Home Blog Page 294

Cisco releases new security tool to identify vulnerabilities in connected cars

Connected cars

Cisco, the networking hardware company, recently released an open-source hardware tool dubbed ‘4CAN’ to find security vulnerabilities in connected cars. The newly launched security tool will allow automobile security researchers and car manufacturers to identify potential flaws in sensors and control systems in modern cars, to ensure vehicle security.

Cisco stated that vulnerabilities in the control systems might cause serious threats in the cars, which allows attackers to get control of the vehicle’s system.

“To help secure modern automobile technology, Cisco has dedicated resources for automobile security. The Customer Experience Assessment & Penetration Team (CX APT) represents the integration of experts from the NDS, Neohapsis, and Portcullis acquisitions. This team provides a variety of security assessment and attack simulation services to customers around the globe. CX APT specializes in identifying vulnerabilities in connected vehicle components,” Cisco said in a statement.

“During a recent engagement, the Connected Vehicle Security practice identified a gap in tooling for automobile security assessments. With ease-of-use, modern car computing requirements, and affordability as motivating factors, the Connected Vehicle Security practice has built and is open-sourcing a hardware tool called “4CAN” with accompanying the software, for the benefit of all automobile security researchers. We hope 4CAN will give researchers and car manufacturers the ability to test their on-board computers for potential vulnerabilities, making the vehicles safer and more secure for drivers before they even leave the lot,” the statement added.

Consumer Watchdog, a non-profit organization, also had come up with a report stating that all advanced cars with Internet connections to their safety-critical systems are apparently vulnerable to fleet-wide hacks.

The report, Kill Switch: Why Connected Cars Can Be Killing Machines And How To Turn Them Off, revealed that automakers have disclosed the high risk of such hacks to their investors, but are keeping the public in the dark as they market new features based on Internet connections. For example, Ford disclosed to the Securities Exchange Commission in its 10K filing that the company and its suppliers have been the subject of a malicious hack, but the public is unaware of the exact details.

Cyberbit Partners with Purdue University to Boost Cybersecurity Workforce Training

96% of Cybersecurity Professionals are Happy With Their Roles

Cyberbit, a provider of cyber range training and simulation platforms, recently joined hands with Purdue University to boost cybersecurity workforce education and training. As part of the partnership, Purdue University will launch a Cyberbit Range, a realistic training platform for cybersecurity professionals.

Cyberbit uses a hyper-realistic simulation approach to train and assess cybersecurity experts. This approach is now widely adopted by the industry as a means to cope with the ever-growing global cybersecurity skill shortage. Over the past year alone Cyberbit has launched over 30 cyber range classes and opened dozens of cyber ranges with Managed Security Service Providers (MSSP), universities and enterprises worldwide.

In addition to the cyber range, Cyberbit offers Security Orchestration, Automation and Response (SOAR), Industrial Control Systems (ICS) security, and Endpoint Detection and Response (EDR). These products are offered either as standalone products, or jointly, providing one of the only integrated platforms in the world for detection, incident response, and simulation across the converging IT/OT/IoT attack surface. Cyberbit’s portfolio helps security operations do more, with less, by reducing overwhelming alert volumes, accelerating incident response, consolidating security technologies and seamlessly managing multi-vector IT to OT attacks.

The new alliance allows security professionals to work with Purdue’s cybersecurity workforce to assess and enhance cybersecurity skills and boost organizational readiness toward cyber-attacks.

“Pilots have flight simulators, soldiers have firing ranges, now Purdue University has a cyber range — a state-of-the-art cyberattack simulator,” said Adi Dar, CEO of Cyberbit. “We’re excited to work with Purdue’s world-class team to ensure its industry partners are learning, retaining what they learn and building the reflexes needed to remain prepared in the highly dynamic world of cybersecurity.”

“Cyberbit was spun out of leading Israeli defense technology company, Elbit Systems to develop and bring to market a suite of cutting edge cyber defense technologies. It is the world’s leading provider of cyber ranges for simulated cybersecurity training. Our joint efforts will improve learning outcomes, and we applaud Purdue’s disruptive approach to cybersecurity in academia,” Dar added.

Planning a Roadmap on Cybercrime Management is the need of the hour: EY-FICCI report

PRESS RELEASE: With the increase in the adaption of digital technologies across the country, be it individual, organizational and at the national level, there is a need for participants from law enforcement agencies (LEAs), academia and industry to collaborate and keep up with the pace of the technological advancements and crime sophistications. Expedited modernization, both at central and state level, leveraging emerging cyber technologies and building-up integrated institutional cybercrime management infrastructure is required to stop the increasing cybersecurity threats, states a report titled ‘Innovation led cybercrime management’ launched by EY, a provider of assurance, tax, transaction, and advisory services, and the Federation of Indian Chambers of Commerce & Industry (FICCI).

