Home Blog Page 29

Conti Ransomware Group Exploits Log4j Flaw to Compromise VMware Servers

Log4j

While organizations and security admins worldwide are immersed in mitigating the Log4j vulnerability effects, new exploits are being weaponized to entice more fear. Recently, security experts from AdvIntel revealed that Conti ransomware operators abused the Log4j flaw (CVE-2021-44228) to gain access to the internal VMware vCenter Server and encrypt vulnerable devices.

Weaponizing the Log4j Vulnerability

The researchers stated that Conti ransomware became the first sophisticated ransomware group weaponizing Log4j vulnerability. The threat actors targeted specific vulnerable VMware vCenter for lateral movement directly from the compromised network resulting in vCenter access affecting victims in the U.S. and European networks. AdvIntel has recommended that users and organizations patch their systems immediately to avoid further exploitation of the Log4j flaw.

Also Read: Log4j Explained: How It Is Exploited and How to Fix It

“AdvIntel discovered that multiple Conti group members expressed interest in exploiting the vulnerability for the initial attack vector resulting in the scanning activity leveraging the publicly available Log4j2 exploit. The current exploitation led to multiple use cases through which the Conti group tested the possibilities of utilizing the Log4j2 exploit. This is the first time this vulnerability has entered the radar of a major ransomware group,” the researchers said.

Several reports also stressed that threat actors exploited the Log4Shell flaw to deploy a new ransomware variant Khonsari and a remote access Trojan Orcus, using botnets like Mirai and Muhstik against vulnerable systems to spread malware.

Apache Issues Patches

The security concerns with Log4j continued to increase. After discovering the third critical vulnerability, the Apache Software Foundation (ASF) released one more patch. Tracked as CVE-2021-45105 (CVSS score: 7.5), the flaw is stemmed from the incomplete fix of Log4Shell vulnerability CVE-2021-44228. The flaw reportedly affects all versions from 2.0-beta9 to 2.16.0, allowing attackers to launch a DDoS attack.

“Apache Log4j2 versions 2.0-alpha1 through 2.16.0 did not protect from uncontrolled recursion from self-referential lookups. When the logging configuration uses a non-default Pattern Layout with a Context Lookup (for example, $${ctx:loginId}), attackers with control over Thread Context Map (MDC) input data can craft malicious input data that contains a recursive lookup, resulting in a StackOverflowError that will terminate the process,” ASF said in an advisory.

Facebook Issues Cease and Desist Warnings; Bans Seven Surveillance-for-Hire Groups

Facebook Data leak, Facebook bans cyber mercenary

Facebook, based on months of investigation, has banned seven cyber entities from their platform for manipulating and engaging in surveillance activity.

Facebook revealed that the surveillance services were indiscriminately targeting human rights activists, critics of authoritarian regimes, journalists, opposition parties, and dissidents.

“Today, as part of a separate effort, we are sharing our findings about seven entities that we removed from our platform for engaging in surveillance activity and we will continue to take action against others as we find them,” Facebook said.

Measures Taken

Facebook identified seven different surveillance-for-hire entities that provided services across all three phases of the surveillance chain — Reconnaissance, Engagement, and Exploitation — to indiscriminately target people in over 100 countries on behalf of their clients. These providers are supposedly based in China, Israel, India, and North Macedonia; the entities are Cobwebs Technologies, Cognyte, Black Cube, Bluehawk CI, BellTroX, Cytrox, and an unknown entity in China.

To put a reign on their services, Facebook has banned related internet infrastructure and issued Cease and Desist letters.

“Putting them on notice that their targeting of people has no place on our platform, we also shared our findings with security researchers, other platforms, and policymakers so they can take appropriate action. We alerted around 50,000 people who we believe were targeted by these malicious activities worldwide, using the system we launched in 2015. We recently updated it to provide people with more granular details about the nature of targeting we detect, in line with the surveillance chain phases framework,” shared Facebook.

Surveillance-For-Hire

Facebook explains that a global industry operates surveillance-for-hire. They target people on the digital platform to collect intelligence, manipulate them to share information and compromise their devices and accounts. This industry is burgeoning with companies that provide intrusive software tools and surveillance services indiscriminately to any customer without verifying for whom the service is being used. There is no accountability of who is being targeted and if any human rights issues are being violated. According to Facebook, the industry has banned these cyber entities, democratized these threats and made them available to government and non-government groups that mostly do not have these capabilities.

There has been an evident uproar against these so-called “mercenary spyware firms” as they have been identified to facilitate the world’s worst human rights abuses. Israel-based NSO Group, known for its surveillance software Pegasus, is only a part of the bigger cyber mercenary industry. In October 2019, Facebook sued the NSO Group for violating the Computer Fraud and Abuse Act. Recently, Apple also filed a lawsuit against the NSO Group to hold it accountable for the surveillance and targeting of Apple users.

