates that ransomware attacks targeted towards K-12 schools have risen by 23 percent.

Emsisoft, an anti-malware and anti-virus service provider has shared interesting facts in a recent survey. A key highlight of the report states that there were at least 86 universities, colleges and school districts impacted, which in turn disrupted operations of around 1,224 individual schools. The report also shared a list of top three incidences of public schools being affected by ransomware attacks:

  1. Louisiana public schools: In July, Louisiana Governor declared a state of emergency after three public school districts fell victim to ransomware. A State of Emergency was re-invoked in November when another ransomware attack affected 10 percent of Louisiana’s 5,000 network servers and more than 1,500 computers.
  2. Rockville Centre School District: On July 25, Ryuk ransomware hit Rockville Centre School District. The district’s insurance carrier negotiated the ransom demand of US$176,000 down to US$88,000 which was covered by them.
  3. Las Cruces Public Schools: In late October, a ransomware attack infected thousands of servers and devices in Las Cruces Public Schools, in New Mexico. The district disagreed to pay the ransom and instead ended up reformatting close to 30,000 devices. Las Cruces Public Schools has been attacked three times in the past six years.

The effects of such attacks on educational institutions regards loss of personal information, including student grades and qualifications, teacher employment and payroll information, family records and medical health records.

The K-12 Cybersecurity Act has been introduced to address these risks. This Act directs the DHS Cybersecurity and Infrastructure Security Agency (CISA) to first study the specific cybersecurity risks associated with K-12 educational institutions. Once the study is done, CISA will then be responsible to develop cybersecurity recommendations and set up online tools to help schools with their cybersecurity requirements.

“Schools across the country are entrusted with safeguarding the personal data of their students and faculty but lack many of the resources and information needed to adequately defend themselves against sophisticated cyber-attacks,” said Senator Peters. “This commonsense, bipartisan legislation will help to ensure that schools in Michigan and across the country can protect themselves from hackers looking to take advantage of our nation’s cybersecurity vulnerabilities.”

“The safety of our schools is always my top priority, and that includes protecting the information of our students and teachers,” said Senator Scott. “I’m proud to sponsor the K-12 Cybersecurity Act of 2019 to further protect our schools, students and educators, and give them the resources they need to stay safe.”

Marc Egan, Director of Government Relations, National Education Association lauded the efforts put in by the two senators. He said, “We applaud Senator Peters and Senator Scott for introducing the K-12 Cybersecurity Act of 2019, which will help prevent hundreds of cyber-attacks on our schools each year. An assessment of risks and specific, tangible guidelines on how best to protect our school networks from being taken hostage will help our educators prevent such interruptions to teaching and learning and protect sensitive student data.”

Vodafone Idea and IBM Jointly Launches “Secure Device Manager”

vishing attacks

Vodafone Idea Business Services (VIBS), the enterprise arm of Vodafone Idea Ltd. (VIL), announced the launch of Vodafone Secure Device Manager (VSDM) by collaborating with IBM.

According to the partnership deal, VIBS will leverage IBM Security MaaS360, a comprehensive Unified Endpoint Management (UEM) platform, to deliver an AI approach to UEM to enable endpoints and end-users. The Vodafone Secure Device Manager platform is designed to secure emails, protect devices containing company data used for automating the field sales force, and securing company data and apps on Bring Your Own Device (BYOD) scenario, all while respecting the personal privacy of the employees.

Vodafone Idea claims that VSDM will help companies with a wide array of functionalities like containerization, secure access to company apps, ability to push policies, control access to apps while at work, provide content that employees need to be productive while maintaining data security and personal privacy.

It also stated that the VSDM platform is flexible and can be customized as per the company’s security policies with the option of different policies for different employee profiles. The platform provides AI insights and contextual analytics, capabilities to proactively defend against malware and other threats, Single Sign On (SSO) to Web & SaaS Apps on devices, and Business Dashboard for Apps.

