Home Blog Page 268

FBI Defines FaceApp as Counterintelligence Threat

apple face id

FaceApp, the AI-powered photo-morphing app that took the internet by storm for its unique features and controversial privacy policy has hit the headlines again.

The FBI recently slammed FaceApp as a counterintelligence threat and advised its users to be vigilant.  The comments come after the U.S. Senator Chuck Schumer wrote to the FBI and the U.S. Federal Trade Commission (FTC) stating concerns over FaceApp in July this year.

“A warning to share with your family & friends. This year when millions were downloading #FaceApp, I asked the FBI if the app was safe. Well, the FBI just responded. And they told me any app or product developed in Russia like FaceApp is a potential counterintelligence threat,” Chuck Schumer tweeted.

In its investigation report released on November 25, the FBI revealed the risks posed by the Russian-made face-editing application. The FBI stated that not only FaceApp but other mobile applications developed in Russia may also cause a potential counterintelligence threat.

In its letter to Chuck Schumer, the FBI said, “It considers any mobile application or similar product developed in Russia, such as FaceApp, to be a potential counterintelligence threat”.

It’s said that Russia’s intelligence services maintain robust cyber exploitation capabilities to remotely access all communications and servers on Russian networks.

FaceApp, which launched in 2017, rise to fame in 2019 with its #AgeChallenge viral movement. Millions have uploaded their photos of future aged versions using the application.

The mess began after several experts and users finally read the terms and conditions of the app. Over user content, it reads, “You grant FaceApp a perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully-paid, transferable sub-license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content, and any name, username, or likeness provided in connection with your User Content in all media formats and channels now known or later developed, without compensation to you.”

Recently, security pros found that FaceApp collecting the list of users’ Facebook friends unnecessarily. According to an Indian security researcher Athul Jayaram, who flagged the issue, the app contains a feature that allows users to download and edit photos from their Facebook accounts. However, this option will only work when a user accesses the FaceApp account via “Login with Facebook” option.

Jayaram said whenever a user logs in to FaceApp with Facebook credentials, the app enables a feature called “Social Stylist,” designed to allow users to invite their Facebook friends to vote for their posts. However, the researcher clarified that the feature was discontinued after reporting the issue to FaceApp.

Gun Buyback Scheme of NZ Police Leaks 37,000 Citizens’ Data

Ransomware Attack on Azusa Police

The New Zealand Police have admitted a potential data breach on its online notification platform set up to buyback firearms.

The issue came into light after a dealer reported to the Police that he was able to see all firearm owners’ details on the gun buyback program website. The Deputy Commissioner of Police Mike Clement confirmed that they were notified about the breach by the dealer.

The details of around 37,000 firearm owners, including the guns they possess, and bank account information were accessible, the Council of Licensed Firearms Owners (Colfo) stated.

Under the firearm buy-back program, the government provides an opportunity for the citizens to let the police know their prohibited firearm possessions anonymously and exchange them for cash.

What Happened?

The online notification platform is maintained by a German-based software company SAP. The company stated that a new security profile was incorrectly provisioned in the platform due to a human error.

“We unreservedly apologize to New Zealand Police and the citizens of New Zealand for this error. A full internal investigation is already underway within SAP,” the company said in a statement.

It’s said that users were able to screenshot and download information related to other firearm owners. Security pros opined that criminal elements could have accessed the firearm owner’s information before the authorities found the breach.

The Police authorities stated that they’ve launched an investigation to identify how many people accessed the personal details of the gun owners in the incident.

Meanwhile, the Gun buybacks program is continuing using manual processes. The Police stated that the platform will remain offline until SAP ensures its security. The officials also urged affected citizens to monitor their bank accounts to find out any unusual transactions.

Just Another String

Earlier, the New Zealand Treasury office was hit with a cybersecurity scandal. It’s reported that hackers tried to infiltrate the documents of the upcoming budget, which has also been called the “wellbeing budget”.

