Home Blog Page 297

Why Microsoft paid $4.4 million bug bounties to Hackers

Lizard Squad

Microsoft recently admitted that it paid around $4.4 million to hackers as bug bounties in the past 12 months. The technology giant confirmed this at the Black Hat 2019 security event in Las Vegas.

Most large organizations usually conduct bug bounties for finding potential vulnerabilities in their systems, which can be fixed before attackers can exploit these. The bug bounties offer fiscal rewards to hackers for finding technical flaws, making it a win-win situation for both.

But Microsoft is not the first big tech company to offer bug bounties.

Recently, Google announced the increase in bug bounty rewards, making them more lucrative to security researchers. The company stated that it has raised the bounties for Chrome and Google Play bugs.

Google launched the vulnerability rewards program in 2010 and provides cash rewards to security researchers who report vulnerabilities in Google code. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over $5 million (£4 million).

According to Google’s Chrome security experts Natasha Pabrai and Andrew Whalley, the company has doubled the maximum reward on High-Quality Reports from $15,000 (£12,000) to $30,000 (£24,000) and tripled the baseline reward amount from $5,000 (£4 million) to $15,000 (£12,000) for good measure.

“Today, we’re delighted to announce an across the board increase in our reward amounts! Full details can be found on our program rules page, but highlights include tripling the maximum baseline reward amount from $5,000 to $15,000 and doubling the maximum reward amount for high-quality reports from $15,000 to $30,000. The additional bonus given to bugs found by fuzzers running under Chrome Fuzzer Program is also doubling to $1,000,” Google said in an official post.

Cybersecurity startup Cybereason secures $200 million

Startup funding

AI-based cybersecurity startup Cybereason recently raised $200 million in a financing round led by the SoftBank Group. The Israel-based startup stated the new proceeds will help the company’s growth.

Founded in 2012 by former members of the Unit 8200 military intelligence division, Cybereason develops military-grade technology to prevent cyberattacks. The startup is specialized in using artificial intelligence to identify network security incursions. Cybereason claims that its Cyber Defense Platform offers NGAV (next-generation antivirus), EDR (endpoint detection and response), and active monitoring services to its clients.

Speaking on the new investment, Lior Div, the CEO and Co-founder of Cybereason said, “Cybereason’s big data analytics approach to mitigating cyber risk has fueled explosive expansion at the leading edge of the EDR domain, disrupting the EPP market. We are leading the wave, becoming the world’s most reliable and effective endpoint prevention and detection solution because of our technology, our people and our partners. We help all security teams prevent more attacks, sooner, in ways that enable understanding and taking decisive action faster.”

“Autonomous security will democratize and transform the cybersecurity profession. Creating such automation in security requires fusion of multiple data sources, business context, machine learning and big data analytics,” said Yonatan Striem-Amit, CTO and Co-founder, Cybereason.

“Today, there is a shortage of more than three million cyber analysts. Cybereason’s Autonomous Security approach will elevate the analysts to spend time on higher-value tasks. This is a big data problem that all security operations centers run into and Cybereason will solve with machine learning and AI,” Striem-Amit added.

StockX hack: 6.8 million consumers’ data in jeopardy

Data breach

Popular sneaker buying and selling hub, StockX, is the latest victim of a cyber attack after hackers penetrated into the system and stole sensitive information of more than 6.8 million users worldwide.

The venture-backed firm had rolled out an email, earlier last week, asking users to change their password citing “software update”, but TechCrunch in a report pointed out that an unnamed seller contacted the media firm and claimed that information of more than 6.8 million users was stolen from StockX in a data breach in May, earlier this year. The unnamed seller also provided a sample of 1,000 records from the stolen stash following which TechCrunch reached out to customers with unique information about their record, to which every customer confirmed their data to be accurate and in tandem with what the seller had provided.

Following this, Zack Whittaker of TechCrunch tweeted, “@StockX was hacked, with more than 6.8 million user records stolen. Instead of telling its customers, the company told them that this week’s password reset was for “system updates” TechCrunch also went ahead and published their exclusive story. It was only after the hack went public that StockX bothered informing the customers of the hack stating: “We were alerted to suspicious activity potentially involving customer data. Upon learning of the suspicious activity, we immediately launched a comprehensive forensic investigation and engaged third-party data incident and forensic experts to assist.”

StockX also notified that their investigation is still underway, and the forensic data has suggested that customer data like name, email addresses, user names, passwords, shipping addresses and even purchase history of users were accessed by an “unknown third party.” It also stated that financial details were not affected by the breach.