“Today, the breadth and scope of cybercrimes are rising exponentially, damaging the digital aspirations of several industries as healthcare, e-governance, retail, manufacturing, transport and financial services, including digital payments as well as smart cities in India. To mitigate these cybercrimes, India needs to develop a strong cybercrime management ecosystem with a concerted effort from LEAs, academia, and industry. Only such a concerted effort can tackle the myriad cybercrime threats that we face as a society, and can thereby, provide assurance and trust to India’s economy,” said Vidur Gupta, Partner – Cyber Security, EY India.

Some of the major thrust areas in cybercrime management from an Indian context include:

  • Formulation of a standard cybercrime taxonomy, which is to be followed by state and central LEAs, to homogenize the cybercrime management in the nation.
  • Cybercrime research and testbeds to be built for investigations’ experimentation, introducing LEAs to simulated crime scenarios for effective investigation and closure of cases.
  • A formal institutional framework to be built focusing on resolving challenges involving cybercrime threat intelligence sharing through collaboration between central and state police.
  • Revisiting current law of the land such as the IT Act and IPC with respect to emerging use cases, crime, and technology scenarios.
  • Constitute a focused task force to study the dark web ecosystem and present its findings to central and state functions.
  • A joint India-based taskforce may be formulated where police from all the member nations jointly address international issues pertaining to cybercrimes and India can derive the benefit from it.
  • Charting out a next-generation technological strategy to be leveraged by central and state LEA functions
  • Setting up of central and state technology analytic units which would act as information technology functions for LEAs, enabling accelerated investigation and thwarting cybercrimes at the national level.
  • Setting up of state and central centers of excellences (CoEs) equipping LEAs with investigative capabilities and aiding in continuous capacity building.
  • Setting up of cybercrime forensics laboratories in each state to address the challenge of delay in examination of case data.
  • Setting up of cyber police cadre in the formal police recruitment system.

New version of NanoCore RAT emerges online for free

NanoCore trojan on dark web

A new version of the infamous NanoCore RAT (Remote Access Trojan) has resurfaced on the dark web and is being for offered for free. The news has given nightmares to cybersecurity experts across the world. Even though the first version surfaced way back in 2013, it is still considered highly potent and can be deployed for the extraction of financial information from unsuspecting users, or even launch a phishing attack.

Any cyber-criminal could have bought the malware for as little as $25, but a new outing of the trojan was recently leaked on a dark web forum and is touted to be way more dangerous and highly potent compared to the older version. The worst part is, it’s free. Several experts are of the opinion that a trojan can act as a catalyst for a rise in cyber-attacks. It is said that any cyber-crook with limited technical skills can launch an attack using this trojan.

According to researchers at LMNTRIX Labs, who uncovered the news, the new version dubbed NanoCore v1.2.2 can be used to launch an attack against Windows systems to steal hashed passwords, perform keylogging, and discreetly record audio and video using webcams. The malware also disables the recording light on the webcam, thereby making sure that the user is unaware that he is being monitored. But the buck doesn’t stop there. The malware can also remotely restart, shut down a machine, as well as control the mouse or open new web pages, in other words, it can take control of a machine in its entirety and exploit it according to the whims and fancies of the attackers.

“Malware authors today tend to favor easy-to-use interfaces as it helps them write and update code, as well as use the RAT more efficiently. This simple interface also lowers the barrier for entry for any prospective hackers, so even amateurs can launch an attack,” Arannya Mukerjee, a senior threat researcher at LMNTRIX Labs told ZDNet.

According to the researcher, “Anytime an exploit kit or RAT kit is made available for free, it leads to an explosion of campaigns using the malware.” They also anticipate newer and more efficient versions of NanoCore RAT to emerge online soon.

NanoCore RAT has been in the news for a while now. In 2017, the author of the trojan, Taylor Huddleston, was sentenced to serve a 33-month term in jail for aiding and abetting computer intrusions by developing, marketing and distributing the trojan on the dark web.

60% of companies do not think Budget is a constraint for Cloud Migration: CISO MAG report

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

About 40 percent of companies still think budget is a constraint while selecting a cloud vendor for migration. The majority of companies surveyed (60 percent) do not think budget is holding them back from cloud migration. Ease of ensuring patching, certification, and security compliance is the second most prominent requirement. These are some of the findings of a survey and research report published by CISO MAG and included in the August 2019 issue, titled ‘Cloud Security Power List’. The issue is available as a free download.

The research report includes findings on Cloud Migration Trends and strategies adopted by companies for cloud migration vendor selection. It also delves into various security challenges and threat vectors faced by companies.