The budget has been the limelight for being a bill that has been one of the first in the world where the wellbeing of citizens of New Zealand has been kept at the top-most priority. Two days before the document was scheduled to be released, the Treasury office found out that the systems were hacked with over 2,000 attempts recorded in a 48-hour period. The New Zealand police have been alerted over the incident that has occurred in the parliament, and investigations have begun into the incident.

Canon Medical Unveils a Multi-Level Cybersecurity Solution

Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial

The Healthcare industry has constantly been in the firing line of hackers for quite a few years now. The reason behind the following limelight is the worth this data carries on the darker side of the web. Canon Medical has now decided to counter this issue and carry the mantle of cybersecurity in the Healthcare domain by unveiling a new multi-level cybersecurity solution, Gateway Platinum.

Canon has made this solution available to its existing and new customer suites with a premium service plan. What’s so premium about it though? It provides healthcare givers the ease of live monitoring, proactive and predictive technologies and a 24/7 support from Canon Medical’s cybersecurity risk management team.

If you are still curious to know more, following are the three premium features of Gateway Platinum:

  • Barracuda NextGen Firewall Protection: It helps prevent malicious attacks from bad actors with a NextGen firewall and Intrusion Prevention System (IPS). It provides real-time notifications with on-demand reports and network health alerts. A continuous data feed is given to customer’s security information and event management (SIEM) system, and correspondingly an alert engine notifies the customer and Canon Risk Management team of the attacks.
  • InnerVision® Plus with Windows 10: This helps in increasing productivity, boost system availability and isolate healthcare facilities imaging systems from outside threats before data can be damaged or exposed with proactive and predictive remote support. Streamline system cleanup, and troubleshoot devices with data analysis capabilities, on-demand system diagnosis, prevention and early detection alerts, and environmental monitoring status including temperature, humidity and helium levels.
  • Secure VPN to Canon Medical Control Center: Canon Medical provides a secure site-to-site VPN tunnel with multi-factor authentication (MFA). It uses the highest encryption standard for secure data transfers between site(s) and the Canon Medical Control Center.

Canon acknowledges the cybersecurity concerns of the present day. Dominic Smith, Vice President, Service Field & Sales at Canon Medical Systems USA, Inc. echoes the same thoughts by saying, “Our customers are faced with keeping patient information secure, while seamlessly sharing critical clinical information across the systems and networks – it’s a complex challenge. We had these complexities in mind as we designed Gateway Platinum – a sophisticated cybersecurity solution with multiple layers of protection. The new offering gives our customers peace of mind that their systems, network and patient information are secure, and a well-trained risk management team is available to help withstand an attack.”

Researchers Find Vulnerabilities in Autodesk, Trend Micro, Kaspersky Software

Hackers Exploiting Cisco’s ASA/FTD Software to Steal Data

Researchers from the security firm SafeBreach Labs recently disclosed multiple security vulnerabilities in Autodesk, Trend Micro, and Kaspersky software. The company published three different security advisories, describing the issues, to report to the vendors before public release.

According to SafeBreach Labs, the vulnerability, tracked as CVE-2019-15628, effects Trend Micro Maximum-Security version 16.0.1221 and below software components.

The researchers stated that the lack of safe DLL loading meant that attackers can exploit the bug to load unsigned DLLs.

Once exploited, the vulnerability can lead to application whitelisting bypass, evasion of cybersecurity protections, and potentially privilege escalation, the researchers stated.

“The vulnerability gives attackers the ability to load and execute malicious payloads in a persistent way, each time the service is loaded. That means that once the attacker drops a malicious DLL in a vulnerable path, the service will load the malicious code each time it is restarted,” SafeBreach Labs said in a statement.

The other security bug, tracked as CVE-2019-15689, that discovered at the same time affects Kaspersky Secure Connection.  It’s said that this vulnerability can only be exploited if an attacker has already had administrator privileges.

