Home Blog Page 287

Study Reveals Major Security Challenges Companies Face

Cyber security operations

Panaseer, a Continuous Controls Monitoring platform for enterprise cybersecurity, recently revealed the results of its study conducted by Forrester Consulting. The study, named Cybersecurity Requires Controls Monitoring to Ensure Complete Asset Protection, uncovered the biggest challenges facing security leaders.

The findings are based on the responses from over 250 senior security decision-makers from organizations ranging from 3,000 to over 25,000 employees, in North America and Europe.

According to the survey, 86 percent of security leaders are confident that they have no gaps in their security controls deployed across devices, applications, people, and data. Also, 64 percent of companies are making it a priority to implement a risk framework aligning cybersecurity risk and enterprise risk.

The survey opined that the difficulty of today’s IT infrastructures is making it difficult for security leaders to protect their networks. Around 97 percent of the companies experience troubles with their security tools as they use a traditional approach to prevent cybersecurity threats.

According to the survey, the biggest challenges that security pros face with their security tools are: Controlling coverage gaps across security levels; controls do not meet regulatory and compliance policies; getting a real-time view of corporate risks; tracking performance of security controls over time; and Collecting, normalizing, aggregating, deduplicating, and correlating disparate data.

“Rightfully, companies are prioritizing their security and risk initiatives and investing in multiple technologies. Unfortunately, technology investments have provided a false sense of confidence in their security posture. Security leaders must understand that a proactive approach to cybersecurity requires the right tools, not more tools,” the study cites.

“Traditional security tools are insufficient for proactive cybersecurity as they don’t provide a complete, real-time view of cybersecurity risk. Threats are becoming more advanced, attackers savvier and regulation is tightening. This has created a clear market requirement for automated continuous controls monitoring, a new category of solution that provides real-time visibility of assets. The ability to make informed operational security decisions based on trusted security data and metrics will enable security leaders to have real and validated confidence that the company and customer data is protected,” said Nik Whitfield, CEO of Panaseer.

Hackers take over Smart Home

Google Smart Home Hack

With technology making lives easy day by day, cybercriminals too are finding innovative ways to get into our lives. Along with the ease of access, security and privacy are also imperative in this digital age, where our lives are connected with IoT devices.

A Milwaukee-based couple suffered a horrifying incident after their Smart Home setup was hacked by unknown intruders. The couple had installed a Nest system, (a setup of camera, doorbell, and thermostat) in their home last year.

According to Fox 6 News, the couple Samantha and Lamont Westmoreland stated that hackers took over their smart home by compromising the connected devices. The attacker played disturbing music from the video system at high-volume while talking to them via a camera in the kitchen, and also changed the room temperature to 90 degrees Fahrenheit by exploiting the thermostat, the couple stated.

Initially, the couple thought it was a technical glitch and changed their passwords, but the issue continued. The duo later changed their network ID, after realizing that someone hacked their Wi-Fi or Nest system.

“If someone hacks into your Wi-Fi, they shouldn’t be able to have access to those Nest devices without some sort of wall they have to get over,” said Lamont Westmoreland in a statement. “Maybe there are some steps we should take,” said Lamont Westmorland. “I think Nest should be tightening security.”

Commenting on the issue, a Google spokesperson said, “Nest was not breached. These reports are based on customers using compromised passwords (exposed through breaches on other websites). In nearly all cases, two-factor verification eliminates this type of security risk,”

“Nest users have the option to migrate to a Google Account, giving them access to additional tools and automatic security protections such as Suspicious activity detection, 2-Step Verification, and Security Checkup. Millions of users have signed up for two-factor verification,” the spokesperson added.

How Tesla has always vouched for safe and secure cars

Tesla avoids cyberattack, tesla zero-click vulnerabilities

By Augustin Kurian

Until the late 2000s, electric cars had a reputation for being ugly and slow. This was until a small Silicon Valley startup decided to go ahead and not only challenge the thought but even change it. This was the story of Tesla Motors. The carmaker also promised to make a luxury electric sports car that could go more than 200 miles on a single charge. The result was the Tesla Roadster, a battery electric vehicle (BEV) sports car, high on adrenaline and even cybersecurity.

Roadster was followed by the Model S, a luxury sedan from the automaker with oodles of power under the hood. This was followed by the Model X which continues to be one of the fastest and futuristic SUV ever rolled on world’s tarmac. Then came along the baby sibling, the Model 3, a budget electric sedan for the masses.