StockX also tried to justify its action and added that “We want you to know that we took these steps proactively and immediately, because we had just begun our investigation and did not yet know the nature, extent, or scope of suspicious activity to which we had been alerted. Though we had incomplete information, we felt a responsibility to act immediately to protect our customers while our investigation continued—and we took steps to do so.”

StockX’s desperate attempt to cover the entire incident not only raises eyebrows on its morals and ethics but even on the legal front. Even though StockX is based out of Detroit, it has a global customer base and that also means the incident will be subject to the EU’s General Data Protection Regulation. Only time will tell how much StockX would be fined for the incident. For one, the reputation of the company is already soiled. While we speak, the user data is already being sold on the dark web for just about $300.

Protecting consumer data is one thing, but the method for communicating security breaches is something that enterprises need to learn. And the StockX incident should be a lesson for all consumer-facing enterprises.

Sephora’s Online Customers Suffer Data Breach

Panasonic network breach

Any kind of business would become a target for attackers, who are on the hunt for valuable information.   Sephora, a provider of personal care and beauty products, recently revealed a data breach that exposed around 3.7 million of its online customers’ records. The French-based cosmetics company said that hackers reportedly posted the compromised information on the dark web for sale.

According to a cybersecurity firm Group-IB, hackers have breached personal data of Sephora’s customers in Hong Kong, Singapore, Thailand, Indonesia, Philippines, Malaysia, Australia, and New Zealand. Sephora stated that the customers who only used the company’s online services or mobile app are affected in the incident.

The exposed information included details like gender, name, surname, skin tone, ethnicity addresses, email details, and contact details. However, Sephora clarified no credit card details were compromised in the incident and they’ve not found any misuse of the stolen data.

Earlier, around 10 French-based companies had fallen victim to a global hacking attack that hit hospitals, car factories, and other organizations in more than 150 countries. The announcement was made by the French government cybersecurity agency ANSII.

In another incident, French automaker Renault had to stop production of vehicles at various sites to prevent the spread of a ransomware cyberattack. Fortunately, France, Romania, and Slovenia had already undertaken preventive measures to stop the spread of the ransomware. Due to this, more than 90 percent of factories in France were running normally. Renault also resumed production within a few days. All Renault factories are back to normal including northern France plant in Douai, a Renault spokesman said.

The Big 3 Battles we are fighting for Endpoint Security

endpoint protection

Contributed by Brian Madden, Lead Feld Technologist, End-User Computing, VMware

This article first appeared in CISO MAG. To read more articles like these, subscribe to CISO MAG here: https://cisomag.com/magazine/

I joined VMware a little over a year ago and since then, I’ve traveled to 18 countries and 26 U.S. states to meet with over 160 current and prospective customers. During these customer visits, I listen to their end-user computing plans and strategy, explain VMware’s vision and product roadmap, and discuss how those two might align. The most surprising thing to me after all these meetings is how similar most customers are, particularly when it comes to their most pressing end-user computing challenges.

I know this goes against everything we learn from Dale Carnegie or from Sales Training 101 – “Make every customer feel special!”. and “Each customer is a unique snowflake!” While every customer and conversation is indeed unique, I’ve found that every customer is more or less fighting the same battles when it comes to locking down devices, apps and data.

Here are my top three observations:

Battle #1: A Dissolving Security Perimeter

Do you remember the days when every employee came into the office, logged into a stationary device that was connected to the corporate network, and IT could definitively identify the security perimeter? Those days are far behind us as employees demand to work from anywhere, including from locations outside of areas where IT has control. Employees also want to access apps and data from a variety of devices, even if IT doesn’t “own” them.

As the number of devices accessing corporate data grows, IT faces an expanding security perimeter problem which in turn results in a larger attack surface. To address this, many companies are adopting a “Zero Trust” approach. Put simply, Zero Trust means that all sources attempting to access company data – either from inside or outside a secure company network – must continuously be verified. This “never trust, always verify” mentality ensures the right people have the right level of access to the right resources and in the right context. While there is no silver bullet when it comes to achieving a Zero Trust security architecture, identity, access, and device management are the core technologies that organizations should start with on their journeys.

By implementing these technologies as part of a broader security architecture, IT can verify user identity and device compliance as individuals access company resources irrespective of their physical location.