An increasing number of tech giants are coming out in support of each other to fight against the violation by surveillance tools and software. Constant exploitation of vulnerabilities on popular platforms and brands has been a rising concern, and active collaboration amongst the giants will have a positive impact in curbing the targeted and state-sponsored attacks.

China-based Tropic Trooper Actors Target Transportation and Government Sectors

Chinese actors target telecom

Security experts identified a new cyber espionage from the Chinese state-sponsored Advanced Persistent Threat (APT) group “Tropic Trooper”  targeting transportation, health care, and government sectors across Hong Kong, the Philippines, and Taiwan. Also known as Earth Centaur and KeyBoy, the Tropic Trooper operators have been active since 2011, conducting various kinds of cyber campaigns.

According to a report from Trend Micro, the group managed to access certain internal documents like flight schedules, financial plan details, and other personal information on the compromised hosts.

Tropic Trooper’s Capabilities

  • Proficient at red teamwork
  • Bypasses security settings and keeps its operation unobstructive
  • Uses backdoors with different protocols like a reverse proxy to bypass the monitoring of network security systems
  • Leverages open-source frameworks to develop new backdoor variants

“We believe that it will continue collecting internal information from the compromised victims and that it is simply waiting for an opportunity to use this data. The activities we observed are just the tip of the iceberg, and their targets might be expanded to other industries that are related to transportation. It is our aim, through this article, to encourage enterprises to review their own security setting and protect themselves from damage and compromise,” Trend Micro said.

Also Read: Chinese Threat Actors Prey on Telcos in Southeast Asia

Tropic Trooper’s Attack Vector

Tropic Trooper initially exploited the vulnerable Internet Information Services (IIS) server and Exchange server vulnerabilities as entry points. Later the attackers deployed web shells, the .NET loader (Nerapack), and the first stage backdoor (Quasar remote administration tool aka Quasar RAT) on the compromised machine. Based on the victims, the actors installed various second-stage backdoors like ChiserClient and SmileSvr.

After successful exploitation, Tropic Trooper started Active Directory (AD) discovery and spread their tools via Server Message Block (SMB). Then, they used intranet penetration tools to build the connection between the victim’s intranet and their command-and-control (C&C) servers. In addition, the group reportedly used multiple tools to dump credentials on compromised machines.

“After successfully exploiting the vulnerable system, the threat actor will use multiple hacking tools to discover and compromise machines on the victim’s intranet. We also observed attempts to deploy tools to exfiltrate stolen information in this stage. We found evidence of specific tools by which the attackers accomplish their goals (network discovery, access to the intranet, and exfiltration) step by step,” Trend Micro added.

Chinese Hackers Targeting Power Sector

In the recent past, security research from Recorded Future found a China-linked threat actor group, dubbed RedEcho, targeting 12 Indian organizations, 10 of which were in the power sector. The researchers uncovered a subset of the servers that share familiar tactics, techniques, and procedures (TTPs) with several previously reported Chinese state-sponsored groups. Read More Here

AI/ML Can Be a Benefactor in Cybersecurity

Artificial Intelligence in manufacturing industry to reach $16bn by 2025, AI

Digitization is growing at a very fast pace, which is touching every aspect of our lives. To truly apprehend the role of AI/ML in cybersecurity, we need to understand how cyber technology and its usage has evolved.

By Shankar Karthikason, Averis Group Head of Cyber Security Strategy, Operation & Advisory

The digital era exposed us to various threats. The importance given to cybersecurity has increased tremendously. From a security professional’s perspective, the need for AI and ML is strong; looking for ways to automate the task of detecting threats and flagging malicious behavior, means moving away from manual methods which will free up time and resources to focus on other tasks.

With today’s fast-moving evolution, it’s impossible to deploy effective cybersecurity technology without relying heavily on machine learning and It’s impossible to effectively deploy machine learning without a comprehensive, rich and complete approach to the underlying data.

Cybercriminals have their ways of means to outreach potential targets in this borderless world. Over the last decade, the rise in identity theft, data breach, and money loss raised exponentially. This is where AI/ML tools and techniques are being developed to play a significant role to fight against these cybercrimes.

AI and ML are becoming major players thanks to the very fact that they’ll stop threats in real-time without impacting the day-to-day operations of the business.

Further, these technologies can keep track of data that escape the human eye, including the growing volume of transactions, video, chats, emails, and more.

Investing in AI without a clear, well-established, and mature cybersecurity program is like pouring money down the drain. One may fix one issue but may end up creating more than that or may even overlook critical and urgent issues.

So things you may want to consider firstly:

1. Identify your business needs

It’s important to first identify your business problems AI is presumably to resolve. Assess every paint point and evaluate how AI potentially will help to resolve.

2. Evaluate your companies readiness to adopt and support AI

Discover the main concern and issue surrounding your business and take a step to check if your organization is ready to adopt AI. IT infrastructure plays a fundamental role to manage and analyze the data set of AI. AI requires rich data to perform its task effectively in order for you to obtain the desired result. Start with a small sample and move on from there to see how it performs.