It is not only Tesla’s story of making electric cars cool, but also the safety and security of these all-electric connected cars also stood out from the rest— even the ones who came much later to the party. In 2015, automaker Fiat Chrysler had to issue a recall for almost 1.4 million vehicles after researchers Charlie Miller and Chris Valasek of Wired demonstrated a wireless hack on Jeep Grand Cherokee, taking over the controls of the dashboard, steering wheel, powertrain, and even the brakes.

In 2016, while Tesla was showing off its technological prowess Nissan had to shut its proprietary app Nissan Connected EV for its Leaf line-up after it was found that hacker could access the cars’ climate control and other battery-operated features to drain the batteries.

Where every other manufacturer goes wrong?

At a time when cars have become computers on wheels, the situation isn’t all that rosy on the part of security. A study by Ponemon stated that nearly 30 percent of companies in the automotive segment does not have a proper cybersecurity team to handle its technology and security infrastructure, let alone secure smart cars. The state is so dire that many do not even engage a third-party vendor to secure the software in the connected cars.

The study also pointed out that nearly 63 percent of all vehicle manufacturers do not even test half of their software, hardware and other technology deployed in their vehicles. The study sampled 15,900 IT security practitioners and engineers in the automotive industry.

How Tesla does it differently?

According to several cybersecurity experts, Tesla cars are the toughest to hack. “Tesla is on the path to be the most secure car,” David Kennedy, the CEO of TrustedSec, told Tech Insider. “I don’t think that they’re there yet, but I think they’re definitely striving for it.”

He also opined how for Tesla, security is never an afterthought. According to him, Tesla has a newer approach because it is relatively a newer brand. From early this year the company also held its often redundant bug bounty program, which gave white hat hackers opportunities to hack the system of Tesla and take home a brand-new Tesla Model 3. The most recent one was the fifth year the company took a bug bounty program.

“We develop our cars with the highest standards of safety in every respect, and our work with the security research community is invaluable to us,” David Lau, vice president of vehicle software at Tesla, said Monday in a statement. Alike technology companies, even Tesla marks its attendance at hacking conferences. For a car manufacturer, it is relatively a newer phenomenon.

Another reason why Tesla functions more like a technology firm is because Tesla is known to have its own operating system and is more on the lines of being an “iPhone on wheels,” where the company periodically pushes “over-the-air” updates to its customers’ car overnight – these include new features (like raising the ground clearance) and security updates.

It is also quite an obvious sight when Tesla goes out of its way to reward researchers who have found flaws with the cars. Most recently, a video surfaced online when Chinese researchers demonstrated a method by which they could remotely open the trunk, turn on the windshield wipers, and even apply the brakes in a new Model S.

The first thing Tesla did was to update its firmware and released an over-the-air software update within 10 days after the vulnerability was notified. The company also maintained that the risk to customers from the vulnerability was very low.

The company then did the most obvious thing you would expect Tesla to do. “We commend the research team behind today’s demonstration and plan to reward them under our bug bounty program, which was set up to encourage this type of research,” the company says in a statement.

Here is the thing: breaches, vulnerabilities, and cyber-attacks have grown exponentially. The automotive segment isn’t any different. In present-day cars, automobile design and architecture include several software and applications at the core–making it imperative for manufacturers to consider security by default–not as an afterthought. Automakers must understand that the first step toward securing their car must begin with making cybersecurity imperative, and eventually, they’ll catch up with Tesla.

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

RiskSense Reveals Major Vulnerabilities used in Enterprise Ransomware Attacks

Ransomware attacks, ransomware, Sinclair Broadcast group

RiskSense, a cyber risk management company, recently revealed the list of topmost vulnerabilities used across multiple ransomware attacks targeting public and private enterprises. RiskSense published its findings in the research report dubbed RiskSense Spotlight Report for Enterprise Ransomware.

The RiskSense report gathered data from a variety of sources including findings from RiskSense threat researchers, publicly available threat databases, and RiskSense proprietary data. The company identified 57 vulnerabilities which are most commonly used by ransomware and vulnerabilities that are still exploited today.

