Home Blog Page 280

How Facebook is Securing the 2020 U.S. Elections from Russian Meddling

Facebook stated that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections.

“We have a responsibility to stop abuse and election interference on our platform. That’s why we’ve made significant investments since 2016 to better identify new threats, close vulnerabilities and reduce the spread of viral misinformation and fake accounts. Today, almost a year out from the 2020 elections in the U.S., we’re announcing several new measures to help protect the democratic process and providing an update on initiatives already underway,” Facebook said in a statement.

The new steps announced by Facebook include, Fighting Foreign Interference, Preventing inauthentic behavior, Increasing transparency, Labeling state-controlled media on their Page and in the Ad Library, Preventing the spread of misinformation, and monitoring candidates accounts, elected officials through Facebook Protect.

“As we’ve improved our ability to disrupt these operations, we’ve also built a deeper understanding of different threats and how best to counter them. We investigate and enforce against any type of inauthentic behavior. However, the most appropriate way to respond to someone boosting the popularity of their posts in their own country may not be the best way to counter foreign interference,” Facebook added.

The latest move adds to a series of measures from Facebook since 2016, after foreign bodies involved in meddling of the U.S. election campaign. The social media giant drew fire for not handling misinformation and election manipulation on the platform too well.

Earlier, Facebook claimed that a Russian group posted more than 80,000 times on its service between January 2015 to August 2017. Nearly 29 million Facebook users directly received their posts in their news feeds. The Facebook officials disclosed these numbers to the Senate Judiciary Committee on October 31, 2017.

US Legislation Launches “Mind Your Own Business” Act

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

From now, the Chief Executive Officers who misuse customers’ data could end up in jail for twenty years.

The U.S. legislation recently proposed “Mind Your Own Business Act”, which prosecutes top-level executives if their companies are found misusing citizens’ information and lying about it. Authored by Senator Ron Wyden, the bill requires organizations to produce annual data protection reports personally certified by the company’s CEO, proving that they obeyed the data regulations.

“This bill is in the first stage of the legislative process. It was introduced into Congress on October 17, 2019. It will typically be considered by committee next before it is possibly sent on to the House or Senate as a whole,” said Ron Wyden.

The new legislation adheres to a draft version known as the Consumer Data Protection Act, which was released for discussion on November 1, 2018.

The proposed bill applies to the companies that hold data of more than 50 million customers or over a million people if they make a revenue of more than US$ 1 billion. In case the company intentionally certifies false reports, then they’re subjected to a fine up to US$ 5 million or face up to 20 years of imprisonment. It also provides customers the right to demand details of any personal data collected by the companies.

Companies are also required to notify their customers what information they collect and what they are going to do with it. The bill also requires companies to provide a site that enables consumers to opt-out of any personal data collection.

Recently, the New York State Legislature passed a new bill in order to strengthen its data breach policies. The new bill, dubbed as Stop Hacks and Improve Electronic Data Security Act (SHIELD), provides more transparency to consumers, while it also imposes stringent penalties on companies without proper cybersecurity measures.

According to the Attorney General Letitia James, the SHIELD Act will update the state’s breach notification laws, expand the current notification requirements for companies, increase penalties for liable companies, and increase the rights of consumers in the event of a breach. The bill imposes tough obligations on businesses that handle sensitive data of customers.  The businesses are required to maintain reasonable data security measures in case they’re collecting personal data from the customers.

Faster and Secure Credit Card Checkout for Online Shopping

one million card data exposed

A consortium consisting of major credit card companies like American Express, Visa, MasterCard, and Discovery have introduced a one-click checkout feature to make the online shopping experience of the users both easier and secure.

With an increase in the number of online shopping consumers, Payment gateways have become an integral part of e-commerce websites. Payment gateways currently provide multiple payment options such as credit cards, debit cards, net banking, mobile wallets, etc. These may seem overwhelming and confusing to the common man, but even after selecting one of the options there’s a host of other data fields that are required to be filled in. This makes the whole online shopping experience dissatisfying to the users as they are doing, who are shopping online to save time.