Apart from the cloud security survey, readers can find more security insights in the stories produced in the issue.

The issue begins with the Knowledge Hub, which details the steps companies must take when embarking on a cloud journey. The article speaks at length about the different models that exist as well as choosing the one that is right for your organization.

In the View Point section, there’s a story about cloud security in the new age era and precautions companies must take in securing their infrastructure–with a focus on the Middle East market.

The Insight section has commentary about cloud bursting and hybrid cloud adoption. The article details the challenges around securing hybrid cloud and the zero-trust model many companies are adopting to ensure cloud security.

Under the spotlight (the interview section) features Rasheed Alodah, Managing Director, Trend Micro, Saudi Arabia. He speaks in detail about his journey, the ever-evolving landscape of cloud security, the market strategy Trend Micro has adopted to stay on top of the game, and the threats in the cloud security space.

Through the ensuing articles on the Power List, the CISO MAG editors listed the powerhouses in the space of cloud security that have, through the years, been at the forefront of innovation and technology. These include companies like Symantec, Akamai, Fortinet, and Cisco.

Trend Micro, Safe T, Oblique Drive, and Dark Trace are also on the Power List and they outline their commitment toward better cloud security.

The August 2019 issue is dedicated to the stories surrounding these companies that have been on the frontlines of cloud generally, and cloud security specifically.

Download a copy of the issue and the report here: https://cisomag.com/power-list/

Facebook Introduces New Tool to Control Data Flow

Facebook copyright complaint

With an aim to ramp up its security and privacy regulations, Facebook has launched a new tool to control the data flow from third-party applications and websites.

The social media giant stated that the new tool allows customers to access ‘Off-Facebook Activity’ that allows them to control the data flow from other websites about their online activity. Facebook also stated that users can now monitor or delete the data flow from others that are shared via business tools like Facebook Pixel or Facebook Login.

Speaking on the new option, Erin Egan, Facebook’s Chief Privacy Officer, said, “Off-Facebook Activity lets you see a summary of the apps and websites that send us information about your activity, and clear this information from your account if you want to. This is another way to give people more transparency and control on Facebook, along with recent updates to our Ad Library, updates to ’Why am I seeing this ad?’ and the launch of a new feature called ’Why am I seeing this post?’”

“This feature marks a new level of transparency and control, and we’ll keep improving. We welcome conversations with privacy experts, policymakers and other companies about how to continue building tools like this,” Egan added.

Facebook has been slapped with a massive $5 billion fine for allegedly violating privacy practices and mishandling user data during the infamous Cambridge Analytica scandal and other privacy breaches.

The Federal Trade Commission (FTC) recently ordered Facebook to adopt new policies for protecting users’ data and expand these policies across Instagram and WhatsApp. Facebook has also been asked to create a new privacy committee that will have independent board members. Moreover, a third-party assessor approved by the FTC will be brought on board to conduct biennial assessments and monitor Facebook’s privacy-related decisions.

Delta sues AI vendor for exposing customers’ data in 2017

Airlines

Delta Airlines sued an artificial intelligence company, which offers chatbot services on Delta’s website, for its lax security measures that caused a 2017 data breach. The airline has filed a lawsuit in the U.S. District Court in New York against the vendor, claiming its poor security and weak passwords led to the data breach that exposed around 825,000 Delta customers.

Delta Airlines stated that the vendor took around 6 months to disclose the data breach. The carrier also stated the vendor disclosed breach details via LinkedIn instead of contacting it directly. According to the lawsuit, the breach exposed customers’ names, contact numbers, email addresses, and credit card information.

The vendor allowed its employees to use the same login credentials and didn’t use multi-factor authentication, according to the lawsuit.

“What’s particularly interesting about this situation is that Delta seems to have had contract provisions and had its provider sign a GDPR compliance addendum in February 2018 requiring immediate breach notification, five months before notifying Delta about the breach,” said Gary Roboff, Senior Advisor at Shared Assessments. “Delta says its vendor was aware of the breach when it signed that agreement.”

“If Delta actually used the words ‘adequate security’ instead of defining more precisely what good security hygiene means, that could be a problem,” Roboff added.

Recently, the U.K. Information Commissioner’s Office (ICO) fined British Airways with £183.39 million ($230 million) after the airline failed to protect its customers’ data. The proposed fine relates to a data breach notified to the ICO by British Airways in September 2018, that exposed around 500,000 customers’ personal information.

The ICO said its investigation found that the breach compromised customer details, including login, payment card, name, address, and travel booking information, which is collected after being diverted to a fraudulent website. The data breach, which began in June 2018, occurred due to the poor security measures to protect customer information, ICO stated.