According to the research findings, nearly 65 percent of attacks are targeted on high-value assets like data servers, around 35 percent of attacks used old flaws, and the WannaCry vulnerabilities are still being used. The research also highlighted that Ransomware cost businesses more than $USD 8 billion in 2018.

Formerly known as CAaNES, RiskSense was founded in 2006 by Srinivas Mukkamala. The company aids private and government organizations to reveal cyber risks and provides clear remediation guidance to fix them. RiskSense’s technical team joined forces with the U.S. Department of Defense and U.S. Intelligence Community on applying artificial intelligence to cybersecurity threats as a part of the CACTUS (Computational Analysis of Cyber Terrorism against the U.S.) project.

“While consumer ransomware targets Windows and Adobe vulnerabilities, enterprise ransomware targets high-value assets like servers, application infrastructure, and collaboration tools, since they contain an organization’s critical business data,” said Srinivas Mukkamala, CEO of RiskSense. “While not totally unexpected, the fact that older vulnerabilities and those with lower severity scores are being exploited by ransomware illustrates how easy it is for organizations to miss important vulnerabilities if they lack real-world threat context.”

Accenture Partners with AXA XL to Offer Cybersecurity Services

NCSC and Microsoft Cyber Accelerator program

Technology company Accenture recently partnered with risk management service provider AXA XL to offer cybersecurity services to AXA XL’s clients.

AXA XL offers casualty, property, financial lines, and insurance solutions to enterprises, globally. The new alliance helps AXA strengthen their cyber capabilities to prevent and recover from cyber-attacks. As per the partnership deal, Accenture is going to provide post-breach security services for AXA XL clients, including incident management and IT forensic services.

Commenting on the new partnership deal Jason Harris, chief executive of AXA XL, said, “We are very excited to announce this comprehensive security partnership, which is designed to identify and serve the cyber-related needs of our clients. As a leader in the cyber insurance market, AXA XL is committed to being a trusted partner in helping our clients improve their cybersecurity. It is paramount that we promote improved cybersecurity while also protecting clients from an insurance perspective in a transparent and forward-thinking way.”

“Cyber risk is one of the biggest threats facing businesses and is profoundly under-insured. In fact, our own research has shown that over the next five years, cyberattacks could cost companies US$5.2 trillion in value-creation opportunities. While this presents insurers with opportunities, the challenges involved in underwriting cyber insurance are significant, especially given the lack of historical data and the rapid evolution of cyber threats,” said Sushil Saluja, a senior managing director at Accenture.

Accenture recently launched Accenture Federal Services (AFS) Cyber Center, a state-of-the-art facility in San Antonio that provides cybersecurity capabilities on an as-a-service basis to help government agencies and the Department of Defense manage, detect and respond to the increasing volume and velocity of cyber threats that target government networks.

The Cyber Center offers a suite of security-as-a-service solutions and leading-edge capabilities in advanced adversary simulation, orchestration & automation, and managed detection and response.  An interdisciplinary team of advanced cyber defense experts deploys advanced technologies — including artificial-intelligence-based cyber intelligence — to help government agencies quickly and cost-effectively identify, emulate and eliminate threats.

Around 169 Million Customer Records Exposed in Healthcare Data Breaches: Study

Healthcare Data Breaches, Premier Diagnostics data exposed

More than 169 million people lost their health records in healthcare data breaches over the past decade, a joint study from Michigan State University and Johns Hopkins University revealed.

The study, which got published in the medical journal Annals of Internal Medicine, analyzed around 1461 health care breaches reported to the Federal government between October 21, 2009, and July 1, 2019. The exposed Patient Health Information (PHI) included patient’s diagnosis, lab results, treatment, and prescriptions along with personal data, including patient names, date of birth details, e-mail addresses, phone numbers, social security numbers, and driving license details.

According to the survey findings, 71 percent of breaches affected 159 million patients, compromising their demographic or financial information, which can be exploited by cybercriminals for identity theft or financial fraud.

Cybersecurity experts say hackers are increasingly targeting the healthcare industry to steal sensitive medical information and sell it on the black market. A recent survey from cybersecurity company Carbon Black stated the rate of cyber-attacks on healthcare industry appear to be increasing exponentially.

In its survey report Healthcare Cyber Heists in 2019, Carbon Black has disclosed what is happening to the Personal Health Information (PHI) that was stolen by cybercriminals. The survey, which involved 20 of the healthcare industry’s Chief Information Security Officers (CISOs), found the healthcare sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that PHI is worth three times more than other personal information since the health information never changes and can be used by cybercriminal groups for extortion or compromise.