The new one-click checkout is not only a faster and secure mode of credit card payment but it also satisfies the new EMV (Europay, MasterCard and Visa) Secure Remote Commerce (SRC) standard–a global benchmark for card payments made across merchant websites, mobile applications, and other connected devices. It simplifies the digital payment experience by allowing users to make payments without logging into the associated account. SRC technology has been successfully tested by networks in the market environment on merchant websites. The “Click to Pay” feature will soon be available for merchants like BassPro, JoAnn Fabric and Crafts, Papa John’s, Saks Fifth Avenue, SHOP.com and Tickets.com in the United States and will be rolled out to the rest by early 2020.

“Delivering solutions to merchants that enable greater levels of security and convenience for consumers is essential for enabling commerce,” says Eddie Alberty, Vice President of Strategic Partnerships, SHOP.com, “With Secure Remote Commerce, we aim to offer standards to merchants that reduce the friction of guest checkout.”

In an earlier story, hackers had compromised more than one million payment card records and posted them for sale on the Dark Web. In the wake of such digital payment concerns, we hope the one-click payment emerges as a game-changer for digital payment security.

A New Defense Against Wormable Exploits

Worm, Virus

By Micha Rave, Sr. Director, Zero-Trust Product Management, Proofpoint

Here’s some good news. Your team doesn’t have to be vulnerable to wormable exploits like BlueKeep, WannaCry, and the most recent wormables found across MS Windows platforms. But to safeguard your system, you may need to make a change in your current approach to security.

Traditional platforms for securing endpoints—think endpoint detection/response tools and anti-virus software—are ill-equipped to prevent wormables from wreaking havoc. Even informing users about the risks will not help. Simply connecting an infected device to a network can cause wormable malware to spread and infect healthy machines throughout the so-called “secure” zone. Similarly, the products that protect your network, like firewalls and network access control solutions, will not prevent lateral movement.

But the good news I alluded to above is that you can use a software-defined perimeter, or SDP, for a much better defense against BlueKeep and its ilk. SDPs do so by providing what’s known as “zero-trust” security for networks via a dual-defense system that features two complementary defenses:

  • Preventing an initial wormable infection from happening to a user’s device.
  • Preventing the spread of the worm, network-wide, from one infected device.

What’s the Problem with Firewalls and VPNs? 

Before delving deeper into SDP solutions and their benefits for protection against wormables, let’s first drill down into what’s wrong with the approach you may currently be using to secure access to your network—enterprise firewalls and VPNs.

Firewalls are designed to keep evil-doers and attackers outside of the enterprise network, and they do a good job mostly. However, wormable exploits spread laterally inside the enterprise network, which is why firewalls are largely ineffective against them once they get inside. Take BlueKeep as an example, which took advantage of the Remote Desktop Protocol (RDP) port. While firewalls may be used to prevent a worm from entering your local area network (LAN) in the first place by blocking susceptible ports, like RDP or RPC, this can’t always be relied upon as a solution since such a block may be infeasible in certain circumstances, for example, when remote workers need remote RDP access. It also won’t keep the wormable from infiltrating the LAN in a situation where a device that became infected outside of the perimeter physically brings the worm in (effectively bypassing the firewall).

And as a TechCrunch report on BlueKeep stated, “If servers at the enterprise firewall level are hit…the potential of every other computer connecting to it fac[es] a similar fate.”

What about the VPN? VPNs are often still the enterprise’s go-to choice to connect employees working remotely; contractors, and third parties who are conducting business virtually—but they shouldn’t be. In fact, the majority of VPN deployments create vulnerabilities to wormables because they are not “always on.” This means when employees are roaming with their devices on public, potentially hostile networks, their devices may become infected. If that does happen, the VPN allows the infection to be passed along to the local network as soon as the device connects over the VPN, again, bypassing the firewall guard.

