Home Blog Page 292

Google launches New Bug Bounty Program

cyberthreats, bug

Google recently announced the launch of its new Developer Data Protection Reward Program (DDPRP) and the expansion of Google Play Security Reward Program (GPSRP), which are intended to detect and mitigate data abuse issues in Chrome plugins, Android apps, and OAuth projects. Google started its vulnerability rewards program in 2010, which offers cash rewards to security researchers who report flaws in Google code.

The search engine giant stated that it’s joining hands with bug bounty platform HackerOne to launch the new bug bounty program. According to Google, bug hunters are required to identify situations like – selling user’s data or illegitimate use of it. The bug reporters will be rewarded with a maximum bounty worth US$ 50,000.

“We’re constantly looking for ways to further improve the security and privacy of our products, and the ecosystems they support. At Google, we understand the strength of open platforms and ecosystems, and that the best ideas don’t always come from within. It is for this reason that we offer a broad range of vulnerability reward programs, encouraging the community to help us improve security for everyone,” Google said in a statement.

Google recently raised bounties for Chrome and Google Play bugs, making them more lucrative to security researchers. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over US$ 5 million (£4 million).

According to Google’s Chrome security experts Natasha Pabrai and Andrew Whalley, the company has doubled the maximum reward on High-Quality Reports from US$15,000 (£12,000) to US$30,000 (£24,000) and tripled the baseline reward amount from US$5000 (£4 million) to US$15,000 (£12,000) for good measure.

IoT startup Astrocast raises US$ 9.2 million to develop IoT modules for Secure Communications

Internet of Things (IoT) startup Astrocast recently secured US$ 9.2 million (€8.3 million) in a Series A round of funding. The Swiss startup said the new proceeds will help it accelerate the production of IoT modules and the deployment of its Low Earth Orbit (LEO) IoT Network.  The company is developing an IoT Nanosatellite Network that provides bidirectional and highly secure connections to any IoT device on Earth.

Astrocast was founded in 2014 by security veterans Bertil Chapuis, Fabien Jordan, Federico Belloni, Jean-Michel Jordan, Julian Harris, and Nicholas Petrig.  It is partnering with the European Space Agency, Thuraya, and Airbus for the development of an advanced Nanosatellite network for IoT devices.

Speaking on the new investment, Fabien Jordan, the CEO of Astrocast, said, “We are excited to see the continued confidence of our investors and partners in the new space race and our company, as we make our mission of building the world’s first IoT network for the planet a reality. As we move toward our commercial launch in Q1 of 2020, we are further confirming our leadership as a fully integrated nanosatellite operator and our unique ability to deliver efficient IoT satellite coverage globally. Next steps with investors will be to secure an accelerated deployment of our global fleet of satellites.”

“It has been an amazing year for Astrocast. With the launch of two satellites and a growing number of pilot customers, the company has demonstrated its ability to bring IoT access to the world,” Jordan added.

In a similar funding news, IoT security startup VDOO secured US$32 million in a Series B financing round led by WRV and GGV Capital along with the participation from NTT DoCoMo. The Tel Aviv, Israel-based startup stated the new funds will be used to accelerate the development of its automated analysis capabilities and also expand the company’s partner and distribution network.

VDOO helps embedded device vendors increase the security level of their products by analyzing the security gaps of each device using the cloud or a closed local environment. The company claims that it uses advanced machine learning to build actionable security requirements. The startup helps vendors to take instant actions towards device runtime protection using a single platform.

Why You Should Stop Borrowing Someone’s Charger

USB charging stations

Cybersecurity experts stated that using someone else charging cable might bring threats to your mobile devices. Attackers could exploit charging cables/cords to access sensitive information from the victim’s mobile.

According to security professionals, hackers could implant Malware into charging cords or cables to hack mobile devices. It’s believed that these kinds of attacks mostly occur in busy places like airports, railway stations, and other public places, where users rely on USB charging stations.

USB chargers can be turned into potential hacking devices by inserting a malicious chip that allegedly allows attackers to access a mobile’s data over open Wi-Fi networks. The surprising part here is the person who’s lending the charger might not be aware that his/her charger was infected.