3. Prioritize the main values for your business.

One’s business need has been assessed, understand the business and financial benefits. Make sure to cover all possible AI applications as part of your short and long-term goals.

4. Look for valuable AI services.

Developing an AI system may take lots of time and resources. Still, there are AI service providers with industry expertise to help you understand the data needs of AI and simplify the AI integration for you.

Points to Remember for Convincing Executives to Invest

1. Do not re-invent rather just plug-In

Avoid telling the board that their entire IT investment will be replaced with some advanced product. Look into AI solutions that can be plugged into the existing system rather than redo entirely.

2. Show the numbers

Executives need the numbers such as data and funds saved. AI provides clear advantages here.

“A Deloitte study found 83% of early AI adopters have already achieved moderate to substantial economic benefits.”

3. Think long term

Do not look into the short-term impact of AI on your business but rather think beyond. Showcase the forecast of business impact and consequences of not analyzing and learning from your data.

AI/ML may already be in most organizations’ to-do list but ones should focus on how they may complement existing systems and business plans rather than boosting the hype in order to obtain internal approval. Getting buy-in on something which is new may be challenging but neglecting the growth and adoption of technologies such as AI may cause potential repercussions.

4. AI and job security

Bayt.com Co-founder and CTO Akram Assaf explains that “most risks with AI come from organizations abandoning their responsibilities. You can’t just install a system and expect it to do the job for you. That’s not how it works, and even advanced cybersecurity systems powered by AI need to be regularly maintained and updated.”

Cybersecurity providers tirelessly introduce ways to prevent and remediate threats brought by threat actors but as soon as these measures are developed, cybercriminals develop new threats to overcome this.

To stay ahead of the curve, AI emerged as a crucial tool for cybersecurity providers. AI helps to strengthen the defensive measure and speed up the response time, but it is yet to reach perfection. AI advances cybersecurity in powerful ways but will not replace human intelligence, at least for now for especially in identifying and mitigating threats. It is a common misconception that AI will replace human intelligence. AI provides the mean of improving the accuracy and efficiency of data being analyzed but when it comes to strategizing and problem-solving, the human element still plays a vital role.

Cybersecurity professionals are still required to differentiate between good and bad data and to tell whether the data is reliable. They need to frequently review the data to ensure relevancy and accuracy.  AI will produce bad analyzes if the data is inaccurate, flawed, or even biased.

At least for now, AI has not reached the level of developing complex strategies or thinking critically through complicated scenarios. People may use AI to assist with thinking through problems but ultimately it’s humans who will make the decisions.

AI will undoubtedly change the way businesses operate, creating a safer, more efficient, and data-driven working environment, and this will affect jobs but as technology improves, machines will need to be updated and replaced.

Jobs will always be available for those who understand the core working of AI systems.

5. AI will replace some jobs

AI will not replace all the jobs as the human role is vital to strengthen AI.

But it is inevitable for humans to make mistakes where computers on the other hand not influenced by human error.

Machines react based on a set of instructions that are pre-determined and execute them out such as data entry jobs. AI may potentially take over such jobs which require performing routine and mundane tasks such as typing, copy-pasting, and transcribing.

In fact, AI may compliment on top of job to provide additional pair of eye to verify your work. Aside  AI may assist in dangerous jobs which may put human life at stake such as mining, factory work, and machine assembly.

Conclusion

AI/ML can significantly change the cybersecurity landscape but it can pose both a blessing and a curse to businesses and customers.

On the other hand, AI can be very resource-intensive and may not be practical in all applications. More importantly, it also can serve as a new weapon for hackers who use the same or even better-enhanced technology to improve their cyberattacks. With the growing number of various digital devices, these hackers already have the opportunity and capability to launch rapid and complex attacks. AI then may soon offers the means to either successfully secure or successfully attack.

It may sound cliche but it’s no longer a question of if an organization will be attacked, but when. Being said cybersecurity personnel need to get out in front of this challenge now by leveraging AI/ML-assisted security solutions that provide the right and fast detection and response capabilities in order to keep pace with these advanced cybercriminals.


About the Author

Shankar KarthikasonShankar Karthikason is Averis Group Head of Cyber Security Strategy, Operation & Advisory. He brings together over 12 years of experience in conceiving and implementing key business strategies towards enhancing the trajectory of the overall operations as well as business growth.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

6 Things CISOs Must Do to Mitigate Risks from Log4j

Mitigate Risks from Log4j

Log4j has been tagged by security vendor Tenable as the “single biggest, most critical vulnerability of the last decade.” MITRE rated the vulnerability as critical and assigned a CVSS score of 10/10. News about the Log4j zero-day vulnerability (CVE-2021-44228, CVE-2021-45046) has been trending since early December. This remote code execution (RCE) vulnerability allows attackers to execute arbitrary code and take full control of vulnerable devices. Here are six things resilient CIOs and CISOs can do to mitigate risks from Log4j.

