Home Blog Page 30

Threat Actors Exploit Log4j Vulnerability to Deploy Khonsari Ransomware

Log4j Vulnerability, Log4Shell

Days after the disclosure of Log4Shell, a critical zero-day vulnerability CVE-2021-44228 in the Apache Log4j library, researchers have now identified threat actors exploiting the Log4Shell flaw to deploy a new ransomware variant Khonsari and a remote access Trojan Orcus.

Threat actors allegedly exploited the flaw using botnets like Mirai and Muhstik against vulnerable systems to spread malware. According to a report from Bitdefender, attackers targeted Linux servers and systems running on the Windows operating system.

“This attempt to exploit the Log4j vulnerability uses the malicious hxxp://3.145.115[.]94/Main class to download an additional payload. On Sunday, 11th December, Bitdefender observed this payload as a malicious .NET binary file download from hxxp://3.145.115[.]94/zambo/groenhuyzen.exe. This is a new ransomware family Khonsari after the extension used on the encrypted files. Once executed, the malicious file will list all the drives and encrypt them entirely, except the C:\ drive,” the report said.

Second Log4j Vulnerability Discovered

The second critical vulnerability (CVE-2021-45046) affects all versions of Log4j from 2.0-beta9 through 2.12.1 and 2.13.0 through 2.15.0, and could allow attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup or a Thread Context Map pattern to craft malicious input data using a JNDI Lookup pattern resulting in a DDoS attack. However, CVE-2021-45046 can be mitigated by applying the patch released by the Apache Software Foundation (ASF) in its latest advisory.

CISA Recommends Fixing Log4Shell Flaw Before Christmas

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently notified organizations to patch the affected and vulnerable systems to the Log4Shell flaw by Christmas. CISA added the Log4Shell vulnerabilities to its actively-exploited security flaws list along with 12 other vulnerabilities. In addition, the agency also announced a dedicated portal that provides guidance on the Log4Shell vulnerability to all public and private sector organizations in the U.S.

“For these vulnerabilities to be remediated in products and services that use affected versions of Log4j, the maintainers of those products and services must implement these security updates. Users of such products and services should refer to the vendors of these products/services for security updates,” CISA said.

Experts Take on the Issue

Glen PendleyCommenting on the rising threats with Log4j vulnerability, Glen Pendley, Deputy  Chief Technology Officer at Tenable, said, “Log4Shell, a critical vulnerability in Apache Log4j, is in a league above every other vulnerability we’ve seen in the last few decades. It gives flaws like Heartbleed and Shellshock, a run for their money because of just how pervasive and devastating it is. Everything across heavy industrial equipment, network servers, down to printers, and even your kid’s Raspberry Pi is potentially affected by this flaw. Some affected systems may be on-premises, others may be hosted in the cloud, but no matter where they are, the flaw is likely to have an impact.

Cybercriminals are already rubbing their hands with glee as early signs of ransomware activity have started to emerge. The worst part is, we aren’t even in the thick of it yet. Don’t be surprised when some major disruptions occur over the next few weeks and months, pointing at Log4j as the root cause.”

Emerging Cybersecurity Technologies to Know for 2022

CISA, cybersecurity, cybersecurity technologies

Technology is constantly evolving and now, more than ever, staying ahead of the digital evolution – specifically cybersecurity – is integral to an organization’s success. This past year, we have seen a major rise in ransomware attacks, and businesses have been paying the price. There are plenty of lessons to be learned from these instances to better protect IT systems and corporate environments moving forward, but the most important finding is that ransomware is now a business security issue for every organization, across every industry and vertical. Unfortunately, in 2022, the threats will likely continue to increase as technology becomes more advanced and hackers develop new tactics. These are the three cybersecurity technologies that every security professional should be aware of to effectively protect their organizations going into 2022.