Health IT Security quoted Simon Pope, Director of Incident Response for Microsoft Security Response Center, when BlueKeep was first reported: “Future malware that exploits this vulnerability could propagate from vulnerable computer to vulnerable computer in a similar way as the WannaCry malware spread across the globe in 2017.”

What Helps: Network Segmentation 

To provide real security, enterprises need a way to minimize the potential surface for attack, and this is achieved by defensively partitioning the network via micro-segmentation. Yet while offering only finely grained access to each user based on the actual services and applications that a specific user requires for business purposes is considered a best practice, it’s complexity can keep many enterprises from taking advantage of it.

Zero-Trust SDP to the Rescue 

A zero-trust SDP solution is a much easier way for an enterprise to allow third-parties micro-segmented access to only the exact resources that each individual needs, regardless of where a device is connected: in or outside of the enterprise network. This model is important because when you think about it, it’s simply foolish to trust a device, third-party, or user automatically without proper authorization and verification. Instead, every user should have a fixed identity that’s uniquely customized just to him or her. All other network resources should be invisible to each user, and that’s exactly what happens in an SDP model. In this scenario, even if a device gets infected, at least it won’t automatically contaminate the entire network. Deploying an SDP solution is significantly easier than manually partitioning the network, and can scale dynamically with your network, users and applications.

When comparing SDP options, an important distinction to recognize is that not all solutions prevent a wormable infection from occurring on a public network. Since devices can end up infected by a worm just by connecting to a “dirty” network, the best approach is to deploy an always-on, zero-trust SDP solution to keep a wormable infection from happening in the first place to minimize its effect in the case that it does.

Micha Rave is the Senior Director of Zero-Trust Product Management for Proofpoint and former VP of Products of Meta Networks. He is an experienced strategic product manager and team leader with substantial experience managing innovative product lines such as Proofpoint’s Software-Defined Perimeter (SDP) platform.   

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Upstream Security Hits Top Gear with Series B Funding

Automotive cybersecurity

Upstream Security, an Israel-based leading automotive cybersecurity company, announced the closure of a US$30 million Series B funding round led by a Global Syndicate consisting of Renault Venture Capital. It also included Volvo Group Venture Capital, Hyundai, Hyundai AutoEver, Nationwide Ventures, and others. The company’s earlier investors Charles River Ventures, Glilot Capital, and Maniv Mobility also participated in this round of investment.

With a recent shift in gears, the automotive sector is zooming towards a connected vehicle industry. This shift has its own problems though. The biggest concern is the cybersecurity of connected vehicles and commercial fleet services. This is where Upstream steps in. It provides cloud-based automotive cybersecurity solutions which not only help in achieving cybersecurity for the vehicles but also help build a secure perimeter around the vehicle’s other integrated services.

Yoav Levy, Upstream Security Co-founder, and CEO said, “This first of its kind investor syndicate, which includes some of the most important smart mobility companies in the world, is a testament to the severity of the problem the industry is tackling and a ringing endorsement of Upstream’s technology and the progress our team has made. Our mission is to protect every connected vehicle and smart mobility service on the planet–the completion of our funding is perfectly timed to meet the growing demand for our data-driven cloud-based platform, providing our customers with the capabilities they need to accomplish this vitally important task.”

Anna Westerberg, acting CEO of Volvo Group Venture Capital and Senior Vice President, Volvo Group Connected Solutions stated, “Upstream Security has a promising offering and capability to support with cybersecurity solutions to meet our future requirements”

Earlier in the year, Upstream Security had entered into a technology partnership with Arilou, a provider of in-vehicle network security for carmakers. This partnership was aimed at creating a fully integrated cybersecurity offering for vehicle OEMs which surely is now reaping them the benefits.

Radiflow and Asset Guardian Join Hands for Industrial Asset Monitoring

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Cybersecurity solutions provider Radiflow and industrial software provider Asset Guardian Solutions came together to launch a joint solution to expand Industrial Asset Monitoring, Change Management, and Risk Assessment Capabilities for industrial enterprises.