  1. Do a complete audit and assessment

The Log4j vulnerability is widespread and impacts enterprise Java-based applications like Cisco WebEx, and custom, in-house developed applications. It is imperative for CISOs and security leaders to do a complete assessment of their assets to gauge the impact of this exploit and identify which systems are affected. This audit should extend to home users and endpoint devices (including home routers) used on the enterprise network. Don’t forget to audit third-party applications from vendors and cloud-based services too. Special attention and priority should be given to systems that store sensitive information such as customer data, transactional and operational data, and intellectual property.

  1. Understand your risk exposure

In what ways have your systems been compromised? What did the hackers do? Did they change passwords? Did they drop a malware payload? Did they change configuration settings? Did they introduce another backdoor? You need to check your entire network and examine all copies of Log4j. After completing this audit, apply remedial steps (patches, mitigation strategies) to minimize risk from associated threats such as botnets, Trojans, and ransomware. Botnets like Mirai and Muhstik and ransomware variant Khonsari already exploited this vulnerability.

Read more about risk exposure in a Gartner article.

  1. Patch immediately

Apply the Apache patch Log4j 2.15.0 immediately. CISA advises affected organizations that have already applied Log4j 2.15.0 to upgrade to Log4j 2.16.0 to protect them against both CVE-2021-44228 and CVE-2021-45046.

  1. If you can’t patch, then apply mitigation strategies

It takes some time to update Java libraries and patch every system. If you are unable to do this immediately, then certain mitigation strategies can be applied.

A researcher at Sophos demonstrated some of these mitigation strategies.

Most apps have a script that starts a Java program. You can adapt your Java applications to suppress remote code execution and data exfiltration. Format your message to disable lookups (format message =true).

Another mitigation strategy recommended by Sophos is to block the Java Naming and Directory Interface (JNDI) from making requests to untrusted servers. If you are using Log4j 2.10.0 or later, you can set certain configuration values that prevent LDAP and similar queries from getting out.

Restrict egress (outbound) connectivity. Each subnet, server, and workload should be allowed to connect only to the endpoints that are required by the business. All other destinations should be blocked. Configure Access Control Lists too.

Read more on how to mitigate risks from Log4j on the Sophos blog here.

  1. Create an incident response plan

Outline the measures your organization will take to deal with this vulnerability. Update your security policies and communicate your plan to employees across all levels in the organization. C-suite and board members should be apprised of the incident and informed as to how to respond to external communication with shareholders and partners. Employees must be vigilant and should be encouraged to report any unusual behavior with their applications or endpoint devices. IT support teams should guide users to update and patch applications on endpoints, just as system administrators patch server-side applications. Remember, everyone is responsible for the organization’s information security.

  1. Don’t trust data that arrives from outsiders

It seems coders place too much trust on untrusted data. Leaving open doors in the code is an invitation for hackers to devise ways to exploit vulnerabilities and manipulate the software. When coding, do not provide options based on assumptions, for functions that users might want to use (and rarely use), because someone with malicious intentions will eventually find and misuse those options. Is your server accepting untrusted data into the log? This is where the zero-trust model and zero-trust architecture should be applied. Software should be designed to never permit untrusted or unauthorized users to use untrusted data to manipulate how that very data gets handled.

Also see:

Log4j Explained: How It Is Exploited and How to Fix It

Log4j Explained: How It Is Exploited and How to Fix It

Log4j

Log4j or Log4Shell, a critical vulnerability in the widely used Apache Log4j Library, has raised alarms and security concerns across the tech and info security communities.

By Rudra Srinivas, Sr. Feature Writer, and Minu Sirsalewala, Editorial Consultant, CISO MAG

The Log4j flaw (CVE-2021-44228), reported last week, is a remote code execution (RCE) vulnerability that enables hackers to execute arbitrary code and take full control of vulnerable devices.

What Is Log4j?

Apache Log4j is a Java-based logging utility developed by the Apache Software Foundation. Several companies use the Log4j library worldwide to enable logging and configure a wide set of applications. The Log4j flaw allows hackers to run any code on vulnerable machines or hack into any application directly using the Log4j framework.

Looking at its severity, MITRE rated the vulnerability as critical and assigned a CVSS score of 10/10.

Affected Systems and Enterprises

The vulnerability reportedly affects systems and services that use Apache Log4j versions from 2.0 up to and including 2.14.1 and all frameworks (Apache Struts2, Apache Solr, Apache Druid, Apache Flink, etc.). However, several security experts opine that it also impacts numerous applications and services written in Java.

Microsoft-owned Minecraft was the first to acknowledge the flaw, stating that the Java edition of the game was at risk of being compromised. The company has urged users to upgrade to its latest release and defend against the deployment of the Khonsari ransomware variant exploiting the Apache Log4j vulnerability. The vulnerability is also leveraged to deploy cryptocurrency miners and remote access Trojan Orcus.

“Everything across heavy industrial equipment, network servers, down to printers, and even your kid’s Raspberry Pi is potentially affected by this flaw. Some affected systems may be on-premises while others may be hosted in the cloud, but no matter where they are, the flaw is likely to have an impact,” said Glen Pendley, Deputy Chief Technology Officer at Tenable.