Battle #2: If Security Policy Diminishes Experience, Employees Will Go Rogue

No matter what security approach IT takes, it must not (but oftentimes does) get in the way of employees’ digital experience. As they watch the corporate security perimeter dissolve, typical IT response and policy is to block application access, which in turn obstructs employee experience and productivity. This will not work. The simple truth is that if IT doesn’t let the employee work in the way they want, employees will find a way to circumvent security tools and processes, putting the organization at even greater risk

VMware recently commissioned research that demonstrates a direct correlation between providing employees with a positive digital experience (i.e., device choice/ flexibility, seamless access to apps, remote work capabilities) and an organization’s competitive position, revenue growth and employee sentiment. So, there is a lot on the line when it comes to making sure your security strategy jives with employee experience.

Again, back to the Zero Trust discussion: With the right architecture in place that puts employee-friendly policies/ tools at the center, IT teams can strike a balance between enterprise security and employee experience. Identity verification, for example, is something employees are used to with the advent of fingerprint and facial recognition security technology. When leveraged to protect company information, the overall experience becomes more natural, familiar, and seamless for employees while also providing IT with the reassurance they need when it comes to security. Win-win.

Battle #3: Security Tool Overload

Another common security pitfall I see customers falling for is buying more products and adding more agents to employee devices. Did you know that cybersecurity teams use an average of over 80 different security products from 40 different vendors? That is crazy. In this security product arms race, what ultimately ends up happening is that InfoSec teams are left with a whole system tray full of agents and nothing is really talking to each other.

The CISO doesn’t know whether the organization is any more secure. Rather, all they know is that they continue to buy more products with the hope of covering every security vulnerability. A new approach is required – one that shifts the mindset away from detecting threats by using more tools, that sends too many alerts and one that burns out IT and InfoSec. This new approach needs to start with a digital workspace platform that has intrinsic security built-in and leverages intelligence from all sources to secure users from apps, endpoints and the infrastructure. So, find solace in the fact that you are fighting the same security battles as your fellow CISO.

The challenge for most organizations is they don’t know where to start. The answer is like that old saying, “How do you eat an elephant? One bite at a time.” A full end-user computing transformation is probably ten (or more?) separate projects, which could take years. The important thing is to focus on small steps that are quicker and easier to implement, but that also provide real value.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Small businesses in the UK suffer 10,000 cyber-attacks per day: FSB

cyberattacks on U.K. organizations

Small businesses in the United Kingdom are the victims of repeated cyber-attacks with around 10,000 attacks occurring every day, according to the Federation of Small Businesses (FSB).

The FSB is a UK-based organization that represents small and medium-sized businesses in the country. FSB stated, in its survey of more than 1,100 smaller firms, that one in five small firms in the UK accepted that it had been the victim of a data breach in the last two years.

The survey also highlighted that more than seven million individual attacks are reported over the same period, which is 9,741 attacks a day.

The annual cost incurred by the firms due to the attacks is estimated to be £4.5 billion and the average cost of an individual attack is valued at £1,300, according to the report.

The study specified that companies based in the North West, South East, and West Midlands suffer the most cyber-attacks —  530,000 small firms reported phishing attacks; 374,000 firms reported malware incidences; there were 301,000 fraudulent payment requests, and 260,000 firms suffered ransomware attacks.

Commenting on the scenario, the FSB Policy & Advocacy Chairman Martin McTague said, “These findings demonstrate the sheer scale of the dangers faced by small firms every day in the digital arena. The issue of business crime is overlooked too often – even more so of late in this climate of sustained political uncertainty and inaction. Meaningful steps must be taken to safeguard our small firms and by extension the wider.”

The mid-market businesses in the UK have lost around £30 billion ($37 billion) in the past 12 months due to security breaches. A research from business and financial adviser Grant Thornton UK LLP discovered that cyber-attacks are a present danger for businesses in the UK. The research report, named Cyber Security – the Board Report, stated that businesses are not prepared to manage cyber risks.

Grant Thornton stated they surveyed over 500 UK mid-market companies, in which half of them reported losses of up to 10 percent of their income over cyberattacks. The research revealed that 63 percent of the companies don’t have a cybersecurity team. Only 36 percent stated that they’ve provided cybersecurity training to their employees. And more than half of the businesses (59%) don’t have a cyber incident action plan, according to the research.

Karamba Security partners with Cypress to offer Embedded Cyber Security Solutions

U.S. and Australia to Jointly Develop Cyber Training Platform

Karamba Security, a provider of embedded cybersecurity, recently announced its collaboration with the semiconductor manufacturing company Cypress Semiconductor to jointly improve cybersecurity for the automotive industry.

Karamba Security provides embedded cybersecurity services to connected machines. Headquartered in the U.S., Karamba Security claims that its technology automatically strengthens the security posture of the connected systems and protects against Remote Code Execution (RCE) cyberattacks.