By Ivan Paynter, National Cybersecurity Specialist at ScanSource

A Zero-trust Environment / Software-defined Perimeter

When it comes to ransomware attacks, hackers cannot encrypt systems they do not have visibility into. However, by combining two technologies – zero-trust and software-defined perimeter – it is possible to address this concern. Software-defined perimeter, in combination with zero-trust, allows for constant enumeration of the user’s device, as well as verifies the identification and access level of the user. Once the user device is verified to the required standard – and only at that time – will the distant end device port be accessible to that user. The strategic use of these two technologies ensures greater security for the organization, as it only allows users access to the network’s element at their designated user accessibility level. This type of platform can be configured in numerous ways to meet one’s cybersecurity needs. At the end of the day, this technology allows users to access the level necessary to perform their required functions. Once the user logs out or is timed out the port is closed, and the distant end system can no longer be identified, as no ports will respond to inquiries.

MDR/EDR/XDR

Endpoint Detection and Response (EDR) is truly the next generation anti-virus with intelligence. Extended Detection and Response (XDR) ties in EDR data with network events for greater visibility within the environment.  EDR’s also allows for greater visibility into behavioral analytics.  Just because the user has access rights to data does not ensure his or her due diligence with said data. EDR and XDR applications increase visibility and correlation of events taking place within the environment reducing the noise so one may identify the threat expediently, therefore reducing dwell time.  As a standalone, most EDR systems provide value-added data but do not provide an in-depth holistic view of the environment. However, integrated with other standard cybersecurity tool sets and EOG 24/7 provides a level of security to allow any CISO a good night’s sleep. MDR platforms become a vital and necessary point of protection from ransomware and other forms of malware.

Technology (Good, Bad and Ugly)

On the opposite side of the conversation, hackers and scammers are also utilizing artificial intelligence and machine learning to their advantage as well. Machine learning and artificial intelligence technologies are great defenses but are also being used to defeat existing cybersecurity defenses. For this reason, it is imperative organizations remain vigilant and current within their defenses.  This is one very strong reason to use a third-party security service to monitor. manage and secure their environment rather than trying to build their own security operation center. Third-party security services are particularly adept at identifying and eradicating malfeasance quickly, to ensure business continuity. Dwell time has now been reduced from months to minutes due to the tool sets, data gathering and correlation most MDR deploy. With the use of behavioral analytics, machine learning, vulnerability scanning, network segmentation, east/west monitoring, and traffic analysis Network Security Operation Centers, combined with artificial intelligence, organizations (ideally through a third-party security provider) can gain a much better understanding of their environments and their user community.

BONUS: The Human Firewall

In addition to staying up to date on the latest technology trends and tools in the cybersecurity industry, it would be unwise to ignore one key element of cybersecurity that does not come from the latest technologies. In the industry, we like to say that the most important line of defense sits between the computer and the chair. As we observed in the Brenntag attack in April 2021, it’s imperative to start with the fundamentals of cybersecurity and provide awareness training, establish multi-factor authentication, network segmentation, and constant vulnerability monitoring. The human firewall is the most effective first and last line of defense against cybersecurity attacks.


About the Author

Ivan PaynterIvan Paynter is the National Cybersecurity Specialist of ScanSource and has over 30 years of experience in cyber security, working at Verizon and Masergy before coming to ScanSource in 2019.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Fear Fatigue Exploits Cybersecurity of Remote Employees

Employees

The increasing hybrid workforce due to the global pandemic has severely impacted cybersecurity, bringing swift changes in the work environment. The latest report from Malwarebytes revealed that the ongoing pandemic and hybrid workforce is reshaping how organizations and employees secure data and their thoughts towards cyberattacks. The report, “Still Enduring from Home,” found that 61% acknowledge that employees experience fear fatigue, with 27% feeling particularly overwhelmed by fear.

Fear Fatigue on Rise

Malwarebytes stated that nearly 80% of survey respondents reported some level of fear fatigue within their organization. Fear fatigue is defined as the demotivation to follow recommended protective behaviors, emerging gradually over time and affected by a number of emotions, experiences, and perceptions. Fear fatigue can often lead to employees’ negligent behavior, such as opening an email attachment without properly scrutinizing the sender or neglecting to turn on a VPN while using public Wi-Fi.

