Home Blog Page 298

Unsecured Database leaks Honda Employees’ Personal Data

DEO data breach

Global automobile manufacturer Honda Motor Company recently suffered a data breach after a leaky database exposed its employees’ sensitive information online.  

According to a security researcher Justin Paine, who discovered and reported the incident, an unprotected ElasticSearch database exposed around 134 million rows of sensitive data from Honda’s network systems.  

Database Zone defines Elasticsearch as a database that stores, retrieves, and manages document-oriented and semi-structured data. 

The exposed information included technical details of employees such as machine hostname, MAC address, internal IP, operating system version, installed patches, and the status of Honda’s endpoint security software. 

Apart from these technical details, the database also exposed employee’s data such as email address, employee name, department, last login, employee number, and account name. The database even revealed information related to the CEO’s laptop, full name, email address, email nickname, employee ID, account name, last login date, department, MAC address, installed patches, OS version, endpoint security status, IP address, and device type. 

The researcher revealed that the database was apparently left online without password protection on July 1, 2019, and it was discovered on July 4. However, authorities at Honda clarified that the database was secured after it was alerted by the researcher. 

Earlier, a similar kind of Elasticsearch server exposed more than 24 million financial and banking documents online. According to security researcher Bob Diachenko, the exposed server contained highly sensitive data of thousands of individuals who took mortgages over the past decade with the U.S. banks and other financial institutions. 

Bob Diachenko stated that he identified the unprotected server on January 10, 2019, which contained 24,349,524 credit and mortgages reports occupying 51 GB storage. The server was taken offline and the data was secured on January 15, 2019, after Diachenko reported the incident to the server’s vendor. 

The insecure server allowed open access to the documents that contained loan and mortgage agreements, repayment schedules, financial and tax documents, names, addresses, birth dates, social security numbers, and other sensitive information. 

Data breach exposed One Million Payment Card details in South Korea

Security researchers discovered that hackers have compromised more than one million payment card records and posted for sale on the Dark Web since May 29, 2019. A recent report, from cybersecurity firm Gemini Advisory, revealed that South Korea is the largest victim of the Card Present (CP) data theft in the entire Asia-Pacific (APAC) region.

“While the entire Asia Pacific (APAC) region is experiencing a noticeable uptick in attacks against brick-and-mortar and e-commerce businesses, South Korea has emerged as the largest victim of Card Present (CP) data theft by a wide margin,” Gemini Advisory stated in its report.

Gemini Advisory stated that it observed around 42,000 compromised South Korean-based CP records posted for sale in the dark web. The report also highlighted that June 2019 had 230,000 records, which is a 448% spike and July was even more drastic with 890,000 records, a 2,019% increase when compared to May’s figure.

The report explained about CP fraud, which involves collecting payment card data from in-person transactions. The attackers to do this by installing malware into a system that has point-of-sale (POS) devices on its network. Another method of accessing CP record is via skimmers that are installed at ATMs or POS terminals, according to the research report.

“While the exact compromised point of purchase (CPP) remains unclear, these records may have been obtained from the breach of a parent company that operates several different businesses in a variety of locations. It is also possible that a point-of-sale (POS) integrator was breached, allowing a threat actor access to a single integrator service that interfaces with many merchants,” the report added.

Nearly half of the South Korean population got affected when their sensitive information was compromised by an insider at the Korea Credit Bureau in 2014. The credit rating company stated that around 20 million records were stolen, which included customer names, phone numbers, social security numbers, credit card numbers and their expiration dates.

The investigation concluded the data breach was done by a temporary consultant at the Korea Credit Bureau (KCB), who gained unauthorized access to the customers’ data from the company’s server and sold it to marketing firms. The culprit and the people who purchased the stolen data from him were later arrested.

Everbridge acquires Threat Intelligence Company NC4

Acquisition

Everbridge, a provider of enterprise software applications, recently announced its acquisition with threat intelligence provider NC4 in a cash deal of around $83 million. The association allows both the companies to provide comprehensive solutions for public and private enterprises to detect vulnerabilities and thwart potential cyber threats.

Based in Boston and Los Angeles, Everbridge offers Critical Event Management (CEM) and software application services to enterprises to help them improve their security posture. NC4 offers threat intelligence solutions to private and government organizations, and communities to assess risk data and mitigate cyber risks.