The vulnerable code also affects some of the prominent IT service companies and tech vendors such as Amazon Web Services, Oracle, Cisco, IBM, Fortinet, and VMware.

“This vulnerability, which is being widely exploited by a growing set of threat actors, presents an urgent challenge to network defenders given its broad use. End users will be reliant on their vendors, and the vendor community must immediately identify, mitigate, and patch the wide array of products using this software. Vendors should also be communicating with their customers to ensure end-users know that their product contains this vulnerability and should prioritize software updates,” said Jen Easterly, Director of Cybersecurity and Infrastructure Security Agency (CISA).

Log4j: It’s Severe and Getting Bad 

The flaw’s severity stresses the inevitability of known vulnerabilities, patched vulnerabilities, and half-day and zero-day exploits in the open-source code libraries, often resulting in major data breaches, supply chain attacks, or ransomware attacks.

Experts also uncovered a second critical vulnerability (CVE-2021-45046) that affects all versions of Log4j from 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0 and could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern to craft malicious input data using a JNDI Lookup pattern, resulting in a DDoS attack. However, CVE-2021-45046 can be mitigated by applying the patch released by the Apache Software Foundation (ASF) in its latest advisory.

Remedial Actions

1. CISA

Federal agencies and security personnel across the globe are working on several mitigation measures to fix this flaw and identify any associated threat activity.

CISA has urged all organizations and security admins to upgrade their systems to log4j version 2.15.0 or apply their appropriate vendor-recommended mitigations immediately to prevent any risks. “To be clear, this vulnerability poses a severe risk. We will only minimize potential impacts through collaborative efforts between the government and the private sector. We urge all organizations to join us in this essential effort and take action,” CISA said.

CISA recommends asset owners take three immediate steps to mitigate the risks from this vulnerability, which include:

  • Enumerating any external-facing devices that have log4j installed
  • Ensuring your security operations center is actioning every single alert on the devices that fall into the category above
  • Installing a web application firewall (WAF) with rules that automatically update so your SOC can concentrate on fewer alerts

For more information, visit Apache Log4j Vulnerability Guidance.

2. Apache Log4j

The Apache Log4j team has issued patches and suggested mitigation steps to address the Log4j security flaw.

  • Log4j 1.x mitigation: Log4j 1.x is not impacted by this vulnerability.
  • Log4j 2.x mitigation: Implement one of the mitigation techniques.
  • Java 8 (or later) users should upgrade to release 2.16.0.
  • Users requiring Java 7 should upgrade to release 2.12.2 when it becomes available (work in progress, expected to be available soon).
  • Otherwise, Apache recommends removing the JndiLookup class from the classpath: zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class
    Note that only the log4j-core JAR file is impacted by this vulnerability. Applications using only the log4j-api JAR file without the log4j-core JAR file are not impacted by this vulnerability.

3. Cisco Talos

Cisco Talos in its advisory recommends disabling the JNDI feature.

“For the largest segment of users, JNDI represents an unnecessary risk, so we suggest disabling this feature so that this threat surface is unavailable. Therefore, we recommend upgrading to Log4j 2.16.0—the latest version—which disables JNDI by default,” said Talos.

Per the advisory, Log4j 2.16.0 is the most recent patch Apache has released. It fixes CVE-2021-44228 and CVE-2021-45046 by:

  • Disabling JNDI by default and limiting the default protocols to Java, LDAP, and LDAPS.
  • Requiring the log4j2.enableJndi system property to be set to “true” to allow JNDI.
  • Completely removing support for Message Lookups.
  • Customers are encouraged to examine their internal and third-party usage of Log4j for vulnerable configurations and take remediation actions.

“If you are uncertain or unable to determine if your implementation is vulnerable, patch aggressively. Given the risk of third-party appliances that include Log4j, we also recommend that customers and partners conduct routine vulnerability scanning and engage in conversations with vendors, partners, and suppliers for additional mitigation support.”

4. SOPHOS

Sophos’ Naked Security revealed IPS rules, WAF rules, firewall rules, and web filtering could help by blocking malicious CVE-2021-44228 data from outside, and by preventing servers from connecting to unwanted or known bad sites. It recommends that users:

  • Patch systems right now. Don’t wait for everyone else to go first.
  • Use one of the mitigations if you can’t patch yet.
  • Be part of the solution, not part of the problem!

Experts Take 

Charlene K. Coon Commenting on the risks involved with the Log4j vulnerability, Dr. Charlene K. Coon, the Board President of Pentagon Cyber, Inc., said, “It is time for everyone to RETHINK how we approach cybersecurity, particularly in our software development. Log4j v1 reached the end of life in 2015. Log4j v2 has been around since 2015. Log4j v1 has been around since 2001, a full 20 years! Log4j v2 has been around six full years! Every version except for 2.12.2 is vulnerable. Every single one. Businesses might start getting mad that programmers are not checking their code better. We will continue to see businesses devastated by cybersecurity vulnerabilities until the industry demands better. Recently Pentagon Cyber, Inc. and Cyber Science Institute, Inc. have partnered up to drive change and offer solutions to this very large Fukushima software development issue.”