Around 4000 Data Breaches reported in the first half of 2019

Iran Hacker Group

A recent survey has revealed that the number of data breaches has increased by more than 50 percent in the first six months of 2019 when compared to 2018. According to a report from Risk Based Security, there were 3,816 data breaches in the first half of 2019, which compromised around 4.1 billion records.

The report, dubbed 2019 MidYear QuickView Data Breach, stated that government agencies suffered 160 breaches, healthcare industry 224 breaches, 199 data breach in the retail sector, finance and insurance reported 183 breaches and 99 breaches in the education sector.

“Looking over the first six months of 2019, it is hard to be optimistic about the outlook for the year. The number of breaches is up, and the number of records exposed remains stubbornly high. Despite best efforts and awareness among business leaders and defenders, data breaches continue to take place at an alarming rate,” said Inga Goddijn, Executive Vice President of Risk Based Security.

According to Goddijn, the data breaches exposed various kinds of information including, Email addresses, passwords, names, Social Security numbers, and credit card numbers. Goddijn also revealed that 1,132 of the breaches occurred in the United States and 353 in other countries.

European companies experienced thousands of data breaches since data protection laws were brought in last year, according to a survey conducted by a law firm DLA Piper. In its GDPR Data Breach survey, DLA Piper stated that over 59,000 data breaches have been reported across the European Economic Area (EEA) by the public and private organizations since the General Data Protection Regulation (GDPR) came into effect on May 25, 2018.

Of the 26 EEA countries, Netherlands topped the list with 15,400 data breach notifications followed by Germany and the United Kingdom with 12,600 and 10,600 reported breaches, respectively. Whereas the lowest number of reported breaches were made in Liechtenstein, Iceland, and Cyprus with 15, 25 and 35 breaches respectively, the survey revealed.

CyberRisk Alliance acquires Cybersecurity Collaborative

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Cybersecurity and business intelligence company CyberRisk Alliance recently acquired Cybersecurity Collaborative, a peer council platform for Chief Information Security Officers (CISOs).

Cybersecurity Collaborative is a private cross-industry forum for CISOs and security professionals devoted to peer association. The company offers a secure platform to share knowledge, skills, and experiences on cybersecurity challenges.

Founded in 2018, CyberRisk Alliance is a diversified marketplace of business information products and services that trains security professionals. The new acquisition allows the cybersecurity community members to access the confidential security reports, critical updates, and CISO-led SWAT teams.

Speaking on the new acquisition, Doug Manoni, the CEO and Founder of CyberRisk Alliance, said, “Cybersecurity Collaborative represents another key investment and an essential component of our platform strategy to serve this fast-growing industry with strong resource demands. We’re privileged to partner with Stuart Cohen and his team with their deep understanding of the community and their ability to support this exclusive and valued service to the community. We’re eager to work with Stuart and build on his impressive accomplishments by adding additional capabilities to the membership offering and expanding into new market segments.”

“We are excited to join the CyberRisk Alliance portfolio of companies. This merger will significantly enhance the current benefits of our confidential peer collaboration with access to an enhanced service offering, solely focused on CISOs and their security teams, with a mission of strengthening member organizations and making them safer,” said Stuart Cohen, the Chief Executive Officer of Cybersecurity Collaborative.

Ransomware affects multiple Government Agencies in Texas

Ransomware attacks, ransomware, Sinclair Broadcast group

The Texas Department of Information Resources (DIR) has revealed that around 23 Local Government Organizations in Texas have been hit with a ransomware attack last week.

“On the morning of August 16, 2019, more than 20 entities in Texas reported a ransomware attack.  The majority of these entities were smaller local governments,” the DIR said in a statement. “The State of Texas systems and networks have not been impacted. It appears all entities that were actually or potentially impacted have been identified and notified.”

The DIR activated the State Operations Center (SOC) to investigate the origin of the attack. It also stated that it has discovered and reported all the affected organizations and is working on fixing the affected systems. However, the authorities clarified that Texas network systems were not affected in the incident.

Along with SOC, several other Texas and the U.S. government agencies were involved in the recovery process, including the Texas Division of Emergency Management, the FBI, the DHS, and the Texas Department of Public Safety.

The news comes after the ransomware attacks in New York and Louisiana that compromised valuable data.

Recently, the Governor of Louisiana, John Bel Edwards, issued a state of emergency after a wave of ransomware attacks hit school districts. According to an official statement, the incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their networks systems.

Monroe College in New York City has also been under a ransomware attack. According to the officials, the hackers have compromised the college’s computer systems and demanded a ransom of around $2 million in bitcoin. The college authorities stated the incident is investigating by the NYPD. “We are, in fact, under cyberattack. A lot of our systems are being held — we do not have access at the moment,” Monroe’s officials said in a statement.