According to researchers, attackers can manipulate this vulnerability during a post-exploitation phase to achieve signed code execution, persistence, and defense evasion.

“The vulnerability gives an attacker the ability to load and execute malicious payloads in a persistent way, each time the service is loaded. That means that once the attacker drops a malicious DLL, the service will load the malicious code each time it is restarted,” SafeBreach Labs stated.

The final vulnerability, named as CVE-2019-7365, was discovered in the Autodesk desktop application – AdAppMgrSvc.exe.

“After an attacker gains access to a computer, he might have limited privileges which can limit access to certain files and data,” the researchers said. “The service provides him with the ability to operate as NT AUTHORITY\SYSTEM which is the most powerful user in Windows, so he can access almost every file and process which belongs to the user on the computer.”

SafeBreach Labs reported the vulnerabilities to the concerned authorities of Trend Micro, Kaspersky, and Autodesk. Kaspersky stated that it has fixed the security issue found in its Kaspersky Secure Connection. Trend Micro too issued a patch to fix the vulnerability.

Even Autodesk released a patch for CVE-2019-7365 for Autodesk Desktop Application (ADA) users. “We highly recommend that customers apply the latest update for ADA by clicking the update button on the application. A security advisory with more information is available on the Autodesk Trust Center,” Autodesk wrote to CISO MAG.

What You Need to Know Now About Banking Trojans

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

By Derek Manky, Chief of Security Insights and Global Threat Alliances, Fortinet

Cybercriminals continue to refine existing malware to evade detection and deliver increasingly sophisticated and malicious payloads. They’re increasingly using banking trojans to drop other payloads and additional banking malware on infected systems to maximize their opportunities for financial gain.

Emotet is an example of this type of iterative process. It is a popular and successful banking trojan primarily spread through spam emails. During its lifecycle, it underwent a few iterations. Emotet had been relatively quiet for months, but Fortinet’s Q3 2019 Threat Landscape Report revealed a sudden surge in spamming activity related to the banking malware.

Communications to domains associated with Emotet detected by FortiGuard Web Filter service.

Why this sudden upsurge in activity?

Malicious actors have been using Emotet in a spear-phishing campaign to distribute TrickBot, a dangerous piece of malware that has been targeting the financial services industry for the last couple of years. Like Emotet, TrickBot primarily spreads via email, though both banking trojans can also propagate via SMB file shares using the EternalBlue exploit.

Emotet got its start in 2014 as an unremarkable banking malware. Since then, it has undergone multiple iterations. Initially, the malware was delivered as a malicious JavaScript file, but later versions used macro-enabled documents, PDF files and weblinks to fetch malicious payloads from a C2 server. The banking trojan’s operators no longer simply maintain the malware; they also actively distribute malware for other attack groups, particularly the ones originating from Eastern Europe. Recently, attackers have begun using Emotet as a payload delivery mechanism for ransomware, information stealers, and other banking trojans including TrickBot, IcedID and Zeus Panda.

New Threats, New Strategy

What can be learned from this example? Malware exists within a complicated ecosystem. With so many interrelated and ever-evolving variants emerging constantly, it’s easy to lose sight of what’s happening in the bigger picture. But one thing we can count on is that cybercriminals will always seek easy money, and malware is a tool to that end. As with legitimate business models, the easiest way to make money is to leverage existing investments and successes. That’s the bigger picture of what we see here: cybercriminals using successful malware to expand business opportunities.

One particularly effective and dangerous example comes from a technique called malvertising. Many computer users today still think they have to click on a file or a link to be infected with malware, but that’s simply not the case. There are many ways for bad actors to deliver their malicious payload—from phishing emails to infecting legitimate websites with malicious scripts to the malvertising approach.