Commenting on the Secure Device Manager launch, Anil Philip, EVP- Products, Solutions, and Partnerships, Vodafone Idea said, “Our strength lies in providing Enterprise mobility solutions which is the key for promoting digital workplace. The rising trend of BYOD and increased security threat of data stored in the cloud and transferred over networks highlights the need for a product like VSDM. It will enable organizations to be more productive by ensuring flexibility and mobility to its employees without having to worry about data safety. We are happy to partner with IBM to offer VSDM to support our enterprise and small business customers in their endeavor for data security and digitalization.”

“Thousands of enterprises worldwide rely on IBM Security MaaS360 as the foundation for their mobile initiatives. VSDM, powered by IBM Security MaaS360, helps organizations to increase employee productivity, by optimizing the functionality and security of mobile devices within the enterprise, while simultaneously protecting the corporate network. Further, with AI capability, companies will be empowered to manage malware and get proactive threat management.  Vodafone Idea Limited’s reach and expertise coupled with IBM’s proficiency in data security can be leveraged to help enterprises secure their devices, prevent malware and permit seamless scalability,” said, Vaidyanathan Iyer, Security Software Leader, IBM India South/Asia.

Hackers Using Process Hollowing for Monero Mining

Process hollowing

Researchers at Trend Micro have observed a new technique called Process Hollowing that is used for Monero Mining. It has been implemented by hackers since early November and geo-targeted towards users mainly in Kuwait, Thailand, India, Bangladesh, the United Arab Emirates, Brazil and Pakistan.

Along with Process  Hollowing, this technique also drops another file that acts as a container. This dropper file, on its own is of no use and its malicious nature remains hidden unless a specific set of command line arguments are used to trigger it. Researchers say, “The dropper is a 64-bit binary containing a packed malicious code, and we found the executable checking the arguments passed to it and verifying it upon unpacking.”

They further found that the infection routine is divided in two stages. The first stage of infection involves an arithmetic operation on alphanumeric strings. “This is used to decrypt the information from the arguments including the cryptocurrency wallet address of the cybercriminals specified as part of the required arguments sent to trigger the malicious file and enable the coinmining activity.”

In the second stage, once the correct arguments are executed, the dropper then executes a child process called wakecobs.exe. The dropper further injects the malicious code into the miner which runs undetected in the background.

Researchers have coined this technique as highly dangerous as “the dropper evades manual scanning and detection by injecting the malicious code in a dropped file, and hiding itself in a different directory without an extension.” This malicious process hollowing cryptomining technique also goes undetected from whitebox, sandbox, and blackbox analysis, thus making it more difficult for IT security teams to find these dropper files.

Earlier, Trend Micro had also reported a sudden rise in a fileless attack technique better known as a zero-footprint attack or non-malware attack. This method of attack does not install any malicious software on a user’s computer, instead it exploits applications that are already installed in the device.

Trend Micro stated that cybercriminals are using increasingly sophisticated attack formats that aren’t visible to traditional security procedures and thus requires constant manual and proactive monitoring on the part of the IT security team of respective organization.

Digital Transformation of Indian Organizations’ Hindered by Cyber-Attacks

Digital Transformation

The digital transformation journey of Indian organizations is getting increasingly hindered by cyberattacks, according to a recent study.

The survey, jointly conducted by cybersecurity firm Forcepoint and IT analyst firm Frost & Sullivan, revealed that 95 percent of organizations have embarked on a digital transformation journey. It also stated that 61 percent of respondents stated that the risk of cyber-attacks is delaying their digitalization progress.

According to research findings, 46 percent of organizations, that begun executing their digital transformation projects, encountered a security incident and 20 percent of the organizations didn’t conduct breach assessment in the last 12 months. The report also highlighted that only 18 percent of respondents thought about cybersecurity at the early stages of the digital transformation projects.