Hackers are using sophisticated methods to break into mobile devices. Recently, security researchers revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to researchers from Kaspersky, a hacker group has been found targeting Israel citizens and other Middle East countries with surveillance malware named Triout.

The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and the ability to make calls or send messages to specific numbers, according to researchers. The researchers said that attackers used Smali injection technique, that allows hackers to disassemble the code of an original application and add malicious code.

Two in Five Companies have lost Business Due to Lack of Cybersecurity: Survey

active directory
active directory

A recent study revealed that every two in five (38 percent) companies stated that they’ve lost their businesses due to lack of cybersecurity capabilities. Conducted by security firm BitSight, the study titled ‘Better Security and Business Outcomes with Security Performance Management’ stated that cybersecurity performance is important to attain business success.

According to BitSight, the study discovers the security complexities in the organizations that usually prevent them from achieving Security Performance Management (SPM). The survey findings are based on the responses of around 207 security decision-makers who are responsible for risk, compliance, and other security operations in the organization.

BitSight helps enterprises manage security performance. The company offers sophisticated Security Ratings Platform that enables organizations to underwrite cyber insurance policies and mitigate cyber risk.

“Financial success, brand perception, business continuity and company reputation now all hinge on security performance,” said Tom Turner, CEO, BitSight. “But in order to effectively manage performance, you have to measure it. We think this study should serve as a wakeup call for security leaders and their executives and boards to take a close look at their strategies for security performance measurement and reporting – after all, their businesses are now on the line.”

Some other notable findings from the survey include:

  • Cybersecurity risk ratings emerge as an early security metric bright spot.
  • Effective security performance management drives business wins and better security outcomes.
  • Commercial success is at risk due to missteps in effectively measuring security performance and communicating it to external stakeholders.
  • Metrics are critical to understanding and improving communication around security performance, but there is vast room for improvement in current methods.

The tech sector is suffering the adversities of the shortage of technically skilled employees in the cybersecurity domain. This causes the “less-technical” staff to exert pressure on their employers. Research published by an independent think tank revealed that business morality is a primary consideration for skilled tech workers who often quit their jobs because their companies do not comply with privacy norms.

According to the study, one out of five technically sound employees end up quitting their job if they find that the policies of the firm don’t comply with privacy norms. Their decision costs the firm a hefty $38,000 every time a skilled professional leaves the company.

Russian Police detain TipTop Gang that infected 800,000 Android Devices

Nobelium

The Russian Police officials recently arrested members of a cybercrime group, dubbed TipTop Group, who have infected more than 800,000 Android phones with malware since 2015. According to Group-IB, a security firm that helped Russian authorities finding hackers, TipTop Group was active since 2015 and making between $1,500 and $10,500 daily.

Group-IB stated the hacker group operated by renting Android Trojans from hacking forums. It’s believed that the group used Hqwar (Agent.BID), a banking trojan, while targeting the customers of Russian banks.

Hqwar malware makes a fake login screen to appear on original banking apps to steal victims’ login credentials. The malware is also able to monitor the victim’s SMS messages, phone calls, and USSD-requests.

“This group received the working name TipTop. Its main goal was the clients of large Russian banks — users of smartphones running Android. To infect phones, the attackers disguised malware under the mobile applications of well-known banks from the TOP-10, as well as under the Viber messenger, the Google Play application store or Adobe graphics applications. Cybercriminals placed links to them on their own resources or hacked legitimate sites. To increase the number of victims, cybercriminals redeemed ads in search engines for “mobile bank” and placed links to their resources there,” said Sergey Lupanin, the Head of Investigation at Group-IB.

Recently, Russia suffered a hacking attack that compromised the country’s Federal Security Service (FSB). According to the official statement, hackers allegedly gained access to 7.5 terabytes of data from a major contractor Sytech. The incident exposed FSB’s secret projects like how Russia is trying to carry out de-anonymization of users of Tor browser collecting information of users’ social networks, and separating the Russian internet operations from the rest of the world.