This approach makes use of the way most of today’s websites pull advertisements from multiple ad servers. If the bad guys can infect the ad server, their malware will be delivered to thousands of websites that are serving up that specific ad. This means any system connecting to a site with that ad—even without the user clicking on anything—will get infected. Usually, a malicious script will redirect the user to the attacker’s server where other malware or exploits are then downloaded.

In light of this and other malware threats, enterprises must reconsider their security strategy – particularly, if they are undergoing digital transformation. The first step is to identify and then eliminate as many points of weakness as possible. This includes a proactive inventory of devices, granular access control and dynamic network segmentation. Next, develop a proactive and integrated security approach that provides consistent protection across your entire distributed environment. In this way, you can better defend your entire network environment—from IoT devices and the mobile edge, the network core, the new WAN edge and out to multi-cloud environments—at speed and scale.

Higher (Threat) Intelligence

Because there will always be criminals ready to use and re-invent malware, cybersecurity will always need to be woven into every new infrastructure or technology initiative in your organization. This requires security to operate in an integrated and collaborative fashion to keep adversaries at bay. However, your security strategy will only be as effective as the data and threat intelligence that inform them. As cybercrime evolves, so will your cyber strategy. It’s an ongoing process that needs the most current and accurate information so you can adapt with agility.

Derek Manky is the Chief of Security Insights and Global Threat Alliances at Fortinet. In his role, he formulates the security strategy for the company. He is actively involved with several global threat intelligence initiatives, including NATO NICP, INTERPOL Expert Working Group, the Cyber Threat Alliance (CTA) working committee and FIRST, all in an effort to shape the future of actionable threat intelligence and proactive security strategy.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

StrandHogg Vulnerability Hunting All Android Versions

Researchers at Promon, a cybersecurity firm better known for its in-app security protection, have found a vulnerability in the Android operating system named “StrandHogg.” It allows malware gangs to hijack legitimate apps and perform malicious operations like phishing.

It is also confirmed that Lookout, a partner of Promon, has identified 36 malicious apps already exploiting the StrandHogg vulnerability in the wild. Promon researchers found that all the 500 most popular apps (as ranked by app intelligence company 42 Matters) are vulnerable to StrandHogg and affect all versions of Android including Android 10.

As per researchers, “StrandHogg uses a weakness in the multitasking system of Android to enact powerful attacks that allow malicious apps to masquerade as any other app on the device. This exploit is based on an Android control setting called ‘taskAffinity’ which allows any app – including malicious ones – to freely assume any identity in the multitasking system they desire.”

To put it in simpler words, when users tap on a legitimate app, a malicious code is triggered in place of the original one. Users are then asked for intrusive permission (e.g. use of mobile microphone, camera, GPS, read and send SMS messages), which gives hackers device access control or shown phishing pages that fetches user’s login credentials and indirectly gives hackers access to security-sensitive apps.

Researchers also pointed out that StrandHogg is unique because it enables sophisticated attacks without rooting the device and asking any special permissions post exploitation. There’s no effective way to block or detect the StrandHogg vulnerability on the device itself. But users can stay alert by looking out for the following:

  • An app or service that you’re already logged into is asking for a login.
  • Permission popups that do not contain an app name.
  • Permissions asked from an app that shouldn’t require or need the specific permissions it asks for (considering the functionality of the app).
  • Typos and mistakes in the user interface.
  • Buttons and links in the user interface that do nothing when clicked on.
  • Back button does not work as expected.

Seems like Android is not the only OS facing vulnerability issues. In September this year, security expert Jose Rodriguez discovered a Zero-Day Exploit in the newly launched iPhone 11 series. Rodriguez revealed, in a tweet, that an attacker can exploit the bug in the new devices and their operating system iOS 13 to bypass the lock screen and access the phone’s contact information. Rodriguez even published a video demonstrating how to crack the device.

“AWS” Hacker Attacks Online Music Service Mixcloud

Compromised Email Accounts

Mixcloud, an online music streaming service provider, was recently compromised by a hacker that tried to sell stolen data of more than 20 million users on the dark web marketplace.