The new collaboration allows Karamba to leverage the Cypress Semper Flash in-memory compute capabilities for connected systems to reduce cybersecurity risks.

Commenting on the new alliance, Ami Dotan, the Karamba Security’s co-founder, and CEO said, “Working with one of the industry leaders in embedded systems solutions enables us to add advanced cryptographic capabilities to our runtime integrity solution, leveraging the flash root of trust. More than ever autonomous vehicles, industrial controllers and the enterprise edge devices need security technology embedded in them, without impacting mission-critical performance. By teaming up with Cypress, we’ve strengthened our commitment to our customers to offer the most advanced cybersecurity solutions.”

“Karamba’s focus on protecting the runtime and software integrity in automotive embedded systems makes this end-to-end collaboration a natural one,” said Sandeep Krishnegowda, director of marketing and applications in the Flash Business Unit at Cypress. “Built-in security speeds up the production of connected systems so they can get to market faster and safer. Our collaboration with Karamba enhances our security offerings, leveraging the unique technology in the Cypress Semper NOR Flash to provide complete and simple solutions for the automotive industry.”

Aviation Cyber Security Market expected to register 11% CAGR during 2019-2024

93% of Global Airlines are Vulnerable to Email Fraud Risk: Report

ResearchAndMarkets.com has just released a report titled Aviation Cyber Security Market – Growth, Trends, and Forecast (2019 – 2024). According to the report, the aviation cyber security market is expected to register a CAGR of around 11% during the forecast period of 2019-2024.

The aviation sector has benefitting from the increasing level of connectivity and digitization across the value chain. The enabling technological advancements in the aviation sector are creating enormous opportunities to have better customer service, security, flight efficiency, operations and the passenger experience both on the ground and in the air.

  • With the advancement of the technology and connectivity, the market has become prone and vulnerable to cyber-attacks of malicious malware activities targeting the aviation sector. For instance, in December 2017 major amount of sensitive security data was stolen at Perth Airport. The world’s biggest airline Cathay Pacific Airways Ltd. also suffered from data breach, with the hacker accessing personal information of more than 9.4 million customers.
  • Detection and prevention are the most sought-after solution as these threats are becoming more stealth with every attack. Owing to such instances the corporates are trying to utilize services of domain experts thus, creating an opportunity for the market.
  • A key driver for the market is the need for technological advancements in order to prevent the aviation sector IT infrastructure and networks from cyber-attacks. Further, as the aerospace sector moves toward the autonomy of spaceflight and is investing billions in developing aviation technologies, the need to protect the infrastructure becomes critical.

The aviation industry relies heavily on IT infrastructure for its ground and flight operations. The security of these airline systems directly impacts the operational safety and efficiency of the industry, and indirectly impacts the service, reputation and financial health. The report highlights cyber security in aviation sector by solution and application spanning from airline management, air cargo management, air traffic control management and airport management.

Key Market Trends

1. Airport Management Holds a Significant Market Share being the Passengers Contact Point

  • With the number of air travel passengers increasing at a rapid rate year over year, airports continue to upgrade their infrastructure intelligence to improve passengers travel experience and support the growth. By enabling the exchange of real-time information on flights schedule, collaboration, and airport-wide process integration, airports significantly improve operational efficiencies, passenger services, and advanced security capabilities. These factors drive the adoption of It systems thus, impacting the market
  • According to SITA Air Transport IT Trends Insights Report, 2018, the airport and the airline have IT investment prioritized as cybersecurity, with 94% of studied airports planning to invest in the cybersecurity programs over the next three years.
  • There is an increase in demand for cyber security in aviation in Asia-Pacific region. According to Indian Government’s Vision 2040, India need s approximately 200 commercial flights airports and an estimated investment of USD 40 to USD 50 billion to handle at least 1.1 billion passengers. Also, the civil aviation authorities of the world are emphasising to enhance and ensure safety and security standards across fast-growing aviation ecosystem.
  1. North America Holds the Largest Market Share
  • According to the Cyber Security Breaches Survey 2018, in the United States, the state of California lost more than USD 214 million through cyber crime alone. Such cases creates a need for the cyber security in the country and impacts the demand.
  • In the United States, the transportation companies and air carriers especially aviation sector, in particular, are incorporating more advanced cybersecurity programs that align with the National Institute of Standards and Technology (NIST) standards.
  • The United States lays high emphasis on its aviation sector and invest mainly in research and development of advanced cybersecurity systems. For instance, 2019 President’s Budget includes USD 15 billion of budget authority meant for cybersecurity-related activities along with Airport and Airway Trust Fund having USD 32.4 million of 2019 budget.
  • In addition, the new budget spending for Canadian infrastructure protection is marked at USD 144.9 million over five years including Canada’s critical cyber systems including sectors in the finance, telecommunications, energy and transport sectors.