The attack occurred on July 13, 2019, by an unknown hacking group named 0v1ru $. Hackers allegedly accessed into SyTech’s Active Directory server from where they gained access to the company’s entire IT network and defaced the company’s website with a “yoba face,” an emoji used in Russian for trolling.

Google researchers disclose major security flaws in iPhones

Apple App Store, Apple vulnerabilities

Security researchers discovered that an iPhone could be turned into a surveillance tool that can expose the victim’s sensitive information, including contacts, Live Location, chat history, emails, photos, and passwords.

According to Ian Beer, Google’s Project Zero researcher, a number of flaws in iPhones could enable attackers to set Monitoring Implants in the devices. The researcher said that they’ve found Fourteen security flaws that existed in iPhones from the past two years.

“Visiting hacked sites was all that is needed for a server to gather users’ images and contacts. A user only had to visit a website to potentially give hackers access to messages, photos, contacts, and location information,” Ian Beer said in a statement.

Apple stated that it fixed all the flaws in a software update released in February 2019, after confirming Google findings.

“We discovered exploits for a total of fourteen vulnerabilities across the five exploit chains: seven for the iPhone’s web browser, five for the kernel and two separate sandbox escapes. Initial analysis indicated that at least one of the privilege escalation chains was still 0-day and unpatched at the time of discovery (CVE-2019-7287 & CVE-2019-7286). We reported these issues to Apple with a 7-day deadline on 1 Feb 2019, which resulted in the out-of-band release of iOS 12.1.4 on 7 Feb 2019,” Beer added.

Recently, digital forensic experts at Google discovered six flaws in Apple’s iMessage software that could impact the iOS operating system and make the devices vulnerable to attacks. The bugs were discovered by Natalie Silvanovich and Samuel Grob.

However, Apple has released fixes for the vulnerabilities recently and urged users to update. But the researchers said the patch for the sixth discovered bug is not yet provided in the update to its mobile operating system.

According to researchers, four of the six security bugs, CVE-2019-8641, CVE-2019-8647, CVE-2019-8660, and CVE-2019-8662 can execute malicious code on a remote iOS device, without a user’s knowledge. The bug can be exploited when an attacker sends a malicious message to the victim’s phone, which will be executed when a user opens and views the received message.

Attackers Hacked Twitter CEO’s Account using SIM Swapping Attack

Cyber Espionage Campaign Naikon APT

Jack Dorsey, the CEO & Co-founder of Twitter, had his own Twitter account compromised by a hacking group named Chuckle Squad. According to an official statement, hackers used SIM Swapping Attack technique to take over Jack’s account by exploiting the cell carrier vulnerability, which enabled them to post anti-Semitic comments in his account feed.

However, Twitter officials clarified that Jack’s account is now fixed and there is no sign that Twitter’s systems have been hacked.

Describing how the account got hacked, Twitter said, “The phone number associated with the account was compromised due to a security oversight by the mobile provider. This allowed an unauthorized person to compose and send tweets via text message from the phone number. That issue is now resolved.”

“Annoying tweets are coming from a company called Cloudhopper that Twitter previously acquired to help with its SMS service. Hackers abusing the phone number that associated with Jack’s Twitter account and if they text 404-04, the text will be posted on his Twitter account,” Twitter added.

Earlier, the micro-blogging giant revealed that it discovered and fixed a security bug that could have exposed users’ phone country codes and locked accounts details. Twitter stated they noticed unusual activity in its Application Programming Interface (API) and observed a large amount of traffic coming from IP addresses located in China and Saudi Arabia. Twitter stated the bug was fixed on November 16, 2018, and then informed users that may have been affected due to the security bug.

“Automation can help us by making sure our recovery environment replicates the real environment”

Jeffrey Wheatman, Research Director, Gartner

Security leaders are grappling with a number of challenges today but with more automation coming into cybersecurity, they are seeing some solutions to ease those challenges. Certain areas of cybersecurity are leveraging automation, AI and ML, and can detect threats on a scale that’s not possible for humans to do manually. Jeffrey Wheatman, Research Director, Gartner tells Brian Pereira of CISO MAG where automation in security is heading and how it can help solve the skills shortage problem or manage resilience risk.