The incident came to light after the hacker, who goes by an online name “AWS” contacted multiple media firms to reveal the attacks and provided stolen data samples as a proof of the breach.

According to reports, the attacker accessed users’ data, including usernames, email addresses, account sign-up dates, SHA-2 hashed passwords, registration dates, IP addresses, and links to profile photos. It’s said that the hacker kept the data dump for sale for around US$ 2,000.

Mixcloud said that most users had signed up to their services via Facebook credentials and did not have a separate password to their Mixcloud account. For users who have separate passwords for their Mixcloud accounts, the company said that their passwords should be safe, as they were salted and passed through a strong hashing function (SHA256 algorithm), making it difficult to decode. However, Mixcloud urged its users to reset their passwords to be on the safe side.

“We received credible reports this evening that hackers sought and gained unauthorized access to some of our systems,” the company said in a statement. “We are actively investigating the incident. We apologize to those affected and are sorry that this has happened. We understand this is frustrating and upsetting to hear, and we take the trust you put in us very seriously.”

“Our understanding at this time is that the incident involves email addresses, IP addresses and securely encrypted passwords for a minority of Mixcloud users. The majority of Mixcloud users signed up via Facebook authentication, in which cases we do not store passwords,” the statement added.

The Future of Endpoint Management is Cognitive

future of endpoint management

By Vaidyanathan Iyer, Security Software Leader, IBM India/South Asia
Today, the biggest test chief information security officers (CISOs) face is to find the perfect balance between watertight security and seamless user experience across all the endpoints in their network. This even as the traditional management of endpoints has undergone a sea change from a decade ago when all devices were on-premises. Present-day CISOs find themselves in a quagmire as end-users access an unprecedented number of devices and applications outside the premises. In this article, we take a look at the challenges and also look ahead at the future of endpoint management.

The quagmire of devices and apps 

Consumerization of information technology (IT) over the last many years led to the rise of Bring Your Own Device (BYOD) processes on the enterprise side. This means enterprises had to contend with all major operating systems like Apple iOS, macOS, Google Android, Microsoft Windows and a host of applications. On the other hand, the proliferation of smartphones expanded the use cases for businesses while also bringing along more security challenges for them. After all, mobile data can inherently expose them to countless risks stemming from its transmission, storage, and overall protection mechanisms.

Apart from the above challenges, they needed to ensure compliance with local, national and global regulations and emerging data privacy concerns. Above all, companies needed to put in place a strong mobile security strategy. At the same time, the focus on employee experience was picking up. Digital workspaces for users with personalized enterprise app catalog became imperative for seamless user experience across devices. Enterprises had to build capabilities to recommend apps based on user behavior.

The need for the tools and resources required to balance the benefits of mobility with its associated risks led to the metamorphosis of mobile device management (MDM) into Enterprise Mobility Management (EMM). However, over the last couple of years, EMM solutions have lost relevance as manual assessment and remediation put businesses at risk.

Traditional enterprise mobility management losing relevance 

Conventional EMM was proving to be time-consuming, as IT was saddled with mountains of endpoint data. The limited resources at disposal to solve limitless issues made it inefficient. For example, with EMM, IT managers while investigating potential malware attacks had to manually assess and research the potential malware threats, identify remediation methods and manually resolve for each of the devices. In instances of new regulations or legal ramifications, they needed to talk to their legal team to find out if they affected the current security policies and users and then manually remediate the issues. Besides, the system was becoming expensive as point solution investments became a norm to address gaps in the operating system (OS) support across available tools.

In such a scenario, IT managers were stuck on a path of business upkeep instead of business transformation. They faced roadblocks to actualize the full potential of the endpoints and, ultimately, the workforce. Dead as a dodo, EMM has now morphed into Unified Endpoint Management (UEM).