Radiflow provides cybersecurity solutions for critical industrial automation networks (ICS/SCADA), like chemical plants, power utilities, and wastewater facilities. Its industrial threat detection system iSID provides real-time visibility of networked industrial assets, protocols, and ports on an OT network. Radiflow’s security platform validates the behavior of M2M (machine-to-machine) applications and H2M (human-to-machine) sessions in distributed operational networks.

The Asset Guardian software solution provides a convenient and cost-effective way to reduce the risk of unauthorized entry. The company is focused on protecting the integrity of process control systems software that is used to control operations and production processes. The company claims that it has a client base of blue-chip organizations across the world operating in the Pharmaceutical, Oil & Gas, Power Generation, Chemical, Transportation Utilities, and Food & Beverage industries.

“In this new integrated solution, iSID’s asset inventory now incorporates the asset information stored in the Asset Guardian database, including the detailed asset information that is not available from traffic monitoring. With this new detailed asset information from Asset Guardian, such as logic version, ownership, geo-location and more, the result is a far more granular risk score calculated by iSID for each asset,” Asset Guardian said in a statement.

“Our Integrated and comprehensive joint platform solution capability will provide greater insight, clarity, and security to our global customer base to help protect the integrity of their OT ICS assets against ever-increasing cyber threats to safeguard operational resilience, govern compliance, standards, security and deliver effective management of change and disaster recovery,” said Ewan McAllister, CEO of Asset Guardian Solutions.

UC Browser Android Users are Vulnerable to Man-in-the-Middle Attacks

UC Browser Vulnerability

Security experts found unusual activities in UC Browser for Android, exposing more than 500 million users to Man-in-the-Middle attacks.

According to a research by security firm Zscaler, UC Browser and UC Browser Mini apps unusually requested an unprotected (HTTP) channel to download an additional Android Package Kit from the remote server. It’s said that UC Browser and UC Mini violated Google Play security policies and make it possible for any malicious app to enter a user’s device.

According to the research, UC Browser downloads a third-party app to devices over unsecured channels, which become victim to Man-in-the-Middle (MiTM) attacks. Using MiTM attacks, the hackers can spy on the victim’s device, install an arbitrary payload that performs phishing attacks, steal personal data, including usernames, passwords, and credit card numbers.

“As we began to analyze the UC Browser app, we found that the requests were being made to download an additional Android Package Kit (APK) over an unsecured channel (HTTP over HTTPS). Downloading and/or updating components from a third-party source violates Google Play policy,” Zscaler said in a statement.

Zscaler stated that it found three unusual activities on the UC Browser app during its investigation, which include, Downloading an additional APK from a third party, Communication over an unsecured channel, and Dropping an APK on external storage.

Zscaler also highlighted that it found UC Browser Mini from the same developer with the same functionality and issues. “During our analysis, we found the APK being dropped on external storage, but we did not find the APK being installed. It is possible that this functionality is still under development or there may be other reasons it wasn’t installed, such as exception, disabled unknown-sources option, or rooted device,” Zscaler added.

Cisco Fixes Vulnerabilities in its Aironet Access Point Software

Cisco Vulnerabilities

Networking hardware company Cisco released patches for critical security vulnerabilities that existed in its Aironet Access Point Software. Security pros at Cisco stated that the vulnerabilities could lead bad actors to remote code execution.

Up on exploit, the vulnerabilities, named CVE-2019-15260, CVE-2019-15261, and CVE-2019-15264, could allow an attacker to gain access to view sensitive information, meddle with wireless network configurations, and cause a denial of service. However, Cisco has released fixes for all the three high-severity flaws targeting its Access Point Software.

“The vulnerability is due to insufficient access control for certain URLs on an affected device. An attacker could exploit this vulnerability by requesting specific URLs from an affected AP. An exploit could allow the attacker to gain access to the device with elevated privileges,” Cisco said in a report.