Competitive Landscape

The competitive rivalry in the market is high among the dominant market players such as Cisco Systems, Inc. and Thales Group among others. There is significant research and development spending being done by the market vendors to improve the offering on a continuous basis. Version upgrades with enhanced capabilities differentiate the market offerings. The market is experiencing collaborations, mergers and acquisitions to enable stronger technical capabilities and wider applications.

  • In April 2019 – Thales Group acquired a software security company Gemalto for USD 5.4 billion. It plans to create a new division, to be named as digital identity and security, for redefining its divisions as aerospace, space, ground transportation, defense and security, and digital identity and security.
  • In October 2018 – Cisco acquired Duo Security to integrate its network, device and cloud security platforms. Duo’s zero trust authentication and access products has helped the company to let its customers to securely connect users to any application on any networked device.

 

Internet Connected Cars are vulnerable to attacks: Report

Connected Cars

Consumer Watchdog, a non-profit organization, stated that all advanced cars with Internet connections to their safety-critical systems are apparently vulnerable to fleet-wide hacks.

The report, Kill Switch: Why Connected Cars Can Be Killing Machines And How To Turn Them Off, revealed that automakers have disclosed the high risk of such hacks to their investors, but are keeping the public in the dark as they market new features based on Internet connections. For example, Ford disclosed to the Securities Exchange Commission in its 10K filing that the company and its suppliers have been the subject of a malicious hack, but the public is unaware of the exact details.

Researchers stated that most connected vehicles share a similar vulnerability. According to the report, the infotainment system is connected to the Internet through a cellular connection, and also to the vehicle’s CAN (Controller Area Network) buses. This outdated 1980s era technology links the vehicle’s most critical systems, such as the engine and the brakes. Experts agree that connecting safety-critical components to the Internet through a complex information and entertainment device is a security flaw. This design allows hackers to control a vehicle’s operations and take it over from across the Internet.

The report revealed that every connected car comes with an Internet kill-switch that physically disconnects the Internet from safety-critical systems. It concludes that future designs should completely isolate safety-critical systems from infotainment systems connected to the Internet or other networks.

“Connecting safety-critical systems to the Internet is inherently dangerous design,” said Jamie Court President of Consumer Watchdog.  “American car makers need to end the practice or Congress must step in to protect our transportation system and our national security.”

“Despite working on the problem for more than a decade, carmakers have proven incapable of creating Internet-connected vehicles that are immune to hacking, which is the only standard that can keep consumers safe,” the report concludes.  “With connected cars rapidly overtaking the market, consumers will soon have no haven from the online connections that threaten them.”

A similar study by Ponemon stated that nearly 30 percent of companies in the automotive segment does not have a proper cybersecurity team to handle its technology and security infrastructure, let alone secure smart cars. The state is so dire that many do not even engage a third-party vendor to secure the software in the connected cars.

The study also pointed out that nearly 63 percent of all vehicle manufacturers do not even test half of their software, hardware and other technology deployed in their vehicles. The study sampled 15,900 IT security practitioners and engineers in the automotive industry.

Dragonfly lets hackers steal WPA3 Wi-Fi passwords

Patchwork BADNEWS, APT31 threat group

The new Wi-Fi security protocol WPA3 is no longer secure. University researchers have discovered several new holes that enable hackers to steal Wi-Fi passwords.  No one has exploited these vulnerabilities yet, but it merits immediate patching.

The flaws in the WPA3 Wi-Fi authentication protocol were discovered by Mathy Vanhoef of New York University Abu Dhabi and Eyal Ronen of Tel Aviv University & KU Leuven.  They published the results of their research in a technical paper, available on Vanheof’s dedicated microsite. Vanhoef also discovered the KRACK vulnerability that affected WPA2 in 2017.

It may be recalled that the Wi-Fi Alliance launched WPA3 in June. It came in two flavors: WPA3-Personal, and WPA3-Enterprise.

The issues relate to WPA3-Personal which uses an authentication protocol called Simultaneous Authentication of Equals (SAE), also known as Dragonfly. A WPA3-Personal device uses it as a handshake mechanism to connect with other Wi-Fi-enabled devices.