The move towards unified endpoint management 

Businesses must have a holistic view of the devices, users and beyond. A combined view of devices and users will help them pinpoint risky devices and users. They can accordingly, infuse identity authentication and authorization to allow conditional access or turn on multi-factor authentication for risky users. They can gauge the overall enterprise-wide risk exposure. Thus, the centralized nature of UEM reduces the complexity businesses face on a day-to-day basis. More importantly, UEM provides threat management capability on the endpoints besides end-user analysis of apps and their performance to recommend corrective actions.

UEM allows enterprises to put their expensive and ineffective multi-solution dependencies behind them while maintaining protection and control over desktops, laptops, smartphones, tablets, ruggedized devices, wearables and the Internet of Things (IoT) in addition to apps, documents, and data. Normally, UEM platforms support all major OS types, including Apple iOS, macOS, Google Android, and Microsoft Windows, along with their latest software versions. The right UEM solution also makes it possible for businesses to migrate effortlessly from legacy PC platforms such as Windows 7 to more powerful, modern updates like Windows 10.

Nonetheless, while UEM is valuable, it is just another tool. It needs something more to make it invaluable. Something that will challenge companies to think differently and manage their IT smarter. What is this key element? The answer perhaps lies in cognitive technology.

Benefits of cognitive technology – why is it here to stay 

Cognitive capabilities enable organizations to understand vulnerabilities and patches for the infected devices and recommend relevant actions to remediate. Cognitive technology self-discovers and analyses threats and immediately points to the affected devices and recommended steps to fix the problem. It provides an overview of any new regulation that may be in play related to the incident, and potentially how many endpoints are affected. This way, IT managers can move on to the next incident and avoid manual investigation and remediation for each endpoint. Imagine the risk exposure to the organization if they do not get real-time updates and benchmark threats in a world of changing vulnerabilities.

Cognitive lets organizations swim effortlessly in the sea of threats and manage all endpoints in a unified endpoint management console for laptops, tablets PCs, mobile and IoT. A cognitive tool delivers opportunities, risks and general information so IT managers can make sense of the erratic endpoint behavior they encounter every day. Such a solution can source insights from structured and unstructured data, giving administrators, ample, relevant context to make their most important decisions. Each insight could be tailored to the industry, company size and the construct of an enterprise’s external environment, including its devices, platforms, and most commonly used apps.

So Cognitive technology coming into UEM is the future of endpoint management.

Are enterprises prepared?

Now the moot question to ask is, are enterprises confident of combating a zero-day mobile malware threat with their legacy MDM or EMM solutions? Do they perceive they will be able to randomly discover threats, conduct research, determine the impact of the threat on their IT environment and remediate to fix the problem, all on their own without any assistance from intelligent tools? Are they truly confident? The answer would be a resounding “no”.

Whereas with a UEM platform powered by cognitive computing technologies, they can realize new efficiencies from time saved in responding to customers with a rapid, increased opportunity with broad device support and scalable UEM services and security solutions for any compliance requirements.

Compliance requirements could be those such as GDPR. With cognitive technologies, this is just the beginning. As more cognitive capabilities are added, a UEM platform with cognitive technologies will build greater knowledge and context for a smarter approach to securing and enabling endpoints, end-users and everything in between. Enterprises know that their IT environment is getting bigger and busier by the day. However, the IT managers’ role remains the same – they are still tasked with making the most of a tumultuous endpoint environment and making sense of it.

Cognitive capabilities will help organizations realize greater value from a UEM approach and is a step in the right direction. Many organizations have started moving towards a cognitive technology-based UEM platform to not just fight the daily threats but also be future-ready.

The future of endpoint management is cognitive.


Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

NYPD infected by a Ransomware, Accidentally!

NYPD

NYPD’s fingerprint database was shut down for a few hours in October last year, when an accidental ransomware infection affected nearly 23 machines linked to the department’s LiveScan fingerprint-tracking system.

How it happened?