“The vulnerability is due to insufficient validation of Generic Routing Encapsulation (GRE) frames that pass through the data plane of an affected AP. An attacker could exploit this vulnerability by associating to a vulnerable AP, initiating a PPTP VPN connection to an arbitrary PPTP VPN server, and sending a malicious GRE frame through the data plane of the AP,” Cisco added.

Cisco recently released an open-source hardware tool dubbed ‘4CAN’ to find security vulnerabilities in connected cars. The newly launched security tool will allow automobile security researchers and car manufacturers to identify potential flaws in sensors and control systems in modern cars, to ensure vehicle security. Cisco stated that vulnerabilities in the control systems might cause serious threats in the cars, which allows attackers to get control of the vehicle’s system.

“To help secure modern automobile technology, Cisco has dedicated resources for automobile security. The Customer Experience Assessment & Penetration Team (CX APT) represents the integration of experts from the NDS, Neohapsis, and Portcullis acquisitions. This team provides a variety of security assessment and attack simulation services to customers around the globe. CX APT specializes in identifying vulnerabilities in connected vehicle components,” Cisco said in a statement.

WordPress Websites Infected with Fake Plugins

Attackers Target 900,000 WordPress Sites in a Week

For beginners, bloggers and corporates alike, the WordPress platform is a favorite mainly due to the ease it provides in creating and maintaining personalized website(s) using a wide range of WordPress plugins. These plugins are easy to use, creative, free–but also fake and malicious at times. A research conducted by a website security company, Sucuri, has raised the flag for website developers and security personnel.

Reports suggest, fake plugin names like “initiatorseo” or “updrat123” were used by hackers to gain and maintain backdoor access with compromised websites. It was observed that the internal code of these fake plugins differs from each other, but they possess a similar structure and header comments from the popular backup/restore plugin UpdraftPlus. The researchers stated that, “The metadata comments within these fake plugins include copies from version 1.16.16 of UpdraftPlus, which was released on July 23, 2019.”

These fake plugins are created easily by hackers with the help of readily available resources or by adding corrupted web shells into the source code of the original plugin. The reason why these fake WordPress plugins remain hidden to the user’s plain sight is because they do not affect a user’s (WordPress) Dashboard unless they are using browsers with specific User-Agent strings. The attack on a website is carried out by these plugins once they establish a backdoor entry. Hackers are intimated about the servers’ GET request, to which they respond with a POST request consisting of infected files. These malicious files or web shells are then infused in the websites’ root directories. Researchers also mentioned that, “compromised websites may be used for malicious activity that is completely invisible from outside, including DDoS and brute-force attacks, mailing tons of spam, or crypto mining.

An earlier independent study done by WPScan stated that WordPress plugins are the biggest source of vulnerabilities and data breaches in WordPress. It accounts to 54 percent of the global WordPress vulnerabilities count.

QKD: The “Black Swan” of Data Security

Network Encryption, DSCI Whitepaper on Encryption

By Sunil Gupta, CEO, QNu Labs

The world produces 2.5 exabytes of data every day. And 3.2 billion global internet users continue to feed the data banks with 9,722 pins on Pinterest, 347,222 tweets, 4.2 million Facebook likes–plus all the other data we create by taking pictures and videos; saving documents, opening accounts and more.

Another report proclaims that we create more data every data than the data created until that day. We have reached the limits of the data processing power of current computers, but the data just keeps growing exponentially.

That’s why there’s a race from the biggest leaders in the industry such as Google, Microsoft, IBM and Intel to be the first to launch a viable quantum computer that would be exponentially more powerful than today’s computers, to process all the data we generate, every single day, and solve increasingly complex problems. These quantum computers will be able to complete calculations within seconds, that would otherwise take today’s computers, including current supercomputers, thousands of years to calculate.