“It’s clear from this study that many APAC organizations are on the back foot when it comes to enterprise cybersecurity in the borderless organization,” said Kenny Yeo, Industry Principal, APAC ICT, Frost & Sullivan. “Security leaders need to look beyond perimeter security, leverage automation, and have a better grasp of the psychology of both cybercriminals and their business users. Incorporating behavior modelling into their IT security architecture is certainly a way to identify potential risks and fend off cyberattacks.”

Rise of Data Breaches

The study found that 69 percent of Indian organizations are at risk from cyber-attacks where 44 percent of them have encountered data breach before.

Banking, Financial Services and Insurance (BFSI), IT services, and Business Process Outsourcing (BPO) services emerged as the top sectors to perform regular breach assessment to ensure there was no security incident in the company.

“Organizations today need to urgently embrace “secure-by-design” into their digital transformation projects. Adopting a behavior-centric security approach that focuses on understanding users’ behavior on the network and within applications to identify behavioral anomalies can mitigate cyberattacks before they happen,” said Alvin Rodrigues, senior director and security strategist at Forcepoint Asia Pacific.

Google Cloud Partners with Multiple Firms to Boost Cloud Security

Google Cloud, Google Cloud Confidential Computing

Google recently announced multiple strategic partnerships and security partner integrations to further advance its cloud security capabilities for its cloud computing services platform, Google Cloud.

Speaking on the new initiative Kevin Ichhpurani, VP of the Google Cloud Global Ecosystem and Sunil Potti, VP of Engineering at Google Cloud Security said, “We understand that many customers have dedicated tools and strategic relationships with the industry’s leading security vendors. We want to meet you where you are, allowing you to preserve your investments, as well as benefit from the functionality you can’t get on other clouds. That’s why we work closely with partners in the security industry to help you better secure your applications and information.”

According to reports, Google Cloud is introducing a new solution to help customers manage the deployment of agent-based endpoint security and vulnerability management solutions—through collaborating with McAfee and Palo Alto Networks.

Palo Alto Networks will expand its services on Google Cloud to jointly develop new solutions for open application modernization platform Anthos. McAfee will integrate its MVISION Cloud solution for data security, threat prevention, governance, and compliance capabilities for container workloads with Google Cloud.

The Other Partnerships Include:

  • By collaborating with Citrix Systems, Google Cloud makes Citrix’s Workspace available for its customers. The partnership integrates Citrix’s remote access tool with G Suite to provide a single sign-in experience, multi-factor authentication, and enhanced security policies for G Suite users.
  • Exabeam, a cybersecurity and security information event management (SIEM) company, will expand its SaaS Cloud security management platform on Google Cloud. This helps customers bring the scale and speed of the cloud to their existing SIEM platform.
  • ForgeRock joins Google Cloud as a Premier Partner in the identity space for its cloud-native suite of identity products. The partnership with the ForgeRock platform helps customers build and maintain cloud-ready architecture to automate multi-cloud deployments and deliver a Digital Identity Platform on Google Cloud.
  • An alliance with Fortinet enables customers to connect facilities to Google Cloud with secure SD-WAN solutions. Fortinet integrates its FortiCWP service with Google Cloud Security Command Center.
  • A new collaboration with Semperis and STEALTHbits to enable customers to manage, audit, and protect their Microsoft Active Directory-dependent apps and workloads running on Google Cloud.

 Expanding Active Partnerships:

Google Cloud also announced that it’s expanding existing partnerships to simplify implementation and management activities. The company is extending its active deals with existing systems integrators and security services providers, which include:

  • Arctic Wolf is making its security operations center (SoC)-as-a-service available to Google Cloud customers
  • Security systems integrator Comm-IT extends its support to Google Cloud customers by providing a unified view of security risks across cloud deployments
  • Deloitte is launching new cyber-attack risk mitigation services.
  • IBM Security provides consultancy services to Google Cloud customers.
  • Wipro is going to offer new security services for Google Cloud platform
  • Cyderes is going to work with the Chronicle’s Backstory tool
  • Optiv extends its partnership deal with Google Cloud to deliver new solutions to reduce security risks as customers move to the cloud.