The new collaboration combines NC4’s real-time threat intelligence platform with Everbridge’s existing Global Intelligence Operations Center (GIOC) analysts and CEM platform to create end-to-end threat assessment and incident communications platform, that reduces the damage of internal and external threats to critical assets.

“With NC4, we are adding the industry leader in threat intelligence, making Everbridge one of the largest providers of data for enterprise security and operations in the world,” said David Meredith, CEO of Everbridge. “NC4 offers the most comprehensive threat data in the industry and this acquisition dramatically expands the overall situational awareness Everbridge will provide organizations, from incident identification to response, mitigation or ultimately, avoidance and prevention.”

“Verified sources and analysis eliminate the noise and enable us to generate the most impactful information while eliminating false positives,” said Karl Kotalik, President and CEO of NC4. “It takes the best of both worlds, machine learning and AI-enabled incident collection and human analysis, to generate the most meaningful intelligence. Everbridge’s market-leading platform, the breadth of its offerings, and the experience of its global team made for a natural fit with NC4. We look forward to aligning with the market leader to jointly provide organizations with unprecedented visibility into the threats and incidents that can impact people and business.”

Earlier, Everbridge partnered with G4S, a globally integrated security company. Through this partnership, G4S will utilize Everbridge’s Critical Event Management platform and products in combination with its own security services and software toolsets to deliver new integrated security services and solutions for its global customers. The combined security solutions can be used in a customer’s GSOC (Global Security Operations Center), G4S’s virtual GSOC managed service, or a hybrid of both security environments.

Addressing the unanswered organizational needs of today’s CISO

data protection

Contributed by V3 Cybersecurity

The past twenty years in cybersecurity have been an incredible study in the hyper-growth and evolution of an industry.  We can attribute much of the forced evolution to increasingly sophisticated threat actors, vendor expedience in getting to market, and the media for highlighting the security shortcomings of popular brands to protect client data.  Had we not publicly shared the experience of threat evolution from DDoS to Ransomware and the public shaming of Target, one could argue that the cybersecurity industry would have followed a more traditional course of evolution.

During this period, technology has evolved from non-stateful network layer firewalls as the primary control, to today’s container-based application layer controls and everywhere in between.  Operationally, we have gone from health and availability monitoring to User Behavior Analytics and predictive control methods using enterprise Security Information and Event Management (SIEM) technology.  Incident response has effectively evolved into its own sub-industry with focus on forensics, threat hunting, and response readiness.

Despite these advancements, hyper-growth has left equally important areas of cybersecurity struggling to keep up.  The most notable is the cybersecurity skills gap that continues to be a focus of the industry in trying to meet market demand.  To narrow the focus, the lack of skills and experience in the Chief Information Security Officer (CISO) role is creating an unrealized blind-spot for many security programs.  Even the most tenured CISOs are being challenged by the increasing demands of the role and needs of their stakeholders.  Let’s explore some of the areas that CISOs we have spoken with are challenged with as the threat landscape and technology continue to evolve at record pace.

The ability to understand the effectiveness and communicate security posture effectively is one of the most challenging issues that CISO’s face today.  This capability is critical when securing resources, aligning security with the organization’s risk profile, and in being able to show due care on behalf of the organization in the event of a compromise.  CISO’s look to consulting firms for maturity benchmarking, conferences for peer interaction, and vendors to help understand and develop their vision.  These sources, while valuable, have significant flaws and inherent bias, yet they continue to be the primary sources for communication with cybersecurity program stakeholders regarding the security posture of the organization.

The need to effectively communicate the context of cybersecurity programs is further supported by the National Association of Corporate Directors (NACD)’s “2019 Governance Outlook,” in which The NACD report specifically called out the need for boards to appropriately review the effectiveness of their organizations’ cybersecurity management programs.  Knowing the level of organizational integration between regulatory requirements and cybersecurity threats landed these two issues in the top three trends concerning boards in 2019.

The good news is that there are innovative companies focused on using technology to assist cybersecurity leaders in solving their most complex problems.  “In the past twenty years leading and consulting cybersecurity organizations, communicating the business context and demonstrating due care has placed CISO’s in an isolated and vulnerable position.  We intend to address this issue and provide a platform that provides unparalleled transparency with live dynamic benchmarking against commonly accepted cybersecurity standards and frameworks.  Our goal is to help CISO’s move toward a fully integrated cybersecurity program in which security becomes a responsibility of the organizational leadership, board, and industry,” said Jorge Conde-Berrocal, CEO of V3 Cybersecurity, Inc.

The Minerva platform by V3 Cybersecurity, Inc is positioned to disrupt the maturity assessment segment of the cybersecurity industry.  The platform provides a subscription-based vehicle for dynamic and live visibility into the maturity of cybersecurity programs using accepted standards like NIST CSF, NIST 800-53, and ISO27001.  The platform dynamically updates the industry benchmarks with each new client on the platform.  The Maturity Engine provides the ability to take snapshots which allows for the communication of maturity over time.  Additionally, the platform allows for ad hoc benchmarking based on CISO input in order to address current program maturity elements independent of the selected Standards.

“Our Research and Development team examined the maturity assessment business model and found numerous issues with the approaches used by consulting firms.  These include assessment fatigue, interviewer bias, response distance, currency, and consultative captivity,” continued Jorge.  The current business model is reflective of an agency focused approach to a market driven requirement.  It is easy to understand why the general sentiment of CISO’s we discussed this topic with was that assessments remain a costly and necessary evil in the management of their security programs.

“The need for holistic and integrated security is the North-star for most organizations, however we continue to see organizations struggle with adopting and managing fully integrated security programs.  The need for integration and visibility into the various elements of a security program are required for effective leadership today,” says Rootstrap, Inc. CEO David Jarrett.  Rootstrap Inc. is a Los Angeles based development firm focused on secure code and product development.

Despite the challenges with the current assessment business models, the importance of assessments and benchmarking remain a critical pillar in the ability to demonstrate due care.  This places CISO’s in a difficult position between required use of costly consultants for assessments and the lack of demonstrable evidence of organizational progress.  Given the choice between poor options, CISO’s continue to hire consultants to provide some level of assurance to the organization that they are exercising due care.

This new breed of security company is focused on helping leaders manage the business of security while helping the organization’s stakeholders understand the liability and risk associated with their collective cybersecurity decisions.  The ability to provide business context is the next evolution for cybersecurity programs and leaders.  With the tools and intelligence being developed to address issues like benchmarking, stakeholder buy-in, organizational goal alignment, and incident exposure valuation, the cybersecurity leaders of tomorrow will no longer be isolated and viewed as hurdles for the business.  Tomorrows leaders will be seen as expert communicators and educators of the implications and risks associated with decisions made by the organization.

CISO MAG does not evaluate the advertised product, service, or company, nor any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Confluera raises $9 million in Series A funding

Startup funding

Cybersecurity company Confluera Inc. recently secured $9 million in a Series A funding round led by Lightspeed’s Founder & Managing Partner Ravi Mhatre with participation from John W. Thompson, former CEO of Symantec and Chairman of Microsoft; Frank Slootman, former CEO of ServiceNow; and Lane Bess, former CEO of Palo Alto Networks.

The Palo Alto-based company stated the new proceeds will support its cybersecurity platform that intercepts and defends against cyberattacks.

Founded by security experts from Oracle, Juniper, LinkedIn, and Rubrik, Confluera helps security analysts to turn into cyber defenders by enabling them to stop breaches in real time. The company claims that its Real-time Attack Interception and Defense platform is a pioneering product in the industry to identify and stop ongoing multi-stage attacks.

“The cybersecurity industry is broken. The industry has focused on a plethora of point solutions that fail to address modern cyberattacks. We have created a unique platform to deterministically intercept and stop cyberattacks in real time,” said Confluera Co-Founder & CEO Abhijit Ghosh. “We aim to help enterprises around the world manage security risks across their infrastructure.”

“Confluera is uniquely positioned to revolutionize how brands protect themselves and their customers from modern cyberattacks,” said Ravi Mhatre, Founder of Lightspeed Ventures. “This funding round will enable Confluera to accelerate its growth and bring to market a cybersecurity product that is unmatched in its ingenuity and effectiveness.”

“The caliber of the Confluera team speaks to the confidence we have in their innovative and market-disrupting approach to cybersecurity,” said John W. Thompson, Chairman of Microsoft. “The fact that the Confluera platform can help identify and engage with the attackers in real time, is the first step towards winning the cyber warfare.”

 

Emerson launches new cybersecurity lab in India

Industrial Cybersecurity

The technology and engineering company Emerson recently announced the launch of its new cybersecurity lab in Pune, a city in India. The new center, which is located at Emerson’s Innovation Center, employs 900 people and works on future innovations and cybersecurity training for security professionals.

Emerson stated the new facility will help manufacturers adopt digital transformation strategies by protecting their plant operations, networks systems, and data resources, the Economic Times reported.

The facility, which is a part of Emerson’s global cybersecurity network, will focus on defining security requirements, designing threat models, maintaining security practices and simulating cyber-attacks in industrial environments to prevent potential threats.

“Cybersecurity is frequently cited by customers as a top consideration for Industrial Internet of Things adoption,” said Lal Karsanbhai, executive president of Emerson’s Automation Solutions business. “Emerson’s investment in a broad portfolio of technologies and services is helping global leaders accelerate their digital transformation with confidence.”

“This new center further extends our leadership in industrial transformation and enhances our ability to collaborate with customers on the critical element of cybersecurity as they adopt the latest digital technologies to optimize performance,” Karsanbhai added.

According to a recent survey by network and endpoint security firm Sophos, less than 10 percent of Indian IT managers are confident that they have skilled cybersecurity talent to thwart a cyber-attack. The survey titled, ‘The Impossible Puzzle of Cybersecurity’, points out that IT teams only about a third of their time to manage security, but most of them takes a punch due to lack of experts, budget and technology.

Among the surveyed, nearly 81 percent felt that the cybersecurity budget of their organization is way below what is required, with 89 percent stating that they find it very difficult to keep up with the challenges that are thrown at them.

The study surveyed over 3,100 IT decision makers from several small and medium sized industries in India, Canada, Mexico, Colombia, Brazil, the UK, France, Germany, Australia, Japan, South Africa and the United States and was conducted between December 2018 and January 2019.

Cybersecurity startup CyberSmart raises €1.4 million

Startup Investment

Cybersecurity startup CyberSmart recently secured €1.4 million ($1.5 million) in a financing round led by deep-tech investor IQ Capital. The London-based company stated the new funding will help building next-generation technical capabilities and expanding business reach.

CyberSmart, which was in stealth mode for two years, is founded in 2017 by cybersecurity experts Jamie Akhtar and Mariella Thanner.

CyberSmart helps the Small Medium Enterprises (SMEs) identify weaknesses in their information security systems, using machine learning capabilities. The startup also develops practical strategies to address cybersecurity threats. CyberSmart claims that its compliance technology platform prevents up to 99.3% of potential cyber threats.

“Having been in stealth mode since 2017, through both GCHQ’s Cyber Accelerator and CyLon, we’re excited to be able to scale our operations and start talking about how we’re helping to protect our nation’s most promising businesses from cyber threats,” said Jamie Akhtar, CEO of CyberSmart. “This funding will enable us to achieve scale within our home market and invest in enhanced technical capability.”

“CyberSmart is a superb example of the types of companies that IQ Capital invests in – deep tech startups with the potential for global scale,” said Kerry Baldwin, partner at IQ Capital. “Cybersecurity is now at the top of the agenda at board-level for all data-rich businesses, however, few have proactive strategies in place to tackle the issue. CyberSmart is backed by the Government to help and certify businesses, and we are excited to be part of their growth journey.”

Head of SEC Enforcement Department resigns

Securities and Exchange Commission

Robert A. Cohen, the chief of the United States Securities and Exchange Commission (SEC), a Division of Enforcement’s Cyber Unit, has stepped down from his services.

According to an official announcement, Cohen served as the first chief of the Cyber Unit since its commencement in 2017.  The Cyber Unit focuses on cyber-related trading violations like hacking, cybersecurity disclosures, and securities violations relating to cryptocurrency and digital assets.

Speaking on his resignation, Cohen said, “It has been a privilege working with great colleagues at the SEC, whom I cannot thank enough for their commitment, perseverance, and friendship. I am proud of our work together, which has had a strong and positive impact for investors.”

Stephanie Avakian, the Co-Director of the SEC’s Division of Enforcement, stated that Cohen supervised a number of investigations during his tenure. “Rob has been a true leader in the Enforcement Division. We relied on Rob to lead the Cyber Unit because of his record of handling complex, high priority enforcement cases with both toughness and fairness, while also mentoring and training countless SEC attorneys and supervisors,” said Stephanie Avakian.

“The Cyber Unit has been a great success under Rob’s strategic leadership,” said Steven Peikin, Co-Director of the SEC’s Division of Enforcement. “Soon after its creation, the Cyber Unit immediately began filing impactful cases that protect investors and demonstrate the SEC’s ability to respond nimbly to new and difficult challenges.”

Capital One breached! 100 million credit card applications leaked

Capital One

Capital One Financial Corporation, a bank holding company, recently disclosed a data breach that affected approximately 100 million individuals in the United States and approximately 6 million in Canada. The company stated that the attacker exploited a specific configuration vulnerability in its digital infrastructure and allegedly accessed the data.

The compromised information included names, addresses, phone numbers, and dates of birth, along with 140,000 Social Security numbers, 80,000 bank account numbers, credit scores, and transaction data. However, Capital One clarified that no credit card account numbers or log-in credentials were compromised in the incident.

The FBI charged the suspect, Paige A. Thompson, with computer fraud and abuse. Thompson, who went by the hacker name erratic, allegedly exploited a misconfigured firewall to access the Capital One cloud repository and exfiltrate the data in March 2019.

“On July 19, 2019, we determined there was unauthorized access by an outside individual who obtained certain types of personal information relating to people who had applied for credit card products and Capital One credit card customers. This occurred on March 22 and 23, 2019. This type of vulnerability is not specific to the cloud. The elements of infrastructure involved are common to both cloud and on-premises data center environments,” Capital One said in a statement.

“The configuration vulnerability was reported to us by an external security researcher through our Responsible Disclosure Program on July 17, 2019. We then began our own internal investigation, leading to the July 19, 2019, discovery of the incident,” the statement added.

Security researchers stated that Phishing and Ransomware attacks are the most reported types of cyber-attacks on financial services firms. According to the Audit and Consulting firm RSM International in the United Kingdom, around 819 cyber incidents were reported by Financial services firms to the Financial Conduct Authority (FCA) last year.

RSM said that Retail Banks were the most frequently affected by cyber-attacks (486 security incidents) followed by wholesale financial markets (115 attacks), and retail investment firms (53 incidents). In 2018, financial firms reported around 93 cyber-attacks, in which half of these (48 attacks) were phishing attacks while 20 percent (19 attacks) were ransomware attacks.

 

Google researchers disclose vulnerabilities in Apple iMessage

Apple iMessage

Security researchers at Google have discovered six flaws in Apple’s iMessage software that could impact the iOS operating system and make the devices vulnerable to attacks. The bugs were discovered by Natalie Silvanovich and Samuel Grob, digital forensic experts at Google Project Zero.

However, Apple has released fixes for the vulnerabilities recently and urged the users to update. But the researchers said the patch for the sixth discovered bug is not yet provided in the update to its mobile operating system.

According to the researchers, four of the six security bugs, CVE-2019-8641, CVE-2019-8647, CVE-2019-8660, and CVE-2019-8662 can execute malicious code on a remote iOS device, without user’s knowledge. The bug can be exploited when an attacker sends a malicious message to the victim’s phone, which will be executed when a user opens and views the received message.

The researcher described that the fifth and sixth bugs, CVE-2019-8624 and CVE-2019-8646, allow an attacker to leak data from a device’s memory and can read files without the user interaction.

Earlier Natalie Silvanovich discovered that answering a WhatsApp video call can compromise smartphones. The researcher stated that a security bug in the WhatsApp messenger application allows attackers to take control of the smartphone by placing a WhatsApp video call. Describing the issue as a “memory corruption bug in WhatsApp’s non-WebRTC video conferencing implementation,” Silvanovich stated that a memory heap overflow issue causes when an attacker places a specially created malformed RTP (Real-time Transport Protocol) via WhatsApp video call request, resulting in the break-in to the mobile memory.

The security flaw discovered in August 2018 affected the WhatsApp application on Android and iOS devices, but not on WhatsApp Web, the research report stated. The Facebook-owned messaging app fixed the flaw on September 28 for the Android platform and October 3 for the iPhone platform after Silvanovich reported the issue to the WhatsApp team.