The emergence of Quantum Computing

About a month ago, Google claimed to have built a quantum computer that could carry out calculations beyond the ability of today’s most powerful supercomputers, thus achieving Quantum Supremacy, supposedly a holy grail. As per the Nasa website, this quantum computer can perform a calculation in 3 minutes and 20 seconds, that would take today’s most advanced classical computer, Summit, approximately 10,000 years to accomplish. This is also supposed to be the first computation that can only be performed on a quantum processor.

This feat is invaluable and critical if we have to process the monumental amount of data we generate and solve very complex problems. The promise is that, due to their ability to work on Q-bits instead of bits, quantum computers will allow quick analysis and integration of our enormous data sets which will improve and transform our machine learning and artificial intelligence capabilities to the next order.

Unfortunately, like every great technology, Quantum Computers also bring along negative aspects. The industry is gravely concerned that quantum computers will be able to crack most of today’s encryption that uses “trapdoor” mathematical functions that work easily in one direction but not in the other. That makes encrypting data easy, but decoding it is difficult without the help of a special key.

A new study by MIT Technology Review shows that quantum technology will catch up with today’s encryption standards much sooner than expected. That should worry anybody who needs to store data securely for 25 years or more.

How Quantum can strengthen encryption

Cryptosystems are designed to cope with the worst-case scenarios: An adversary with infinite computing resources and access to plaintext/ciphertext pairs knows the encryption and decryption algorithms, so they can choose plaintext or ciphertext values at will. The only element not accessible to this adversary is the secret key, and thus the security of a cryptosystem depends solely on the security of the key.

Today’s encryption (secret) keys are highly vulnerable due to many reasons such as weak randomness, advances in CPU power, new attack strategies, the emergence of new algorithms such as Shor’s, which when run on Quantum simulators or Quantum computers will ultimately render much of today’s encryption unsafe. A particular concern is that data encrypted today can be intercepted and stored for decryption by quantum computers in the future.

Quantum safe technology needs to be adopted.  A technology that can address the practical difficulties such as safeguarding the hacking of encryption keys long, truly random keys, distributing the keys to recipients, sender, and receiver to be totally synchronized to make sure that the same keys are used for the same message, and ensuring that keys are never reused.

Quantum Key Distribution (QKD) is one such technology that addresses all these challenges. QKD is a key establishment and distribution protocol that creates a shared symmetric key material by using quantum properties of light to transfer information from Alice to Bob in a manner that will highlight any eavesdropping by an adversary.  This can be used to derive a key, and the resultant key material can then be used to encrypt plaintext using one-time pad encryption or using AES to provide unconditional security.

Here are some potential applications of  Quantum nature of secret keys to address some of the important problems of the industry:

Quantum safe authentication – A quantum token is used to authenticate a person and to provide access control across the organization.

Secure ‘Data in Transit’ between Enterprise Server and Data Centres – Uncompromised encryption keys generated and distributed between the two entities ensuring the absence of eavesdropping.

Securing ‘Data at Rest’ at the Private Cloud or Public Clouds – Enterprises can generate and use their own unconditionally secure keys to encrypt their data in the cloud ensuring full control of their data.

Secure ATMs – All confidential information such as PIN, etc. from the ATMs is transmitted to the bank, encrypted using QKD.

Security against anti-skimming – Quantum secret is used to encrypt the PIN.

Securing online banking – Replacing TAN with Quantum TAN.

Securing against Cardholder Not Present (CNP) fraud – Keys are not available to an attacker via phishing or keylogging, and the transaction details encrypted via a one-time pad that cannot be retrieved by unauthorized actors.

If QKD is used in carefully selected applications, alongside existing classical cryptography, then great benefits can be derived by the deployment of this technology.

QKD surely has its niche amongst the fundamental building blocks of cryptography and set to cause a cataclysmic upheaval in the world of cryptography.  QKD is a ‘Black Swan’ of Data Security.

The writer is the co-founder and CEO at QNu Labs. Before joining QNu Labs, he was COO at Paladion Networks responsible for driving and growing business for MEA and India regions. 

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.