LifeLabs Pays Ransom to Recover 15 million Users Data

Ransomware Attacks, Graff ransomware attack

LifeLabs, a Canadian laboratory testing and diagnostics services provider, reported of a Ransomware attack to the Office of the Information and Privacy Commissioner of Ontario (IPC) and the Office of the Information and Privacy Commissioner for British Columbia (OIPC) on November 1, 2019.  Under careful monitoring and expert advice from top cybersecurity , LifeLabs finally bowed down and paid an undisclosed ransom amount to regain access to its 15 million customers’ personal data and close to 85,000 Laboratory Test Results.

LifeLabs confirmed that they were subject to an attack affecting the personal information of customers based mainly in the states of Ontario and British Columbia. The compromised customer data included personal information such as names, addresses, emails, usernames and passwords, health card numbers, and lab tests.

“An attack of this scale is extremely troubling. I know it will be very distressing to those who may have been affected. This should serve as a reminder to all institutions, large and small, to be vigilant,” said Brian Beamish, Information and Privacy Commissioner of Ontario. “Cyberattacks are a growing criminal phenomena and perpetrators are becoming increasingly sophisticated. Public institutions and health care organizations are ultimately responsible for ensuring that any personal information in their custody and control is secure and protected at all times.”

Although the stolen data was dated before 2016, a data breach this big cannot be dusted under the carpet. Taking complete responsibility of this lapse, Charles Brown, LifeLabs President and CEO said, “Personally, I want to say I am sorry that this happened. As we manage through this issue, my team and I remain focused on the best interests of our customers. You entrust us with important health information, and we take that responsibility very seriously.”

He emphasized “that at this time, our cybersecurity firms have advised that the risk to our customers in connection with this cyber-attack is low and that they have not seen any public disclosure of customer data as part of their investigations, including monitoring of the dark web and other online locations.”

LifeLabs also said that they have taken all required and prescribed remedial measures to patch the flaws in the affected systems and their corresponding networks. In addition, they have also agreed to provide cybersecurity protection services such as identity theft and fraud protection insurance to all its affected customers.

Vulnerability Found in TP-Link’s Archer Routers, Now Fixed

Home Routers for botnets

TP-Link’s Archer Router series which is capable of handling high-speed online traffic had a vulnerability that if exploited, could allow hackers to bypass the admin passwords and remotely take control of the devices.

This vulnerability (now tracked as CVE-2019-7405) was first discovered in TP-Link Archer C5 (v4) routers. Grzegorz Wypych, a Senior Security Consultant at IBM X-Force Red said, ” This is a zero-day flaw that was not previously reported and can affect both home and business environments. If exploited, this router vulnerability can allow a remote attacker to take control of the router’s configuration via Telnet on the local area network (LAN) and connect to a File Transfer Protocol (FTP) server through the LAN or wide area network (WAN).”

The vulnerability could be exploited by simply sending a character string longer than the allowed number of bytes through an HTTP request. This is also known as Password Overflow. The built-in validation checks the referrer’s HTTP headers; this tricked the TP-Link routers into believing that it is a valid HTTP request, making the password void and replacing it with an empty value.

Few of TP-Link Archer routers had only admin access with root privileges. Since it is the only access level, all processes are run by the user under this access level, thus allowing an attacker to operate as admin and hijack the device completely. It was also observed that the RSA encryption keys failed since they don’t work with empty passwords.

“The risk is greater on business networks where routers such as this can be used to enable guest Wi-Fi. If placed on the enterprise network, a compromised router can become a point of entry to an attacker, and a place to pivot from in recon and lateral movement tactics,” explained Grzegorz.