The survey revealed that around 83 percent of surveyed healthcare organizations stated they’ve seen an increase in cyber-attacks over the past year and over 66 percent surveyed said that cyber-attacks have become more sophisticated over the past year.

Researchers Discover Banking Malware ‘ATMDtrack’ Targeting Indian Banks

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

Security experts discovered a malware that’s intended to exploit ATMs of India Banks and steal customers’ sensitive information. The malware, dubbed ATMDtrack, allows the attackers to read and store customers’ card data when they are inserted into the infected ATMs.

According to Konstantin Zykov, a researcher at Kaspersky Labs, the attacker who created the ATMDtrack has been traced to the cyber-hacking outfit Lazarus Group controlled by North Korea’s primary intelligence bureau.

The scandalous Lazarus Group is a prime suspect in a series of cyber-muggings, including the cyber- attack on Sony Pictures Entertainment in 2014, and the WannaCry ransomware attack in 2017.

North Korea was accused multiple times earlier for stealing valuable information and cryptocurrencies. Through the years, North Korea has been linked to a series of cyber-attacks, either to display its cyber prowess or just to fund their activities. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from a Bangladesh Central Bank account at the New York Federal Reserve, and move it to Sri Lanka.

“Our investigation into the Dtrack RAT actually began with a different activity. In the late summer of 2018, we discovered ATMDtrack, a piece of banking malware targeting Indian banks. Further analysis showed that the malware was designed to be planted on the victim’s ATMs, where it could read and store the data of cards that were inserted into the machines. Naturally, we wanted to know more about that ATM malware, so we used YARA and Kaspersky Attribution Engine to uncover more interesting material: over 180 new malware samples of a spy tool that we now call Dtrack,” said Konstantin Zykov in a statement.

“When we first discovered ATMDtrack, we thought we were just looking at another ATM malware family because we see new ATM malware families appearing on a regular base. However, this case proved once again that it is important to write proper YARA rules and have a solid working attribution engine because this way you can uncover connections with malware families that have appeared in the past. One of the most memorable examples of this was the WannaCry attribution case,” Zykov added.

EC-Council’s CISO MAG Summit & Awards Middle East edition to kick-off

CISO MAG Middle East Awards

The future is being rewritten and we can very confidently vouch for the Middle East to compete against the most advanced regions in the world. The GCC region has already joined the bandwagon of digital arenas that are paperless, fast-track, high on technological advancements and innovations. Digital security, healthcare and the implementation of high-tech transportation are a few of the focus areas for the emirate. And the government has continued to extend its support for the cause. Although digitization holds the potential for rich rewards, it also brings with it, significant risks from an ever-evolving host of cyber threats perpetrated by cybersecurity adversaries: cybercriminals, nation sponsored, insiders, and cyber hacktivists. And that’s why there’s a growing interest for Cybersecurity in the Middle East.

EC-Council’s CISO MAG Summit & Awards is set to host its Middle East edition on the 21st October 2019 at JW Marriott Marquis Hotel Dubai, to recognize the efforts of several cybersecurity initiatives at the individual, corporate and government level.

The event would be graced by Sultan Al-Owais, Director of Information Technology, Prime Minister’s Office, UAE; Tony Chacko Joseph, CISO-eDirham, Public Revenue Department, Ministry of Finance, UAE; and Thomas Heuckeroth, VP Cyber Security, Group Chief CyberSecurity Officer, Emirates Group to name a few.

The event would witness a slew of panel discussions, technical rounds and discussions, and an award ceremony which would be followed by a cocktail reception.

The Middle East edition of CISO MAG Awards Global series has been sponsored by DarkTrace. Other eminent partners include QNu and DTS Solution.

The Middle East Cybersecurity market share is set to touch US$ 20 Billion by 2024. The cost of cybercrime is causing considerable concern to governments and business leaders across the globe. The GCC region has also been at the epicenter of cyberattacks. It is estimated that out of the top 10 countries with the highest cyber-attacks, three are from the Middle East. Here, government, education, energy & utilities, and BFSI industries are the most targeted verticals by cyber attackers.