How does automation address some of the areas that security leaders are struggling with today? How is automation technology for security evolving?

Security leaders are struggling in a number of areas. One, there’s a human capital problem. We do not have enough people with the right skillsets. The technology is also getting more complicated. This is where automation can help.

Secondly, there is too much background noise. We have too many sensors and agents and devices that are collecting data and I doubt if humans have the capability to parse through all of that noise and extract value. Human beings, by nature, are not great at identifying patterns. So automation helps from that perspective as well.

Finally, automation speeds up the detection, response and recovery piece, an area that a lot of people struggle with. People have done a fairly good job with protection, prevention and stopping the bad actors. But when they get in, the ability to detect and respond, doing so manually, is way too slow.

I think automation is improving over time and getting more mature. The original aspect of automation was about signature based, and simple analysis and scripting. But as we see artificial intelligence and machine learning get better and stronger and more usable, automation is actually leveraging a lot of those things as well. There is standalone automation and then there’s automation in existing toolsets like SIEM, data loss prevention and endpoint protection.

Which areas of security are leveraging automation and AI the most?

Endpoint protection is leveraging AI, ML–data analytics too, for things like integrated risk management tools and platforms. We’ve also seen AI used for application security testing and for DevOps implementations.

Looking at data usage patterns I think we are going to see more of that in the cloud. One of the challenges of cloud is that once the data leaves our network, we lose the ability to control. AI and ML can help us in understanding how the data is used, helping us identify patterns and therefore identify things that don’t match which might be a trigger or an alert.

How do businesses manage resilience risk through automation?

One of the challenges that we used to see is that the backup environment, the failover environment sometimes didn’t match the real environment. So we would patch our production servers and wouldn’t necessarily move that configuration update into our recovery center. That’s the way that automation could probably help. I think AI and ML as part of automation can help us anticipate outages beforehand, and therefore we will be better poised to have resilience.

If the AI and automation tells us there’s a lot of bad traffic going on out there, we should be prepared before it hits us. We should be able to see a malware attack spinning up, and be able to catch it (before it impacts us).

Automation can help us by making sure our recovery environment replicates the real environment. It could look at the automated analysis through the environment and do constant situation awareness.

Are the CISOs doing enough to reskill their teams and what should be the correct approach?

Part of it is outside the scope of what CISOs can do. We need to start thinking about how do we create people who are solutions-focused rather than technically aligned. For instance, a network security engineer does not have a lot of visibility into applications or the data level or the cloud. We need people to think more about the bigger picture.

The traditional education has been aligned with a narrow view. So it is about pushing our people to be more solutions focussed. The way to do that is by moving people around (the organization) and by skills transfers. By having people work directly with the business and understanding how they use the technology and the systems.

One of the things we see people doing, but not as much as they should, is they can go to other areas in the business for resources. For instance, people who work in finance have good risk-based mindsets.

Making our job descriptions less technical and more solutions focused will essentially double the labor pool because we will be able to recruit people from all sides of the gender continuum.

Getting our people to think more like hackers and not just defenders, because the attackers have different mindsets. There are also tools like Cyber ranges and attack simulation and  we need to use these tools to train people.

How do you see the role of the CISO evolving?

CISOs need to shift mindsets. The CISO’s job is not (only) to protect the organization. The CISO’s job is to provide information for his/her stakeholders to enable them to make the right decisions about what risks to accept and which ones to… They have to work with the business to find the right balance between protecting the business and running the business. Unfortunately, a lot of security leaders think it is their job to protect the business and to protect people from… and I don’t think that’s right.

Security leaders need to be more effective communicators. We need to not try to make the business speak our language. We need to try to speak their language. I don’t think we have enough security and risk leaders who have got to that.

The CISOs are not doing an effective job in building the bridge or the connection between ‘here are the things we do, and here’s why you should hear about them’.