Changing Cybersecurity Habits

It was found that remote work environments have driven changes in spending on cyber protection:

  • More than 70% of respondents said they now spend more on cybersecurity tools, cloud-based software tools, and IT support and management staff.
  • Over 71% saw an increase in the use of password management tools, 66% reported an increase in the use of VPNs, and 65% increased their use of data management and backup platforms.
  • Despite the increase in spending on cybersecurity tools, 62% were concerned about accidentally exposing data, while 51% harbored concerns that cloud-based collaboration tools may not offer adequate security, especially as use increased significantly.
  • Nearly 55% revealed that their organizations had made some improvements in their cybersecurity posture since the beginning of the pandemic, with 70.5% implementing new cybersecurity training and 74% implementing new tools.

“While organizations showed great versatility in shifting to dispersed work environments during the pandemic, it also brought to light the need for an entirely different and more robust approach to security that offers more education and support to employees. We have more threats coming through on less secure personal networks and a rise in brute force attacks to reach businesses through remote desktop protocols. We need a holistic approach that secures employees no matter what network they are on or what device they are using,” said Adam Kujawa, Director of Malwarebytes Labs.

“Given that personal devices are often not secured or protected as well as work devices, this can significantly increase and organizations’ threat surface for potential cyberattacks. Stronger awareness and overall protection that helps keep threats at bay have improved for many organizations over the course of the pandemic. However, with cyberattacks and threats continuing to escalate, organizations need a robust, layered security approach that puts in failsafe measures for the inevitable human error that comes with fear fatigue, providing the confidence needed for employees to work securely and productively from anywhere,” Kujawa added.

Opinion

Stressed and distracted employees expose enterprises to cyberattacks. And phishing is one of the major security risks, as attackers try to target the entire network system. Since the pandemic hit, the personal and professional spaces have blurred and it is important to understand and address these issues as fear fatigue or stressful employees could leave a lasting impact on cybersecurity.

U.S. Consumers Lost $148 million to Gift Card Scams in 2021

Gift Cards, cyber ghosts

The holiday season is around the corner, and cybercriminals are already targeting users with fake shopping deals and scams. A report from the U.S. Federal Trade Commission (FTC) revealed that Americans lost $148 million to gift card scams during the first nine months of 2021, which is an increase compared to last year.

The report stated that over 40,000 consumers used gift cards to pay a scammer in that time frame. Most consumers also paid fraudsters impersonating large companies or government agencies.

“Since 2018, both the numbers of consumers filing reports in which gift cards were the form of payment to scammers and the amount they have reported lost have increased steadily. Scammers favor gift cards because they are easy for people to find and buy, and they have fewer protections for buyers than some other payment options. Scammers can get quick cash, the transaction is largely irreversible, and they can remain anonymous,” the report said.

Top Gift Card Brands Impersonated by Hackers include: 

  • Target – reported a loss of $35 million
  • Google Play- $17 million loss
  • Apple – $16 million loss
  • eBay – $10 Million
  • Walmart – $6 million

Also Read: 3 Common Online Frauds to Watch Out in 2022

Other Key Findings

  • Target gift cards emerged as the most popular choice for scammers in the reports received by the FTC. Target gift cards accounted for about $35 million in payments to scammers, more than twice as much as any other brand of gift cards.
  • The median amount lost when consumers paid with Target gift cards, $2,500, was higher than any other card brand, with nearly a third reporting losses of $5,000 or more.
  • One in four people who report losing money to fraud says it happened when a scammer tricked them into giving the numbers on the back of a gift card.
  • Scams demanding gift cards often start with a phone call from someone impersonating a well-known business or government authority.
  • Many people report that a scammer posing as Amazon or Apple told them to send pictures of the numbers on gift cards to fix a supposed security problem with their account.

“Gift cards are far more frequently reported than any other payment method for fraud, and the numbers have reached staggering new highs compared to past years. Scammers favor gift cards because they are easy for people to find and buy, and they have fewer protections for buyers than some other payment options. Scammers can get quick cash, the transaction is largely irreversible, and they can remain anonymous,” the report added.

Preparing for the Quantum Threat: The Road Ahead to Quantum-secure Cryptography

Quantum Cryptography

With the rapid advancement of quantum computers, the threat they pose to encryption is no longer a question of if, but when. The NSA and UK National Cyber Security Centre have been warning companies for years to secure their systems as the threat is both severe and imminent.

While quantum computers have huge promise, they also risk introducing an unprecedented cybersecurity problem. Quantum computers will have the power to crack the encryption used to protect almost all of the world’s sensitive information, enabling them to smash through the encryption standards used today to protect workers’ most sensitive conversations, personal data, secure networks, and business transactions.

Research from the likes of Goldman Sachs, IonQ, and QC Ware shows the successfully improved performance of a specialized quantum algorithm on real hardware.

The Scale of Quantum Security Threat

Quantum computers will have the power to solve computational problems that were previously thought impossible, and while this presents many opportunities, it also poses a significant security risk as it renders traditional encryption methods – particularly RSA and ECC that are used to protect virtually all of the world’s sensitive information – obsolete. Modern computers would take years to crack the mathematical problems that underpin all modern encryption, but fully scalable quantum computers will be able to do it efficiently. This means that virtually every organization and the device is at risk.

The quantum threat is not just a worry for future data – it is also possible to store information now and decrypt it later. Companies are currently at risk of having data stolen now and stored for decryption once quantum computers have been fully developed. A recent report by Booz Allen Hamilton reveals the likelihood of major players in the quantum field, fostering information now that they plan to decrypt later. This outlines the importance of companies preparing for the threat as soon as possible, as security is already at risk.

Roadmaps laid out by experts have predicted that quantum computers will surface sometime this decade, but companies need to begin preparations now for implementing new cryptography to ensure their future data is protected. The threat of such an attack is credible and urgent enough that the NSA and other government agencies across the world have warned that ‘we must act now’ to prepare for it.

Designing New, Quantum-ready Encryption Standards

After the NSA’s warning on the quantum threat in 2015, the US Government’s National Institute of Standards and Technology (NIST) initiated a process to define new, quantum-ready cryptographic standards – known as post-quantum cryptography. Implementing these standards will be the biggest cryptography transition that has taken place in decades.

For the last 6 years, NIST has been in the process of identifying and standardizing post-quantum algorithms to establish a clear starting point to guide us toward a quantum-secure future, with the new algorithms replacing the current classical-security standards. With over 80 submissions from over six different continents, it has truly been a global effort followed closely by academia, industry, and government.

The NIST standardization process is coming to a conclusion in the coming weeks as NIST plans to pick a handful of diverse algorithms out of the remaining candidates.

How Can Companies Prepare for the Threat?

NIST is unequivocal that businesses should be preparing now, stating that “it is critical to begin planning for the replacement of hardware, software, and services that use public‐key algorithms now so that the information is protected from future attacks”.

Understanding the timeline for necessary post-quantum security is essential for ensuring the safety of the company. Businesses should consider the timeline in which they need to employ quantum-safe solutions and choose a strategy to gradually implement new cryptography – in some cases, a complete transition could take up to 5-10 years. CISOs should be aware of a realistic path to implementation which, for many companies, will likely involve integrating hybrid cryptography solutions. A number of offerings now exist that provide widely used public-key encryption and incorporate one of NIST’s finalist algorithms that will soon be established as a benchmark for protection against quantum attacks.

In terms of preparation, businesses should begin with a “quantum risk assessment” that consists of the following; a software/hardware cryptography audit, establishing what information needs to be kept confidential and for how long, identifying data that requires long term integrity, identifying what data privacy regulations need to be followed, review their infrastructure and flexibility, assess their crypto agility and the potential limitations on their infrastructure. Based on the outcome, a transition to the Post-Quantum Cryptography roadmap should be put in place. Organizations should keep the NIST guidelines in mind and follow their updates during the design and implementation phases of their PQC roadmap.

Changing the standards of a technology that is deeply embedded in our daily lives is a tremendous task that will take a lot of preparation and a long time to execute securely. We are changing the standards because we have to. Because the potential damage of the quantum threat to our society is wide-scale, it threatens all industries from finance and utilities to national intelligence. Speaking of which, intelligence agencies are taking the threat seriously, and have made it crystal clear that Post-Quantum Cryptography provides the best mitigation against the quantum threat. However, with the NIST standardization process coming to a conclusion by the end of this year, it’s time for companies and the whole supply chain of cybersecurity products, software, and hardware, to take action.


About the Author

Ali El KaafaraniDr. Ali El Kaafarani is the CEO, Founder, and Researcher at the Mathematical Institute, University of Oxford, where he co-founded the cryptography group when he joined in 2015. Prior to that, Dr. El Kaafarani was a Research Engineer at the Cloud and Cybersecurity team at HP Labs. He holds a Ph.D. in cryptography from the University of Bath, U.K.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Kronos Private Cloud Customers Impacted by a Ransomware Attack

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

The cybersecurity space is abuzz with service disruptions, stolen data, account hacks, scams, data breaches, and ransomware attacks. Some of these make headlines every day. No one is secure, be it Ikea, Volvo, the critical infrastructures, the crypto wallets, or even the Prime Minister of India, whose Twitter account was recently hacked. Both individuals and organizations are targets for the threat actors.

Kronos, a workforce management and human capital management cloud provider based in the U.S., was recently attacked by a ransomware gang. The service disruption of its Kronos Private Cloud (KPC) platform resulted in complete chaos at the customers’ end.

Kronos is a popular HR and payment tool used widely and has a huge global customer base.

In a communication sent to impacted KPC customers, the company reported the cybersecurity incident that had disrupted the KPC. An unusual activity impacting the parent company Ultimate Kronos Group (UKG) solutions using KPC was noticed, and immediate action was taken to investigate and prevent the incident.

The notice said, “It is a ransomware incident affecting the KPC — the portion of our business where UKG Workforce Central, UKG TeleStaff, Healthcare Extensions, and Banking Scheduling Solutions are deployed. At this time, we are not aware of an impact to UKG Pro, UKG Ready, UKG Dimensions, or any other UKG products or solutions, which are housed in separate environments and not in the Kronos Private Cloud.”

Services Go Offline 

The KPC solutions were unavailable, and customers were requested to evaluate and implement alternative solutions to ensure business continuity. The company has not been able to provide a definite timeframe to restore the systems and its services. Kronos claimed, “Any of these solutions deployed in on-premise (self-hosted) environments are not affected, and we are not experiencing impact to UKG Pro, UKG Dimensions, or UKG Ready.”

Unanswered Questions

The incident was reported on December 11, 2021, and we have no information on the adversary, techniques, or ransom demand. The company has only disclosed the nature of the breach and assigned it to a ransomware attack. The extent of the damage caused to the customers is immeasurable as these are basic applications used daily by the entire workforce of an organization.

Shmulik Yehezkel, Chief Critical Cyber Operations Officer at CYE expressed, “Today, the industry classifies attacks into categories: CNE, for Computer Network Exploitation or espionage; CNI, for Computer Network Influence, and CNA for Computer Network Attack; this upcoming year, we are going to see more and more state-level actors carrying out what we call CN-ALL attacks. In this type of attack, state-level actors will combine all the cyber warfare elements–espionage, influence, and disabling systems. These attacks will be particularly challenging because they require response simultaneously on several fronts. CISOs need to be prepared to deal with the technical aspects of recovering data and accessing backup systems, while also dealing with law-enforcement and legal teams, addressing the media, and, when needed, informing regulatory officials.”

Newer techniques and trends are already paving the way for 2022, and the number of cybersecurity incidents is only getting more mainstream. There was a time when cybersecurity was all about hacking and virus, but now, it is about protecting and preventing security breaches and state-sponsored attacks.

How to Prevent Password Spraying Attacks

password spraying attacks, credential stuffing attacks

Weak or easy-to-guess passwords are potential threats to corporate networks. Poor password habits could make the entire organization’s security vulnerable to unauthorized intrusions. Threat actors leverage various techniques, like Password Spraying attack, to exploit weak passwords and penetrate vulnerable network systems.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a Password Spraying Attack?

In a password spraying attack, adversaries try to guess users’ passwords by using a list of common and predictable passwords. Password spraying attacks are similar to brute-force attacks, in which threat actors predict users’ credentials to gain unauthorized access to targeted systems by the trial-and-error method.

Password spraying attacks usually enable hackers to:

  • Obtain access to users’ private data
  • Penetrate email and other online accounts
  • Initial access and privilege escalation
  • Evasion of security detection

Hackers Obtain Credentials in Password Spraying Attacks by:

  • Researching on targets’ social media profiles online
  • Leveraging social engineering scams to obtain sensitive information
  • Trying common passwords like – qwerty, password, Password123, 123456, etc., to break into accounts
  • Exploiting compromised accounts to obtain email addresses
  • Moving laterally in the compromised network to affect more accounts and steal credentials

Also Read: These are the Most Common Passwords of 2021

How to Prevent Password Spraying Attacks

Organizations can boost their overall security posture by following basic password management measures. These include:

  • Enabling two-factor or multi-factor authentication procedures
  • Using strong passwords that include numbers, symbols, and both uppercase and lowercase letters
  • Changing all default passwords
  • Keeping well-documented procedures for password resets
  • Implementing a Zero Trust security model to detect anonymous intrusions
  • Restricting access to authentication URLs
  • Enforce the use of strong passwords
  • Enabling CAPTCHA feature for authentication
  • Enabling account lockout option, after multiple wrong login attempts
  • Maintaining security awareness training to employees regularly

Also Read: 6 Practices to Strengthen Your Password Hygiene

Weak Passwords Make Hacker’s Job Easy

Cybercriminals often exploit leaked/stolen passwords from data breaches to break into user accounts. Pet names, favorite movies, or hobbies are used as passwords, exposing user accounts to password spraying and account takeover attacks. According to a survey, 63% of employees in the U.S. have reused their passwords on work accounts and devices. It was found that employees are 6.5 times more likely to reuse their passwords.

What Experts Say… 

Ritesh ChopraCommenting on the importance of passwords, Ritesh Chopra, Director Sales and Field Marketing, India & SAARC Countries, NortonLifeLock, said, “The remote working trend and the heightened dependence on digital platforms brought about by the ongoing pandemic have contributed to an increase in cyberattacks, with cybercrime rising through unsecured networks, websites, and emails. We often save financial data, personally identifiable information (PII), contacts, credit and debit card information on our personal devices.

“All this data is at risk online. One of the ways we can secure it is by using password managers that allow us to keep multiple and more complicated passwords. It is good that consumers today recognize the need for cyber safety and that it can start with something as simple as having stronger passwords,” Chopra added.

A robust password management program and adherence to cybersecurity practices are the best defense against evolving hacker intrusions.

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Why a Career in Cybersecurity is More Exciting Than You Might Think

cybersecurity career

Back in 2019, I wrote an article about the talent shortfall in technology and cybersecurity. Unfortunately, since the pandemic and because of Brexit, that gap, particularly here in the UK, has only widened. As of 2021, the global talent shortage already amounts to 40 million skilled workers worldwide. By 2030, the global talent shortage is predicted to reach 85.2 million workers.

By Anthony Webb, VP International, A10 Networks

This means that companies worldwide risk losing $8.4 trillion in revenue because of the lack of skilled talent. This gap is keenly felt in security and again there is currently a shortage of 350,000+ cybersecurity specialists in Europe alone.

I firmly believe that the future of security will only be as strong as tomorrow’s talent.  And as the talent gap continues, companies need to get creative about how and where they find the next cyber expert.

Cybersecurity as a Career Option

While the cybersecurity industry is a fantastic and dynamic place to work, unfortunately, many are not aware the industry exists as a career option. Therefore, vendors need to do more to attract talent into the sector. This industry has very low unemployment, and as mentioned above, many countries have a deficit of employees. It is a very fast-moving and exciting industry, but sometimes I feel like a lone crusader when I talk about the benefits of this industry to new talent.

I think many are not aware because there are no specific university degrees in cybersecurity, so it is overlooked as a natural career choice to pursue. That said, institutions have just started to offer degree apprenticeships in cybersecurity.

Such programs are designed to help young people explore their passion for tech by introducing them to cybersecurity. It further covers a broad range of activities and offers a bursary to financially support undergraduates through university in a subject of their choice, in addition to a cybersecurity degree apprenticeship scheme.

This is fantastic, but the industry needs to do more, such as partnering with local schools and funding more science, technology, engineering, and mathematics (STEM) programs. We need to create more internship and apprenticeship opportunities for early talent. In addition, vendors should look at launching robust upskilling or retraining initiatives internally.

Passionate Problem Solvers

Those looking towards a career in cybersecurity need to be able to thrive in an environment that is dynamic and fast-moving. It is a sector that is critical to the UK economy and to the daily lives of people up and down the country.

Key attributes include being able to be calm under pressure, being lateral thinkers, versatile and dedicated problem solvers. It’s the same as any industry; police officers have chosen that career path through a desire to protect the public. Cybersecurity professionals are passionate about protecting the infrastructure of nations and enterprises. This is an important job, but an exhilarating one, too. Without a second thought, people, businesses, and institutions all over the UK are relying on the cybersecurity team to defend our digital world.

Cybersecurity professionals also need to be able to simplify complex issues and communicate in layman’s terms. This means that anyone in the organization – from the board to the receptionist – can understand how to protect the business.

High Stakes, High Rewards

Today, we live in a world where our phones are rarely out of our hands and our laptops are central to our ability to perform work. Since the pandemic, we’ve gone online for just about everything and this means we are exposing more data than ever. This reliance on technology makes protecting our devices, networks, and data critical. This is an industry where the stakes are high. Data breaches, exfiltration, and high ransoms are making headlines daily and the costs to organizations, their brand reputation, and their customers have become astronomically high. But there are also high rewards for working in the industry, cybersecurity professionals have the opportunity to, not only solve critical problems but use technology for good.

The pandemic has shone a light on the escalating threat landscape in all industries. The implications of a compromised credit card or an unsuspecting phishing link are great. Hackers can earn more money with minimal effort than ever before. Cybersecurity industry professionals need to respond with speed and innovation and think like a cybercriminal. The more hackers we face, the smarter security professionals need to be. There are clearly endless opportunities for career growth.

Explore the Possibilities

Where should someone interested in a career in cybersecurity begin?

Get as much varied experience as possible. In today’s work environment, the days of working for one company for your entire career are over. If offered an assignment abroad, grasp it with both hands. It can result in becoming more experienced in how different cultures deal with data protection and cybersecurity needs.

There are various resources available that provide information about cybersecurity apprenticeships, and hopefully, in the near term, we will start to see similar initiatives. Likewise, people in the cybersecurity industry need to do a better job educating and informing those entering the workforce about career opportunities.

Cybersecurity is a profession that requires constant learning and acquiring new skills. There is a multitude of resources, including online learning, cybersecurity books, and security-related news available to those who want to learn more and ultimately enter the profession. Be a passionate practitioner.

I have no doubt that smart people applying innovative technology will always find a way to solve a cybersecurity problem.


About the Author

Anthony WebbAnthony Webb is a leader with a high level of drive and determination and the proven ability to deliver vision and strategic direction. With a significant ‘C’ level engagement spanning over a 20-year sales career in the IT, Data Communications, and Telcom industry, Anthony serves as the VP International at A10 Networks. In his current role, he is responsible for the management and expansion of sales and the company’s channel strategy is also part of his area of ​​responsibility.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Did Snatch Ransomware Snitch Volvo Cars’ R&D Data?

Volvo

As news of ransomware attacks continue to grow, Volvo Cars is another name that has found a place on the victim list.

By Minu Sirsalewala, Editorial Consultant, CISO MAG

In a recent notice, Volvo Cars confirmed that it was a victim of data breach by a third-party; its R&D file repository was illegally accessed and some data was stolen.

Snatch ransomware claimed responsibility for the breach, though Volvo Cars has not validated or reported the claim.

Borns IT- und Windows-Blog, a German blogger, shared the news through his blog post that the DarkFeed website has published brief information in which the Snatch ransomware group claims a successful attack on the company. The ransomware gang has shared screenshots of the stolen data establishing the breach.

Volvo said in a statement, “Volvo Cars has conducted its own investigation and is working with third-party specialists to investigate the property theft. We do not, with currently available information, see that this has an impact on the safety or security of our customers’ cars or their personal data. We cannot comment further at this time.”

In an exclusive email interaction with CISO Mag, Volvo Cars shared, “We are aware that an organization called ‘Snatch’ has claimed responsibility for the property theft; Volvo Cars is investigating.”

On the ransomware demand it asserted, “No files have been encrypted; however, the company has been approached by the third party.”

It also added, “After detecting the unauthorized access, we immediately implemented security countermeasures including steps to prevent further access to its property and notified relevant authorities.”

What is Snatch?

According to malpedia, Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode, which loads minimal drivers and background apps or agents. In this mode the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload. Due to the Safe Mode the malware goes undetected and is difficult to identify.

Sophos MTR Team revealed, “The ransomware, which calls itself Snatch, sets itself up as a service that will run during a Safe Mode boot. It quickly reboots the computer into Safe Mode, and in the rarefied Safe Mode environment, where most software (including security software) doesn’t run, Snatch encrypts the victims’ hard drives. Snatch runs itself in an elevated permissions mode, sets registry keys that instructs Windows to run it following a Safe Mode reboot, then reboots the computer and starts encrypting the disk while it’s running in Safe Mode.”

Threat actors have been resorting to tools and techniques primarily used for testing and troubleshooting to launch cyberattacks. Like the pentesting tool Cobalt Strike and the Safe Mood used for troubleshooting. There has been a trend where threat actors are also looking at old school techniques and repackaging them to launch unexpected campaigns and coming out of their hideouts.

And this is one of the security trends we see coming in 2022.


MinuAbout the Author

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

 

 

Hackers Actively Exploit Log4Shell Flaw in Apache Log4j

Log4Shell

Log4Shell, a severe zero-day vulnerability in Apache Log4j library, sheds light on the risky practices of organizations relying on open-source code libraries to build enterprise-scale applications. The remote code execution (RCE) vulnerability CVE-2021-44228 reportedly allows remote hackers to execute arbitrary code and take full control of the vulnerable devices.

Apache Log4j is a popular Java logging library leveraged by numerous organizations worldwide to enable logging in a wide set of popular applications.

Security researchers from Netlab stated that adversaries are actively exploiting vulnerable servers by leveraging Log4Shell to deploy cryptocurrency miners and malware variants like Cobalt Strike.

Botnets to Exploit Log4Shell

The researchers also found threat actors using botnets like Mirai and Muhstik against vulnerable systems to spread malware and orchestrate distributed denial-of-service (DDoS) attacks.

“The Log4j vulnerability that came to light at the end of the year can undoubtedly be considered a major event in the security community. We have been concerned about which botnets would be exploiting this since the vulnerability was made public. Our Anglerfish and Apacket honeypots have caught two waves of attacks using the Log4j vulnerability to form botnets, and a quick sample analysis showed that they were used to form Muhstik and Mirai botnets respectively, both targeting Linux devices,” the researchers said.

Affected Systems Include:

Systems and services that use the Java logging library, Apache Log4j between versions 2.0 and 2.14.1. This includes many applications and services written in Java.

Mitigation

The Apache Foundation recommended that all developers and users update the library to version 2.15.0 using methods described on the Apache Log4j Security Vulnerabilities advisory to avoid hackers exploiting their servers.

If applying the patch is impossible, Apache also provided certain remediation steps in its advisory. These include:

  • For Log4j 2.10 or higher: add -Dlog4j.formatMsgNoLookups=true as a command line option or add log4j.formatMsgNoLookups=true to the log4j2.component.properties file on the classpath to prevent lookups in log event messages.
  • For Log4j 2.7 or higher: specify %m{nolookups} in the PatternLayout configuration to prevent lookups in log event messages.
  • Consider blocking LDAP and RMI outbound traffic to the internet from vulnerable servers.