The incident took place at the Police Academy in Queens, when a third-party contractor was setting up a digital display system. As soon as he connected the already infected NUC mini-PC to the police network, the virus attached itself to the system.

How NYPD responded?

The Deputy Commissioner for Information Technology Jessica Tisch said, “Cops realized within hours that there had been a breach. The department’s cyber command and the Joint Terrorism Task Force were notified of the contamination almost immediately.” The cyber forensic investigation found that the ransomware was “never executed”. But the NYPD shut down LiveScan that night and reinstalled software on 200 computers citywide as a precautionary measure, she added.

The IT contractor that accidentally infected the network was brought in for questioning but was neither charged nor arrested as the breach impacted 0.1 % of the department’s computers, and that too unknowingly.

Lessons to Learn

The NYPD cyber cell and incidence response team did a fantastic job by

  • quickly detecting and containing the infection (by shutting off the fingerprint database),
  • cleaning the systems (by reinstalling software in 200 systems on the same network) and
  • determining that there was no malicious intent on the part of the contractor (by questioning him in person) who caused the mess.

What could have been different?

The infected machines were a part of the NYPD’s LiveScan fingerprint system that is a very critical system for any law enforcement agency. The Academy’s digital display network should ideally not have anything to do with the LiveScan (fingerprint database) network. Had firewalls or Access Control Lists (ACL) and Virtual Local Area Network (VLAN) been used to separate the digital display network from the rest of the network, the damage could have been limited to the less critical signage network only. The question is, “Is this Feasible?” The answer is Network Segmentation.

Network Segmentation

Network segmentation, also known as, network segregation, network partitioning, or network isolation divides a computer network into smaller parts with an intent to improve network performance and security.

Segmentation works by controlling how traffic flows among the parts. The network traffic in one part can be stopped from reaching another, or can limit the flow by traffic type, source, destination, and many other options. This methodology not only helps in containment but also in keeping the remainder of the network live even when one or more modules/systems on the network are affected or compromised.

This setup type is not cost efficient, and this is one of the main reasons why they are not the first choice in government organizations. In case of the NYPD incidence though, had there been network segmentation in place then that would have helped the containment of the ransomware to the signage network only and a need to shut down the entire fingerprint database system – LiveScan could have been avoided.

Around 61 percent Malware ads Target Windows OS: Devcon

BotenaGo, malware over encrypted connections

Security researchers revealed that most Malvertising campaigns (malicious ads) target the Windows platform more often than any other operating system.

According to the analysis by cybersecurity firm Devcon, 61 percent of the malicious ads observed between July 11, 2019, and November 22, 2019, were aimed at the Windows operating system. While the second most targeted OS is ChromeOS with 22.5 percent and least targeted are iPadOS at 0.8 percent and Linux at 0.3 percent.

A malicious ad campaign is a series of digital ads that are designed to have a malicious effect on the end-user. The campaigns are designed to redirect users to malicious sites or trick them into downloading malware.

Devcon’s malvertising stats also highlighted that around 22 percent of the malicious ads targeted Google’s fledgling OS, which is more than macOS (10.5 percent), iOS (3.2 percent), and Android (2.1 percent).

Devcon also recommended some necessary security steps to defend against bad ad campaigns:

  • Use antivirus software and ensure it is updated
  • Don’t get attracted by Clickbait ads
  • Clear your cache
  • Use secured browsers
  • Say no to the “Save Password” feature in browsers
  • Whenever you see a bad ad, report it to the site holder

In a similar research report, Microsoft disclosed a new malware campaign targeting thousands of Windows systems across the world. The malware, dubbed Nodersok, was developed to infect computers to turn them into proxies for launching cyber-attacks.

Security researchers at Microsoft stated the attack begins when a user downloads the HTML application (HTA) file named Player1566444384.hta. Researchers stated the malware has infected thousands of computers across the world targeting various sectors including Healthcare, Finance, Transport, Aerospace, and Education, mainly in the U.S. and Europe.