In a lot of cases those C-levels and board members see security as a cost center. They know cybersecurity is a problem, but they don’t always understand why; they don’t understand the impact. And unless CISOs can effectively demonstrate why security played a critical role to achieving business objectives, we are going to see shrinking budgets and that’s going to lead to a lot of problems.

Broadcom acquires Symantec’s enterprise security unit for $10.7 billion in cash

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Broadcom, a global technology leader that designs, develops and supplies semiconductor and infrastructure software solutions, today announced an agreement to acquire the enterprise security business of Symantec Corporation for $10.7 billion in cash. The addition of Symantec’s enterprise security portfolio will significantly expand Broadcom’s infrastructure software footprint as it continues to build one of the world’s leading infrastructure technology companies.

Hock Tan, President and Chief Executive Officer of Broadcom, said, “M&A has played a central role in Broadcom’s growth strategy and this transaction represents the next logical step in our strategy following our acquisitions of Brocade and CA Technologies. Symantec’s enterprise security business is recognized as an established leader in the growing enterprise security space and has developed some of the world’s most powerful defense solutions that protect against today’s evolving threat landscape and secure data from endpoint to cloud. We look forward to expanding our footprint of mission critical infrastructure software within our core Global 2000 customer base.”

With product lines across endpoint security, web security services, cloud security and data loss prevention, Symantec’s enterprise security business offers its customers a best-in-class suite of integrated enterprise security solutions. Deploying Symantec’s enterprise security suite through Broadcom’s channels will strengthen its differentiated portfolio license agreement (PLA) strategy of offering significant overall savings to customers, while creating a predictable, recurring revenue stream for its business that will drive returns for shareholders.

The transaction is expected to drive more than $2 billion of sustainable, incremental, run-rate revenues and approximately $1.3 billion of Pro Forma EBITDA, including synergies. The transaction is expected to generate more than $1 billion of run-rate cost synergies within 12 months following close. Additionally, Broadcom expects to achieve double-digit cash-on-cash returns on its investment.

Transaction Details

Under the terms of the asset purchase agreement, which has been approved by the Broadcom Board of Directors, Broadcom will pay Symantec $10.7 billion in cash at closing. Broadcom intends to fund the transaction with proceeds from new committed debt financing.

Broadcom expects its current dividend policy of delivering 50% of its prior fiscal year free cash flow to shareholders to remain unchanged. However, Broadcom now intends to utilize excess cash flow beyond its dividend payments to focus on rapidly paying down debt as opposed to stock repurchases. Broadcom believes access to the investment grade credit market is fundamental to its strategy and fully intends to maintain its investment grade credit rating.

The transaction, which is expected to close in the first quarter of Broadcom’s fiscal year 20201, is subject to regulatory approvals in the U.S., EU and Japan and other customary closing conditions.

Following the closing of the transaction, Broadcom will own and incorporate the Symantec brand name into the Broadcom portfolio.

Reaffirms Fiscal Year 2019 Revenue Guidance

Broadcom today also reaffirmed its fiscal year 2019 revenue guidance of $22.5 billion, with $17.5 billion from semiconductor solutions and $5 billion from infrastructure software, as last provided in its second quarter fiscal year 2019 earnings release on June 13, 2019.

A new Approach for Organizations to Minimize Liability and Demonstrate Due Care

Cloud Security Market

By V3 Cybersecurity

Our last article “Addressing the Unanswered Organizational Needs of Today’s CISO” focused on disrupting legacy consulting models and providing CISOs with a new capability for establishing real time and dynamic cybersecurity visibility and benchmarking into their security program.  Additionally, we examined how the new capability provided a platform for reducing individual liability within the board and officers of the company.  The Caremark International Inc. Derivative Litigation established that if your directors are doing what they can to meet their duty of care, then they are unlikely to be held liable for poor compliance oversight.  The Minerva Platform by V3 Cybersecurity provides a new approach for organizations looking to minimize liability and demonstrate due care.  Now we want to turn towards two topics that are of equal importance when providing business context to your cybersecurity program–organizational exposure and alignment.