It is also estimated that 90 percent of UAE business leaders and IT security practitioners believe their security solutions are outdated. While the GCC region has been at the forefront in combating cyber-attacks from across the globe, cyber-related legislation and ICT education is also the need of the hour, as regulations and education can bridge the gap between citizens and the cybersecurity. And this is transforming cybersecurity in the Middle East.

EC-Council’s CISO MAG believes that visionaries in the industry who have dedicated their corporate lives to the cause of creating a cyber secure world will be responsible for bridging this gap. Governments have also taken an active part in bringing about this change by creating awareness programs and funding the right kind of projects to lead the way for a better and more secure future. It is a historic time for all us to be a part of this global revolution in the cybersecurity domain.

Russian Hacker Pleads Guilty to JPMorgan’s Data Breach

JP Morgan Data Breach

Andrei Tyurin, a Russian hacker, pleaded guilty in the Federal Court for being involved in the theft of more than 80 million clients’ information of JPMorgan Chase & Co in 2014, making it one of the largest thefts of customer data in U.S. history. The hacker was also accused of stealing customer information from other banks, brokerage firms and financial companies in the U.S., including Fidelity Investments, E-Trade Financial, and Dow Jones & Co.

“Andrei Tyurin’s extensive hacking campaign targeted major financial institutions, brokerage firms, news agencies, and other companies.  Ultimately, he gathered the customer data of more than 80 million victims, one of the largest thefts of U.S. customer data from a single financial institution in history.  With today’s plea, Tyurin’s global reign of computer intrusion is over and he faces significant time in a U.S. prison for his crimes,” said Manhattan U.S. Attorney Geoffrey S. Berman.

According to the official statement, Tyurin will forfeit US$ 19 million and might face 15 to 20 years of the sentence. In total, Tyurin pleaded guilty for bank fraud, identity theft, computer intrusion, wire fraud, and illegal online gambling. Andrei Tyurin was extradited to New York from the Republic of Georgia last year for his involvement in the JPMorgan data breach.

In 2014, JPMorgan, the American multinational investment bank, reported a massive data theft that exposed more than 80 million customer records. The company reported that attackers compromised an employee’s personal computer and went on to gain unauthorized access to the company’s server. The bank declared that names, email and postal addresses, and phone numbers of account holders were compromised.

However, the account login credentials such as social security codes, PINs and passwords remained safe. The phishing attack was carried out in June, discovered in late July, and could not be stopped till the middle of August 2014. Prosecutors said that Tyurin was allegedly worked for Gery Shalon, an Israeli who’s facing charges over the hack in a Manhattan federal court along with two other Israelis, Joshua Samuel Aaron, and Ziv Orenstein.

Facebook Acquires Servicefriend to boost its cryptocurrency Libra

U.S. and Australia to Jointly Develop Cyber Training Platform

With an aim to make its cryptocurrency ‘Libra’ customer-friendly, Facebook recently acquired Servicefriend, an Israel-based startup that builds AI-driven bots for messaging apps, TheMarker reported.

Servicefriend, better known for its ‘Hybrid Bot Architecture’, develops bots that interact with clients via messaging or text apps, using artificial intelligence. The company claims that it provides enterprises the scalability of a bot with the intelligence and understanding of a human.

Facebook announced its cryptocurrency Libra and digital wallet Calibra in June 2019.  Libra Association is a pool of large enterprises and non-profits, including Visa, Spotify, Mastercard, Lyft, eBay, and Uber, which are responsible for processing the transactions of the crypto coin and blockchain. Despite the regulatory issues, Facebook is moving ahead with its Libra coin, which is expected to launch in 2020.

“We acquire smaller tech companies from time to time. We don’t always discuss our plans,” Facebook said in a media statement. “Facebook’s plan is to build a range of financial services for people to use Calibra to pay out and receive Libra as for example, to send money to contacts, pay bills, top up their phones, buy things and more.”

Facebook recently announced that it’s working with bug bounty platform HackerOne to launch a bug bounty program for its Libra Association. The social media giant is rewarding up to US$ 10,000 to security researchers who discover potential flaws in Libra’s testnet.

“The Libra Association launched its public bug bounty program on August 27, 2019. The Libra Bug Bounty program is intended to strengthen the security of the Blockchain. It enables developers to submit bugs and alert the association to security and privacy issues and vulnerabilities to help ensure a scalable, reliable, and secure launch,” Facebook said in an official statement.