Conclusion

As the year draws to a close, and with the holiday season around the corner, we see a new shift in attack sophistication and scale. And the Log4Shell exploit sounds the alarm that it is much more serious than SolarWinds, Kaseya, or other critical infrastructure attacks reported in the last two years.


About the Authors

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Minu

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

How Does Blockchain Help with Digital Identity?

blockchain

Digital identity plays an essential role in the information security architecture of every organization. It is an online or networked identity accepted by the organization’s security layout for data and devices access. The aim of implementing digital identity is to maintain and ensure information security in the organization. Blockchain technology provides an infrastructure where data cannot be deleted, manipulated, or hacked due to the data being stored in blocks with fixed storage capacity and encryption. Incorporating digital identity with blockchain technology is crucial for the growth and viability of the digital economy. With such implementations, the level of bureaucracy is reduced while increasing the processing speed resulting in better interoperability between the sectors/departments. 

By Tim Chase, Field CTO – Enterprise, Lacework

Blockchain for Digital Identity 

Digital identity is vulnerable and can be easily compromised when stored on a centralized server. According to a statistic by tykntech, more than 600 million personal details have been hacked since 2017. Credit card numbers, addresses, and other personal/private information were stolen or were leaked. The employees/individuals register themselves by providing accurate data required for authorization and authentication on various platforms. The data entered is stored in different databases on multiple platforms. Data is changed for several reasons, such as the other user or mobile numbers or changes in bank details; therefore, the information isn’t the same across all the databases. The traditional identity management methods have various usability, privacy, security, and globalization issues. 

With time, blockchain technology has developed and evolved significantly. It is an added advantage as Blockchain is decentralized, immutable, and interoperable infrastructure, making it difficult to hack. Blockchain technology can assist digital identity management by replacing traditional identity and access management strategies with blockchain counterparts. Blockchain can authorize and allow users to manage their identities more efficiently and helps them to overcome persisting issues such as data insecurity, fraudulent identities, and inaccessibility. 

How Is Blockchain Efficiently Used in Digital Identity Management? 

Blockchain, which offers decentralized digital identity management methods, is utilized in various ways. Some of the well-known use cases of blockchain technology for Decentralized and digital identity management could be listed as follows: 

  • Self-Sovereign Identity (SSI): It involves the users storing their digital identities on their own devices and managing them on their own. Choosing what information is to be shared with others without a central authority is achieved by SSI, which can be created independent of the nation, state, corporations, or global organizations. 
  • Data monetization: It could be defined as using an individual’s personal data for calculable economic benefits. Instances that are derived from personally identifiable data significantly increase the value of the underlying data. More than 60% of the global GDP is expected to be digitalized by 2022, confirming that personal data’s value will increase with time. 
  • Data portability: Data portability involves the transfer of the user’s data from one controller directly to another without causing any chaos. EU GDPR’s article 20 grants the user the right to data portability. It enhances the user experience and removes the need to verify identities when porting the data to different and various other platforms and services. 

With the help of decentralized identifiers, any blockchain network can identify and verify the data entered was distributed by a trusted entity. This process takes place without storing the data in the database, adhering to the GDPR standards/policies. Decentralized identifiers are responsible for the separation of the data and direct identifiers. It ensures that there is no link or a connection to the user.  

Advantages of Using Blockchain in Identity Management 

There exist many benefits and advantages of using blockchain technology towards digital identity management, some of which could be listed as follows: 

  • The blockchain ledger is immutable and transparent, the fundamental factor for identity management, increasing users’ trust. 
  • Blockchain-based digital identity has many benefits, such as authentication of users over a wide range of online services or online platforms, thus reducing or eradicating multiple logins while guaranteeing a streamlined and smooth user experience. 
  • Decentralized identities are secured using the cryptography method. Private keys are only known to the user, and public keys are distributed on a large scale. The pairing of the private and the public key results in authentication when the public key holder can verify that the private key holder sends the message and encryption, where the paired private key holder possesses the decryption key to decrypt the encrypted transmission of the public key. 
  • With the help of Blockchain-based digital Identity, users can manage their own digital identities with ease. 

Future Trends and Challenges 

It is well understood that blockchain-based digital identity management is robust and encrypted to ensure security and ease of portability. Hence, mandating its effective incorporation for improving the socio-economic well-being of the users, which is mainly associated with digital identity. With time and advanced technologies, digital identity has become an essential entity that enables users to have various rights and privileges. Although Blockchain has various benefits while managing digital identities, it cannot be considered a panacea. Blockchain technology is continuously developing, and though it offers multiple benefits, there also exist various challenges when aiming to completely replace the traditional identity management methods with the latter. Some of the known challenges include the constantly developing technology and the lack of standardization of data exchange. 