In such a hostile complete device takeover, attackers not only attain privileged access but also lock-out the legit user from using the web services. Thus, TP-Link was very quick to fix this critical vulnerability and release patches for the Archer C5 V4, Archer MR200v4, Archer MR6400v4, and Archer MR400v3 routers to help its customers protect themselves against such cyberattacks.

6 Simple Moves to Respond to a Ransomware Attack

Numerous companies and state governments have been plagued by ransomware attacks, which are now more common than ever. Unlike other cyber threats that usually go unnoticed for long periods, a ransomware attack is experienced immediately, and its impact is often destructive.

Unfortunately, the recovery plans from a ransomware attack are quite limited. The two available options: pay the ransom or move to a disaster recovery mode to restore infected systems. However, one cannot be certain if the decryption key provided by the hacker, after paying the ransom, would serve its purpose.

So, most organizations opt to pay the ransom. This is might be due to lack of proper data backups–or the hackers may have also encrypted the back-ups!

Microsoft stated: “We never encourage a ransomware victim to pay any form of ransom demand. Paying a ransom is often expensive, dangerous, and only refuels the attackers’ capacity to continue their operations; bottom line, this equates to a proverbial pat on the back for the attackers. The most important thing to note is that paying cybercriminals to get a ransomware decryption key provides no guarantee that your encrypted data will be restored.”

Microsoft said every organization should treat a security incident as a “matter of when” it occurs and not “whether” it will happen. The tech giant also summarized few steps intended to help companies better plan and prepare to respond to cyber incidents:

  1. Use an effective email filtering solution
  2. Regular hardware and software systems patching and effective vulnerability management
  3. Use up-to-date antivirus and endpoint detection and response (EDR) solution
  4. Separate administrative and privileged credentials from standard credentials
  5. Implement an effective application whitelisting program
  6. Regularly back up critical systems and files

In its recently released 2019 Cybersecurity Trends report, Microsoft highlighted that phishing was one of the attack vectors that was rising over the past two years. “In 2019, we saw phishing attacks reach new levels of creativity and sophistication,” Microsoft said.

Microsoft reviewed three of the intelligent phishing attacks it had seen in 2019, which include: Hijacking Search Results, Customized 404 Not Found Pages, and Man-in-the-Middle Phishing.

New Orleans Declares State of Emergency After Ransomware Attack

Ransomware attacks, ransomware, Sinclair Broadcast group

New Orleans, a city in Louisiana, is the latest victim of a cyber-attack. The city declared a state of emergency and shut down its computer and network systems after detecting suspicious ransomware and a flood of phishing emails.

The officials stated that currently, it’s unclear if the ransomware compromised any computers. According to Mayor LaToya Cantrell, there is no ransom requests from attackers or evidence of employees being tricked into handing over sensitive data or login credentials.

The incident affected multiple services in New Orleans like Municipal courthouses and the city’s Healthcare for the Homeless, according to Mayor LaToya Cantrell. It’s said that most employees at government agencies were using their Gmail accounts to handle some requests, as the city’s email server was taken offline.

Ryuk Ransomware Likely Behind the Attack

Colin Cowie, researcher and founder of cybersecurity research firm Red Flare Security, stated that Ryuk Ransomware might be behind New Orleans attack. Cowie stated that he observed similarities of Ryuk ransomware on the affected computer systems.

Numerous local and state governments have been plagued by ransomware attacks in recent times. The Louisiana state government fell victim to a ransomware attack for the second time this year. John Bel Edwards, Governor of Louisiana, revealed that a ransomware infection had taken down the government’s IT systems and websites.

John Bel Edwards stated the attack impacted the public state government’s email, website, and other online applications. According to official reports, the attack affected websites for the Office of the Governor, Louisiana State Legislature, Office of Motor Vehicles, Department of Corrections, the Louisiana Division of Administration, and the Department of Transportation & Development.

Earlier, John Bel Edwards issued a state of emergency after a wave of ransomware attacks affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware.