Home Blog Page 284

Autonomous Cyber AI is Revolutionizing Cyber Defense

AI and Security

By Sanjay Aurora, Managing Director, Asia Pacific, Darktrace       

As the near-constant stream of high-profile attacks suggests, the cyber-threat landscape is rapidly evolving with no sign of slowing. Cyber-attackers are not only moving faster, they are adding new and innovative tools within their toolkits. And as the entire world turns online, we are moving towards a future where cyber-threats increasingly threaten the safety of not just our data, but of our physical infrastructure too.

Sifting through the recent data breaches, certain trends emerge for how attacks are set to evolve in the future. Most notably, we’ve entered a critical era where the use of offensive AI by sophisticated threat-actors is nearer than ever. Whilst Cyber AI has, for the past several years, transformed how security teams identify and fight back against threats, we soon expect to see AI on the other side – attackers adopting the technology for nefarious uses.

Indeed, even beyond cybersecurity, AI is lowering barriers to entry and empowering organizations around the world to deliver services at a previously inaccessible scale and speed. Unfortunately, this same power is proving attractive to cyber-attackers. At Darktrace, we have seen the early signs of threat-actors using AI – whether it’s to supercharge spoofing emails or to create advanced malware that adopts its behavior to blend into the background noise of the network.

Take for example, the creation of spoof emails. By using AI, an attacker would be able to generate communication that for the average person, is virtually indistinguishable from genuine correspondence. And by leveraging the speed and scale made possible with AI, it would only take 2 attackers to create code that could generate 2 million emails a day with an 85% success rate – ultimately, making attacks significantly more profitable.  

Attacks on infrastructure

But AI attacks won’t just target emails and corporate networks. There is a more worrying type of attack on the horizon – the sabotage of critical infrastructure. Advanced threat-actors are turning away from just simple data theft and look instead to cause mass disruption. And as cities and nations trend towards ‘smart city’ infrastructure, the attack surface has grown exponentially – meaning that the risk has never been higher. Attackers can use AI to bypass traditional security tools and slowly and subtly cause instrumental damage to the operations of the infrastructure – all whilst going undetected.

These attacks have the potential to compromise our most critical infrastructure by turning off the lights, disrupting transport systems, and ultimately threatening public safety. The past year has shown us that geopolitical tensions are beginning to be played out in cyberspace. Nation states will have to be on high alert to protect their energy grids, manufacturing plants, and airports from sophisticated cyber-threats.

In fact, just last week, during the fourth Singapore International Cyber Week (SICW), the Operational Technology (OT) Cybersecurity Masterplan was unveiled, to enhance the security and resilience of Singapore’s critical infrastructure. A world-leading country in innovation and technology, this move by Singapore demonstrates the significance of the risk of cyber-threat to national critical infrastructure – and will no doubt set the trend for other Asia Pacific countries to follow suit, making cyber defense for critical infrastructure a priority.

Autonomous Cyber AI

Ultimately, the future almost certainly holds the reality of AI-driven cyber-attacks, where malware will have the ability to self-propagate via a series of autonomous decisions and intelligently tailor itself to the parameters of the infected system in order to become stealthier to evade detection. Organizations need to be readying themselves for what is fast becoming a cyber arms race.

Our brave new world seems to be one where algorithms will fight algorithms on the battleground of corporate networks. And only those with the best AI will win. But the fact is, there is no silver bullet for cybersecurity. While many boards are waking up to the reality that cyber-attacks are imminent, action is needed to prevent attacks from doing harm once the threat is already inside. Organizations need to shift their focus from post-breach response to early detection and autonomous response, which will generate a far more positive outcome for their organization and their stakeholders.

Autonomous Cyber AI is revolutionizing cyber defense and may prove to be our best line of defense against future AI attacks. Acting as a cyber ‘immune system’ for the digital enterprise, this AI is capable of learning what is ‘normal’ and ‘abnormal’ for the digital business on an evolving basis, without relying on prior knowledge of threats. Stepping in as the machine defender, this technology can not only identify never-before-seen threats, but also autonomously respond to isolate the attack before it does damage.

Ultimately, digital transformation is happening at such a pace that AI, especially in the area of cybersecurity, is being recognized as a ‘must-have’ in enabling companies to stay ahead of unpredictable threats. And once attackers turn to AI to supercharge their methods, cyber AI will be our most fundamental ally.

Indeed, more than 3,000 organizations around the world have turned to cyber AI as their most crucial weapon in the fight against the threats that no one can predict – the threat that slips through perimeter defenses, or the threat that is already inside.

Humans alone cannot detect the subtle, unusual behaviors indicative of today’s stealthy attacker, or at least, not before it is too late – networks are simply too big and too complex. And in an age where we’ll soon see machines fighting machines, far outpacing human security teams’ ability to keep up, arming up with cyber AI will be crucial to staying one step ahead of an ever-evolving adversary.

CISO MAG does not evaluate the advertised product, service, or company, nor endorse any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Twitter Inadvertently Exposes Users’ Email and Contact Details

PM Modi Twitter

A security blunder by Twitter exposed phone numbers and email addresses of its users who opted for two-factor authentication (2FA) protection. The social networking company stated that user contacts had been used for targeted advertising purposes.

In an official statement, Twitter stated that an error in its ‘Tailored Audiences and Partner Audiences advertising system’ unintentionally used the information, provided by users, to run targeted ads.

“We recently discovered that when you provided an email address or phone number for safety or security purposes (for example, two-factor authentication) this data may have inadvertently been used for advertising purposes, specifically in our Tailored Audiences and Partner Audiences advertising system,” Twitter said in a statement.

Tailored Audiences system allows advertisers to target ads to customers based on the advertiser’s marketing lists.  Twitter stated its unclear how many users were impacted by this error. However, the company assured its users that no personal data was ever shared externally with its advertising partners.

“We’re very sorry this happened and are taking steps to make sure we don’t make a mistake like this again. If you have any questions, you may contact Twitter’s Office of Data Protection through this form,” Twitter added.

Previously, the microblogging giant similarly apologized to its users after it discovered and fixed a security bug that could have exposed users’ phone country codes and locked account details.

Twitter stated they noticed unusual activity in its Application Programming Interface (API) and observed a large amount of traffic coming from IP addresses located in China and Saudi Arabia. Twitter stated the bug was fixed on November 16, 2018, and informed the users that may have been affected due to the security bug. Twitter said the IP addresses might have been linked to state-sponsored actors, and the company is investigating the same to find the origins.

Trend Micro partners with Snyk to Fix Vulnerabilities for DevOps

96% of Cybersecurity Professionals are Happy With Their Roles

Trend Micro, a cybersecurity and defense company, recently announced a strategic partnership with the developer-first security company Snyk to help businesses cope with potential vulnerabilities without interrupting the software delivery process.

The new alliance integrates open source vulnerability intelligence from Snyk with Trend Micro’s comprehensive ability to detect vulnerabilities for teams operating in a DevOps environment.

Based out in Japan, Trend Micro is a major player in the information and network security landscape. Founded in 1988, the company holds a variety of cybersecurity merchandise for multiple operating systems, including threat detection, and antivirus products. Hybrid cloud security, network defense, user protection, and small business products are at the core of its product line.

Snyk helps enterprises in detecting and fixing the vulnerabilities and license violations in open source dependencies. The company claims that its security solutions platform is built on a comprehensive, proprietary vulnerability database, and maintained by security veterans in Israel and London.

“When it comes to DevOps, Trend Micro gets it,” said Geva Solomonovich, chief operating officer at Snyk. “We’re excited to partner with Trend Micro to bring their enterprise customers an easy and scalable way to fix open source vulnerabilities. Together, we will continue to help organizations improve their ability to find vulnerabilities earlier in the development process and provide options for how to mitigate and prevent risk in software development.”

“Snyk’s approach and trust they’ve built directly with the development community is unmatched,” said Kevin Simzer, chief operating officer at Trend Micro. “Our collaboration demonstrates both companies’ understanding of the tools developers needs and how we can provide security without getting in their way. This strategic partnership is the start of future collaboration as we both work to secure the DevOps workflow.”

Recently, Trend Micro launched its new headquarters in Singapore for Asia-Pacific, Middle East and Africa (AMEA) operations. The latest facility will be a part of Trend Micro’s new managed detection and response (MDR) security operations center across North America, Europe, and Southeast Asia.

Trend Micro stated its new center comprises an executive briefing area to host cybersecurity sessions for customers and government officials in the AMEA region. The company is also offering Certification Programs in IT Security to train the security officials in Singapore.

Researcher Discovers Unpatched Zero-Day Flaw affecting Latest Android Phones

GO SMS Pro Android App Still Vulnerable to Data Exposure

Security researchers exposed an unpatched Zero-Day flaw in Android devices. The flaw, which was discovered under active exploitation, targets most of the Android smartphones from popular brands.

According to Google’s Project Zero researcher Maddie Stone, the vulnerability named CVE-2019-2215 could allow an attacker to gain root access to the target devices. It’s said that the bug will not affect older smartphones.

“The bug is a local privilege escalation vulnerability that allows for a full compromise of a vulnerable device. If the exploit is delivered via the web, it only needs to be paired with a renderer exploit, as this vulnerability is accessible through the sandbox,” Maddie Stone said in an official statement. “This issue is rated as High severity on Android and by itself requires installation of a malicious application for potential exploitation. Any other vectors, such as via a web browser, require chaining with an additional exploit.”

The researcher stated that the bug poses a threat to the latest smartphones running on Android 8.x, 9.x, and the preview version of 10. The affected models include, Google – Pixel 1, Pixel 1 XL, Pixel 2, Pixel 2 XL; Samsung – S7, S8, S9; Xiaomi – Redmi 5A, Xiaomi Redmi Note 5, Xiaomi A1; Huawei – P20; Oppo – A3; Motorola – Moto Z3, and LG – Oreo LG phones.

“We have evidence that this bug is being used in the wild. Therefore, this bug is subject to a 7-day disclosure deadline. After 7 days elapse or a patch has been made broadly available (whichever is earlier), the bug report will become visible to the public. We have notified Android partners and the patch is available on the Android Common Kernel. Pixel 3 and 3a devices are not vulnerable while Pixel 1 and 2 devices will be receiving updates for this issue as part of the October update,” Google said in a statement.

Google stated that it will release a patch with its October Android security update shortly after phone manufacturers’ approval.

Security threats to Android devices have increased in recent times. According to security firm Check Point Software Technologies, more than half of modern Android smartphones, including models by Sony, LG, Samsung, and Huawei are vulnerable to a text-based phishing attack.

The malicious actors are using fake phone provisioning messages to trick Android phone users into accepting new settings that provide access to attackers. The researchers stated that the phishing attack is performed through a process called over-the-air (OTA) provisioning.

CheckPoint detailed the attack process as OMA CP (Open Mobile Alliance Client Provisioning) instructions, which is a special SMS sent by a mobile operator to new devices for a network connection. Attackers sending fake OMA CP messages to users, which allow them to allegedly access the victim’s email and web traffic, Check Point stated.

CERT-In Chief Reveals Spurt in Cybersecurity Incidents in India

Dr. Sanjay Bahl, Director General, Indian Computer Emergency Response Team (CERT-In)
Dr. Sanjay Bahl, Director General, Indian Computer Emergency Response Team (CERT-In)

By Brian Pereira

CERT-In is the Indian Chapter of the global Computer Emergency Response Team (CERT), and it has been in existence since 2004. The Indian Information Technology Amendment Act 2008 denotes CERT-in as the national agency to perform various cybersecurity functions, primarily, the collection, analysis and dissemination of information on cyber incidents in India. Speaking at the CSI-InfoComm Summit 2019, in Mumbai last month, Dr. Sanjay Bahl, Director General, Indian Computer Emergency Response Team (CERT-In) said the alerts, advisories and vulnerability analysis that it issues increased from 276 to 436 between 2017 and 2018. He also said that the response activity within CERT-in has increased tremendously.

“In 2015, we were providing a response activity every 10 minutes. But since 2018, we are expected to provide a response activity every two and a half minutes. And we operate 24×7 and 365 days in the year,” said Dr. Bahl. “This shows that reporting has increased. Awareness has also increased. And it also means that ICT penetration in the country has increased.”

CERT-In performs detailed analysis and investigations of cyber incidents and produces vulnerability analysis, alerts, advisories and reports. It is now issuing such alerts and reports every two and half minutes.

“This is due to the increase in the number of products and the frequency of versions. These products have security bugs and have not been completely tested for security. Secondly, we are also seeing new zero-day vulnerabilities that are being exploited. The type of targeted attacks that are happening has also raised the number of security alerts and advisories,” said Dr. Bahl.

Dr. Bahl spoke about the nature of attacks observed by CERT-in. This includes financially motivated crime by state and non-state actors. He told the audience that Advanced Persistent Threat (APT) actors are collaborating to conduct espionage and also financial fraud attacks using the same infrastructure, techniques, tools and processes.

“We are seeing customers being targeted through attacks on their Managed Security Service Providers (MSSPs). We are seeing modular malware, ransomware, crypto-mining attacks and DDoS attacks. These abuse the Internet infrastructure as well as IoT,” he said.

CERT-In also notes the increase in data leaks occurring through unsecured cloud services. It attributes this to misconfiguration issues.

“We observe the spread of automated misinformation and influencing campaigns by state and other malicious organizations, through social media,” said Dr. Bahl. “They are also looking to compromising the privacy of individuals by pushing malware through social media.

There is also tampering of global supply chains, SIM swapping, and SIM hijacking for financial fraud.”

CERT-In’s activities can be classified into four distinct areas: cyber incident response, cyber assurance, cyber intelligence, cyber cooperation and collaboration. It has been empowered by the IT ACT to impose strict action against individuals or organizations that do not report security incidents.

“Incidents need to be reported to CERT-In. All reported incidents are kept confidential.  If incidents are not reported then CERT-In can impose a penalty of Rs 100,000 or one-year imprisonment or both. And this is enforced by the Indian IT Act,” said Dr. Bahl.

Rs 100,000 is equivalent to US$ 1,408.62. 

CISO MAG was invited to attend the CSI-InfoComm Summit 2019.

Negligent Users are Biggest Cybersecurity Threat to German Organizations: Survey

Insider attacker leak data

You are only as strong as your weakest link and the cybersecurity industry is no different. A recent survey by SolarWinds, a provider of IT management software, pointed out that negligent users are the biggest cybersecurity threat to German organizations. The company did the survey in a bid to highlight the threats the cybersecurity professionals are facing daily.

The research, which surveyed over 100 information technology professionals from Germany, stated that user errors constituted the largest share of cybersecurity incidents in the last 12 months, at a whopping 80 percent. The study stressed on the fact that internal factors are the most pressing cybersecurity threats. User errors were followed by exposures caused by poor network system or application security at 36 percent, and external actors infiltrating the company’s network at 31 percent.

To understand the factors contributing to the trend, the survey also found out that poor passwords were one of the major concerns for German techies. Nearly 45 percent of the respondents stated that poor and weak passwords were one of the biggest reasons for the breaches, while 42 percent of the respondents stated that sharing passwords is also another grave contributor. Other factors were accidental exposure, deletion, modification of critical data and even copying data into unsecured devices.

To top it all, it was also revealed that 89 percent of IT experts felt that they were unequipped to successfully implement and manage cybersecurity tasks today, with their current IT skillset.

“Our research shows once again that the biggest risk to the organization comes from the inside, aligning with research SolarWinds conducted in other regions earlier this year,” said Tim Brown, vice president of security, SolarWinds. “This underscores the continued need for organizations to address the human side of IT security and consistently educate users on how to avoid mistakes while encouraging an environment of learning and training. However, that alone is not enough; tech pros also need the best possible technology to effectively fight against both threats from the inside and potentially more sophisticated threats from the outside. SolarWinds is committed to helping IT and security teams by equipping them with powerful, affordable solutions that are easy to implement and manage. Good security should be within the reach of all organizations.”

It is not always an accidental error from insiders; sometimes these incidents are a part of a much larger scheme. Earlier this year, a recruiter from the telecommunications company AT&T Network was charged for paying insiders to upload malware on the company’s computer networks to unlock cell phones.

According to the United States Department of Justice (DOJ), the insiders, who worked in AT&T’s Bothell Customer Service Center, allegedly exploited AT&T’s proprietary locking software to remove millions of phones from the AT&T network system and payment plans, which incurred a loss of a million dollars to the company. It’s said that Fahd and his co-conspirators gave over $1 million in bribes to install malware and spying devices in the company.

U.S. Agreed to Secure Baltic Energy Grid Against Cyber-attacks

The United States and Baltic states recently signed a cooperation deal to protect the Baltic energy grid from cyber-attacks.

The energy partnership agreement, termed as “a critical moment for the Baltic States in strengthening cybersecurity,” was signed by the U.S. Secretary of Energy, Rick Perry, with Estonian, Lithuanian and Latvian counterparts during a meeting in Vilnius, Lithuania recently.

As per the new cooperation deal, the U.S. government has agreed to support the Baltic energy grid protection, as they disconnected from the Russian electricity grid.

The Baltic trio, Lithuania, Latvia and Estonia, are still part of the Russian-controlled power grid, despite joining the European Union and NATO in 2004. Lithuania state said it’s looking for U.S.-based technology companies that can build a standard security software to prevent cyber-attacks from Russian hackers.

“We are committed to working with our allies in Lithuania, Latvia and Estonia as these countries chart their energy future, and enhance their economic and national security through greater energy security,” Rick Perry tweeted.

“Great sitting down with @Skvernelis_S to discuss the strong energy partnership between the US and Baltic states. Together, we will ensure the diversification of energy supplies from reliable sources for the Baltic countries. It is an honor to sign this joint statement implementing the principles of PTEC with Estonian Minister of Economic Affairs and Infrastructure Taavi Aas, Latvian Minister of Economics @ralfsnemiro, and Lithuanian @MinEnergyLT Žygimantas Vaičiūnas,” Perry added.

Canon and McAfee Join Hands to Prevent Security Threats

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Device-to-cloud cybersecurity company McAfee recently announced its strategic partnership with Canon to help businesses with embedded protection against malware for applications running on Multi-Function Devices (MFDs).

As per the new alliance, McAfee integrates its Embedded Control platform as an additional security feature on the new Canon imageRUNNER ADVANCE Generation 3 MFDs, which helps businesses strengthen endpoint security.

Headquartered in Japan, Canon is diversifying businesses across the world, including developing optical technologies, consumer and professional imaging devices, network cameras, healthcare, and industrial equipment.

McAfee claims that its Embedded Control platform protects devices like ATMs and retail point-of-sale systems against zero-day and advanced persistent threat (APT) attacks. It also reduces the risk posed by sophisticated malware like viruses and Trojans.

Commenting on the new alliance, K Bhaskhar, Vice President Canon India, said, “Security is among the top priorities of businesses today as cyber threats continue to develop in sophistication. Our imageRUNNER ADVANCE MFDs are highly secure by design, but with the ever-evolving cybersecurity landscape, we strive to bring our customers the latest in security and innovation. We teamed up with McAfee in a strategic partnership to provide our customers with the most up-to-date security, helping them protect their connected devices and valuable data against today’s vulnerabilities and tomorrow’s unknown threats.”

“As the number of connected devices in an organization grows, so do the risks from malware and attacks,” said Brent Smith, Director of OEM Sales, McAfee. “McAfee Embedded Control ensures the integrity of systems by only allowing authorized access to devices and blocking unauthorized executables. We are excited about this partnership with Canon to help provide their customers with greater assurance that confidential business data will remain protected.”

McAfee forged multiple partnerships in recent times. McAfee acquired NanoSec, a Container Security Startup, to improve its compliance and to mitigate the risk of its container deployments. NanoSec is a multi-cloud and zero-trust application security platform that’s focused on the container approach to application security. The new acquisition allows McAfee to boost its MVISION Cloud and MVISION Server Protection products.

In June 2019, McAfee joined hands with Amazon Web Services (AWS) to offer cloud-based security solutions. As per the alliance, the company announced its Database Security for Amazon Relational Database Service (Amazon RDS). McAfee stated its new security product delivers real-time visibility into all database activities and offers monitoring services to prevent sophisticated attacks.