Conclusion 

Considering the benefits that come with transparency and the trust earned through blockchain frameworks, numerous organizations are merging to ensure interoperability across their borders. Decentralized digital identity systems are on the rise. Almost everyone is switching from the traditional identity management systems to Blockchain-based digital identity systems, which may develop to a greater extent in the near future, with many more advantages. As the technology matures, solutions will evolve and can achieve the best interfaces with robust security.


About the Author  

Tim chaseTim Chase carries a strong technical experience in testing and quality control endorsed by many software & security engineers and leaders and is also an expert at resolving challenging security incidents. He has nearly 20 years of experience with digital and information security architecture, which augments his ability to manage security and risks. Tim is also a member of the Global Advisory Board for EC-Council, a renowned speaker, and a columnist associated with multiple cybersecurity forums, as well as a hard-core information security professional who takes pride in coaching and mentoring strong teams that deliver excellence in technology and business. 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“More States Move to Comprehensive State Laws Like the CCPA to Enhance Security Practices”

design and compliance

As 2022 peeks from the corner, there is anticipation that the year will, maybe, witness better security management to address the continued sophistication of cyberattacks, as witnessed in 2021.

The banking and finance industry, health care, critical infrastructure, and government undertakings are the most targeted and vulnerable to phishing attacks.

Angelo A. Stio IIIAngelo A. Stio III, Partner at Troutman Pepper, in an interaction with Minu Sirsalewala, Editorial Consultant, CISO MAG, shared his thoughts on how other manufacturing entities and educational institutes are continuously targeted by phishing attacks. He also reflected on the preparedness of incidence response, compliance, and safety at organizations.

Angelo is a partner at Troutman Pepper and first-chair litigator who tries cases in courts and arbitration tribunals throughout the U.S. His data privacy and security experience include counseling clients on cyber-breach response and defending clients in individual and class action matters. He works with clients across various sectors to investigate sensitive privacy and security issues and advise on applicable federal, state, and international laws.

Angelo opined, “Threat actors capitalize on impersonation attacks where they send phishing emails attributed to trusted vendors, buyers, and suppliers in the hope of intercepting invoices and redirecting payments to the threat actors account.  Manufacturing entities that do not collect PII from consumers are susceptible because they believe the information related to their business-to-business transactions is not the type that threat actors will target.  Unfortunately, threat actors look for a quick financial gain by intercepting business to business communications to redirect payments.”

The education industry also saw a surge in cyberattacks due to the sudden on-and-off shift to remote learning and online coaching. Universities and research centers made attractive targets for adversaries, with students logging in from their home networks using their personal devices. It was like opening a jar of bees, and the sting was evident.

Challenges Faced by Educational Institutes

Check Point Research (CPR) revealed that the education/research sector has displayed the highest number of attacks than other sectors. In July 2021, there was a 29% increase in attacks against organizations in the education sector compared to H121. By region, organizations in the education/research sector in South Asia are most targeted, followed by East Asia and ANZ. By country, Indian education organizations are the most targeted, followed by those in Italy and Israel.

“Institutes of higher education face challenges in privacy in security because they have many constituents with access to their networks (faculty, staff, administrators, alumni, students and vendors), utilize multiple applications and platforms in the delivery of their services, may utilize unsafe devices to allow remote access, and have budgetary challenges and resource constraints to conduct training on information practices,” said Angelo.

He added, “Higher education institutions in 2021 were targeted because of the large amounts of student data that they collect, maintain, and process.  When counseling clients, we recommend enhanced user verification through multi-factor authentication across their networks, limiting privilege access based on the need to access the information, and engaging in monitoring (either internally or through an external provider) for anomalies and threats to their environment.”

As the attacks do not seem to dwindle, the situation is exacerbated by the management of these cyberattacks. Being prepared for incidence response and taking legal recourse is essential to any organization with a digital presence.

Incidence Response

Though some industries are well equipped and have incorporated incidence response in the security design stage, it is still a desirable phase for most organizations. “Highly regulated organizations in the financial sector (which are subject to the GLBA) and health care sector (subject to HIPAA) are most prepared in terms of their information security policies and response to incidents. This is the case because these entities are subject to comprehensive information security schemes and regulators are ensuring compliance with applicable regulations.” It is essential that businesses start incorporating privacy and security into the design phase to ensure compliance and safety.

Privacy By Design

“There is a concept known as privacy by design, which focuses on embedding concepts of privacy into the design and architecture of IT systems, product development, and business practices.  Businesses are well-served to incorporate principles and privacy at the development stage of all business practices to embed security throughout the lifecycle of information being collected.  In other words, privacy by design requires components of security to be implemented from the first element of data being collected through the deletion of that data from a company’s systems,” Angelo added.

Risk of Non-compliance

Organizations are realizing the importance of cybersecurity and the governing regulations. If they do not follow compliance, the risk exposure is significant and can be very damaging both in the short and long run. Non-compliance could result in exposure to regulatory investigations, fines, penalties, statutory damages, and a major increase in private litigations being pursued on an individual and class-wide bases.