There are countless reports and studies from vendors providing insight into the cost of a data breach.  In most cases, the insight is interesting but cannot be applied in a meaningful way outside of bestowing fear on organizations and generating leads for the vendors.  Equally, we have seen the meteoric rise of cyber insurers and organizations guessing (albeit somewhat educated) about the amount of coverage needed to limit their financial exposure in the event of a cyber breach.  Most of what we see are companies continuing to try and tackle the risk equation with agent-based technical controls and some sort of proprietary ordinal risk indexing method.  There is no argument that these technologies can provide useful insight into threat and anomalous activity, but they do not answer the financial questions that should be leading the conversation.  How many CISOs and security professionals are prepared to answer the questions: “What is the financial exposure to our company if we were to have a major cybersecurity incident?”, or “How much insurance should we have to protect us against a cyber incident and why?”

The few organizations that are trying to tackle the issue are moving the needle in terms of quantification of exposure but are still reliant on high levels of organizational maturity and security staff to understand and drive financial determinations for the organization.  Unfortunately for businesses, most cybersecurity staff are highly sought-after specialists in IT Security and have limited interest in becoming financial analysts.  Not to mention that most organizations have enough challenges finding sound security staff, much less an experienced CISO.

“Organizations need a better understanding of their loss of value in the event of a cybersecurity event.  While understanding the cost of litigation, loss of clients, and remediation activities is one way to get to a valuation, does it accurately reflect the investor’s trust in management or willingness to invest in the organization?  The simple truth is that most organizations do not know their exposure to cyber events.  Even if a company is able to establish a financial value, there are macro and micro influences that are not well understood,” says Jorge Conde-Berrocal, CEO of V3 Cybersecurity, Inc.  “The Minerva platform is solving these challenges and empowering businesses to make informed decisions,” he continued.

The Minerva Exposure Engine by V3 Cybersecurity will provide a machine learning-based approach to valuing organizations and their exposure to a cybersecurity breach.  By examining stock variance over time and applying valuation methods on the forefront of academia, the Minerva Exposure Engine will provide never seen before business insight and context to cybersecurity programs.  This data-driven approach minimizes the need to spend IT security resources on determining the financial exposure of a public cybersecurity event and is not dependent on the maturity level of an organization’s security program.

While understanding organizational exposure with the Minerva Exposure Engine will elevate your boardroom presence significantly, organizational exposure is not the most significant cause of cybersecurity program failure.  One of the most predominant issues facing CISOs today is the lack of alignment with stakeholders and organizational goals.  Speak to most tenured CISOs and they will admit that they have faced significant challenges in aligning the organizational stakeholders to achieve their security goals.  This idea is eloquently stated in the NACD Blue Ribbon Commission on Culture as a Corporate Asset.  “A dysfunctional culture has the potential to undermine the business model and create significant risk for the company.”  Unfortunately, organizational dysfunction leaves most CISOs being viewed as obstacles to progress.  This, in turn, creates high leadership turnover and security organizations struggling to keep up with the changes in regulatory requirements and evolving threat landscape.

V3 Cybersecurity is taking a unique approach to this issue and is using technology to enforce alignment with organizational goals and input from the organizations’ stakeholders to develop the organizations’ priorities.  Through the defined workflow, the Minerva Roadmap Engine will drive the integration of the security program into the organization.  While there will be times in which stakeholder buy-in is not optional (such as regulatory requirements), there are many instances where it is a business decision to prioritize allocating resources.  Our role as CISOs is to inform the leadership team and board of the IT security risk associated with each option and to drive transparency into this process.  This will be done through a simulated impact assessment that will be compared against the current state of the Minerva Maturity Engine.

The process of simulating the impact of projects will give CISOs new capabilities in the contextualization of the impact to organizational security.  This level of visibility will allow tomorrow’s CISOs to focus on effectively communicating and educating their organization of the implications and risks associated with their decisions.

Having real-time insight into your security program, understanding the potential financial exposure from a cybersecurity event, and being able to align the security program with the goals of the organization will enable the CISOs of tomorrow to earn influence and trust within the organization’s leadership and board.  Knowledge is power, but wisdom is empowering.