The new alliance allows users to benefit from real-time protection for database workloads migrated to Amazon RDS while monitoring databases. McAfee claims that its newly designed database Security platform is a highly scalable software solution that monitors the database management system.

Former Yahoo Employee Hacks 6,000 Accounts to Steal Personal Data

Yahoo data breach

A former Yahoo software engineer, Reyes Daniel Ruiz, pleaded guilty for hacking into the personal accounts of over 6,000 Yahoo users, including his friends and colleagues accounts. The California-based hacker previously worked as a reliability engineer for Yahoo! Mail service for more than ten years.

According to the U.S. Attorney Office, Ruiz used his role at work to access internal Yahoo systems and crack passwords to hack accounts, which mostly belong to younger women.

The researcher turned hacker admitted that he made copies of images and videos that he compromised and stored on his personal computer. After gaining the mail access, the hacker compromised other accounts, like Facebook, Gmail, iCloud and DropBox, where he searched for private images and videos.

“Reyes Daniel Ruiz pleaded guilty in federal court in San Jose to hacking into the accounts of thousands of Yahoo users in search of private and personal records, primarily sexual images and videos of the account holders,” said United States Attorney David L. Anderson and Federal Bureau of Investigation Special Agent in Charge John F. Bennett.

The hacker was charged with one count of Computer Intrusion and one count of Interception of a Wire Communication. His sentencing hearing is scheduled for February 2020.

Most of the users of Yahoo services suffered data breach issues in multiple security incidents. Recently, Yahoo agreed to pay US$ 117.5 million for a series of data breaches that affected its users between 2012 and 2016. The affected users will likely get US$ 100 in compensation or two years of credit monitoring services for free.

Yahoo urged the Settlement Class Members to claim for the reimbursement. In case of users already hold credit monitoring services, they can opt for cash payment, which is less than US$ 100 or more (up to US$ 358) per user, depending on how many users are claiming for the settlement, Yahoo said in a statement. According to Yahoo, anyone who had a Yahoo account between January 1, 2012, and December 31, 2016, and is a resident of the United States or Israel is eligible for the settlement.

Indian Users Third Most Affected by Formjacking Attacks: Survey

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

A recent survey from cybersecurity firm Symantec revealed that internet users in India were the most exposed to Formjacking attacks after the U.S. and Australia.

In Formjacking attacks, cybercriminals inject malicious JavaScript code into retailers’ websites to steal shoppers’ payment card details. The implanted malicious code alters the behavior of the targeted website to steal payment card data and other sensitive information in the background, without a user’s knowledge. Attackers use the stolen information to perform financial frauds or sell them on the dark web market.

In its survey report, Internet Security Threat Report (ISTR), Symantec stated that nearly  52 percent of all Formjacking attacks targeted users in the U.S. and 8.1 percent of the attacks targeted users in Australia during the first half of 2019. While India is positioned third with 5.7 percent of Formjacking attacks.

Symantec stated that it monitors billions of URLs and blocked an average of 63 million malicious web requests per day in May 2019. The security firm also revealed that it prevented more than 1.1 million formjacking attacks.

“We expect this formjacking trend to continue and expand further to steal all kinds of data from web forms, not just payment card data. This also means that we are likely to see more software supply chain attacks. Unfortunately, formjacking is showing no signs of disappearing any time soon. Therefore, operators of online stores need to be aware of the risk and protect their online presence,” Symantec said in its report.

In its earlier report, Internet Security Threat Report (ISTR), Symantec stated that cybercriminals are doubling down on alternative methods to make money. The ISTR provides an overview of the threat landscape, including insights into global threat activity, cybercriminal trends, and motivations for attackers.

The survey highlighted that more than 4,800 unique websites are compromised with Formjacking code every month globally. Symantec blocked more than 3.7 million Formjacking attacks on endpoints in 2018, with nearly a third of all detections occurring during the busiest online shopping period of the year – November and December. While a number of well-known retailers’ online payment websites, including Ticketmaster and British Airways, were compromised with Formjacking code.

The report analyzes data from Symantec’s Global Intelligence Network, the largest civilian threat intelligence network in the world, which records events from 123 million attack sensors worldwide, blocks 142 million threats daily and monitors threat activities in more than 157 countries.