“We will continue to see more and more states move to more comprehensive state laws like the CCPA to enhance security practices and provide individuals with rights to access, correct, modify and delete their personal information.”

With increased data collaboration and global stakeholders, compliance needs to be more than just a checklist to ensure data security.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

After Colonial, Gas Distributor Superior Plus Suffers Ransomware Attack

Superior Plus, Saudi Aramco data breach

Cyberthreats continue to target organizations in critical infrastructure sectors, causing severe damage to everyday routines. North American propane supplier Superior Plus is the latest victim to join the bandwagon of ransomware attacks.

In an official release, Superior Plus confirmed that it sustained a ransomware incident that impacted its computer systems. “Upon learning of the incident, Superior took steps to secure its systems and mitigate the impact to the Corporation’s data and operations. Independent cybersecurity experts have been retained to assist the Corporation in dealing with the matter in accordance with industry best practices,” the release said.

Superior Plus is a popular distributor and marketer of propane, distillates, and related products and services, servicing over 780,000 customer locations in the U.S. and Canada.

No Data Compromised

Superior temporarily disabled its operations and applications immediately after identifying the intrusion. The company also clarified that there was no evidence of any misuse or breach of customer or corporate data. While the adversaries behind this incident are unknown, it is investigating the attack and is restoring the affected systems.

“Superior is committed to data safety, is taking the matter very seriously, and asks its customers and partners for their patience as it seeks to remediate the situation,” the release added.

Critical Infrastructures Become Soft Targets

Superior Plus is the latest oil and gas enterprise to sustain a ransomware attack after the infamous attack on Colonial Pipeline earlier this year. The continuous attacks on the critical infrastructures severely impacted the flow of basic resources to the citizens, making the U.S. government introduce multiple security bills to protect the country’s critical infrastructure.

In May 2021, the U.S. House Committee on Homeland Security passed seven bipartisan security bills to bolster defense capabilities, enhance pipeline security, and defend supply-chain attacks targeting U.S. organizations and critical infrastructure. The bills also help state and local governments protect their networks, provide mitigation strategies against critical vulnerabilities, and authorize the Cybersecurity and Infrastructure Security Agency (CISA) to help establish a national cyber exercise program to promote continuous testing of cybersecurity preparedness and resilience to cyberattacks.

Microsoft Fixes 6 Zero-day Flaws in December 2021 Patch Tuesday Update

scope of cybersecurity, Microsoft December 2021 Patch Tuesday

Microsoft released patches for 67 CVEs in its latest December 2021 Patch Tuesday update. Out of 67 vulnerabilities, 60 were deemed important, and seven were critical. Six zero-day vulnerabilities have also been fixed, which were being exploited in the wild.

The December 2021 Patch Tuesday update resolved vulnerabilities affecting Microsoft Office, Microsoft PowerShell, the Chromium-based Edge browser, the Windows Kernel, Print Spooler, and Remote Desktop Client.

  • CVE-2021-43890: A spoofing vulnerability in Windows AppX Installer is a zero-day vulnerability and under exploitation. Microsoft says that it is “aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader.” This could be used in launching phishing campaigns.
  • CVE-2021-41333: The Windows Print Spooler Elevation of Privilege Vulnerability has been made public and has low attack complexity.
  • CVE-2021-43880: The Windows Mobile Device Management Elevation of Privilege (EoP) Vulnerability has been made public but not been exploited. The attacker can only delete targeted files on a system but cannot gain privileges to view or modify file contents.
  • CVE-2021-43893: The Windows Encrypting File System (EFS) Elevation of Privilege Vulnerability was reported by James Forshaw of Google Project Zero.  The vulnerability has been made public but not been exploited.
  • CVE-2021-43240: NTFS Set Short Name Elevation of Privilege Vulnerability has been made public but not known to be exploited.
  • CVE-2021-43883: Windows Installer Elevation of Privilege Vulnerability has been made public but not known to be exploited.

Tenable has identified three vulnerabilities as critical:

  • CVE-2021-43215is a memory corruption vulnerability in the Internet Storage Name Service (iSNS) protocol.
  • CVE-2021-43905is a RCE vulnerability in the Microsoft Office app.
  • CVE-2021-43233is a RCE in the Remote Desktop Client.

Brian Krebs, on krebsonsecurity.com, shared, “The Microsoft patches include six previously disclosed security flaws, and one that is already being actively exploited. This month’s Patch Tuesday is overshadowed by the “Log4Shell” 0-day exploit in a popular Java library that web server administrators are now racing to find and patch amid widespread exploitation of the flaw.”

The remote code execution (RCE) vulnerability “Log4Shell” in the Apache Log4j library allows attackers to execute arbitrary code and take full control of the vulnerable devices. It is a popular Java logging library leveraged by numerous organizations worldwide to enable logging in a wide set of popular applications. It is being viewed as one of the most devastating flaw and we have just begin to explore the tip of the iceberg. Read the full story here.