Home Blog Page 337

Facebook violated cybersecurity law, says Vietnam’s ministry

Facebook

The Ministry of Information and Communications (MIC) of Vietnam stated that Facebook has violated its new cybersecurity law by allowing users to post anti-government comments on its platform.

The concern was raised at a media conference held by MIC’s Authority of Broadcasting and Electronic Information (ABEI). The ABEI stated the social media giant had violated Vietnamese cybersecurity laws in three major areas: managing content, online advertising, and tax liability.

“Facebook had reportedly not responded to a request to remove fan pages provoking activities against the state,” the ABEI said in a media statement. “Management agencies had sent emails repeatedly asking Facebook to remove distorted and misleading content. However, the social networking giant had delayed removing the content, saying it did not violate its community standards.”

“Facebook must co-ordinate with relevant agencies to manage payments and taxes for commercial and advertising transactions in Vietnam. If Facebook did not take positive steps, Vietnamese regulators would apply necessary economic and technical measures to ensure a clean and healthy network environment,” added ABEI.

This comes days after Vietnam lawmakers approved the controversial new cybersecurity law that took effect from January 01, 2019, that controls the Internet content and global tech companies operating in the country. The new cyber law requires Facebook, Google, and other international tech firms to store local users’ data on local servers and set up offices in Vietnam.

The new law prohibits Internet users in Vietnam from spreading anti-government information and posting false information that could cause damage to the country. It also prevents the circulation of content that’s fake, slandering, or inciting violence.

Arilou, STMicroelectronics join hands to prevent cyber threats in automotive industry

Connected cars

Arilou Information Security Technologies, a cybersecurity solutions provider for the automotive industry, and energy-efficient solutions provider STMicroelectronics joined hands to work together on the integration of Arilou’s Intrusion Detection and Prevention system (IDPS) software solution. The new alliance is intended to provide integrated solutions to address the emerging threats via communication buses in Automotive Body and Gateway applications.

Arilou, a part of the global automotive software supplier NNG Group, provides high-end cybersecurity solutions for the automotive industry. The Israel-based company claims that its software IDPS security offers complete detection and prevention measures against cyber threats.

Headquartered in Switzerland, STMicroelectronics offers intelligent and energy-efficient products/solutions across a variety of electronic applications. The semiconductor manufacturer stated that it’s working on developing smarter driving and smarter factories, cities and homes, and the advanced Internet of Things devices.

“This development work allows us to see our software solution tailored to specific devices and applications in the automotive sector,” said Ziv Levi, CEO, and founder of Arilou. “As automotive cybersecurity pioneers, working on this project with ST has allowed us to be among the first to take real steps on a path leading to the fully secured vehicle.”

“Securing the connected car is a multi-layer project and as a leading supplier of automotive processing solutions, ST is, and must continue to be, at the center of efforts to monitor systems, detect intrusions, and protect against those intrusions,” said Luca Rodeschini, Head of Automotive Strategy and Microcontroller Business Unit, STMicroelectronics. “ST’s product, technology, and market leadership require us to work with security experts like Arilou to anticipate and meet cybersecurity challenges head-on.”

Israel’s Radware to acquire Indian-based startup ShieldSquare

Acquisition

Radware, a cybersecurity and application delivery solutions provider, recently announced that it’s going to acquire India-based bot management solutions provider ShieldSquare. The Israel-based company stated the new acquisition will help to expand its cloud security portfolio.

The deal, expected to finalize in the first quarter of 2019, will boost Radware’s existing cloud security portfolio to help companies thwart cyber-attacks, including data harvesting and scraping attacks, account creation and account takeover attacks, denial of inventory, application DDoS, and brute force attacks.

Radware helps enterprises with its cybersecurity and application delivery solutions for the physical, cloud, and software-defined data centers. The company claims that it secures the digital assets of the enterprises by providing infrastructure, application, and corporate IT protection services globally. The acquisition allows Radware to offer ShieldSquare’s leading bot management solutions under its new Radware Bot Manager product line.

Based out in the Indian state Bengaluru, ShieldSquare was founded by security researchers Pavan Thatha, Vasanth Kumar Gopalakrishnan, and Rakesh Thatha in 2014. Its cloud-based Anti-Bot solutions help companies distinguish between human and non-human traffic on their websites, mobile applications, and APIs. The startup claims that it’s one of the pioneers in the bot mitigation industry with strong security solutions for attack detection, threat research, reporting, and analysis categories.

“This acquisition allows us to expand our portfolio with robust bot management solutions that strongly fit our strategic goal to continue and deepen our integrated portfolio, organically and inorganically. Bot management can stand alone as product offerings as well as integrate into our suite of attack mitigation solutions,” said Roy Zisapel, Radware CEO. “We chose ShieldSquare because of their strong technology synergy, advanced machine learning capabilities, and the opportunity to expand Radware’s existing cloud security services. These Bot-Management services along with Radware’s Cloud WAF services offer comprehensive protection of applications. We are excited to welcome the ShieldSquare team into the Radware family.”

Software bug leaks personal data of 285 Singapore Airlines’ fliers

Singapore Airlines

A software glitch possibly exposed personal information of 285 members who used the Singapore Airlines (SIA) services. The Singapore flag carrier stated that a bug in its website caused a data leakage of KrisFlyer, a regular flyer program of Singapore Airlines.

The bug exposed KrisFlyer customers’ personal information, including the member’s full name, email address, membership tier, account number, the accumulated miles/rewards, travel history, passport, and flight information, according to Straitstimes.

The officials at SIA stated that the incident occurred on January 04, 2019, from 2:00 am to 12:15 pm when two or more users logged in to their KrisFlyer accounts at the same time. The airline stated that it has informed Singapore’s Personal Data Protection Commission about the customer information leakage and also notifying the affected customers.

“We have established that this was a one-off software bug and was not the result of an external party’s breach of our systems or members’ accounts. The issue has been resolved and we will carry out a detailed review to ensure this will not happen again,” the airline said in a statement.

“The protection of our customers’ personal data is of utmost importance to SIA, and we sincerely regret the incident,” it added.

The data hacks/breaches have become common in the airline industry. In September 2018, a cyber-attack at Bristol Airport caused technical issues which led to the malfunction of flight information screens. The airport authorities notified that the customers were unable to read any arrival or departure information as the flight information screens went blank.

In a similar incident, British Airways announced that its payment website was compromised, affecting 185,000 customers who made reward bookings between April 21 and July 28, 2018, using a payment card. The airline discovered the incident while investigating on its previous breach that occurred in September 2018, which affected 380,000 transactions.

5 Cybersecurity Workforce Predictions for 2019

By Deidre Diamond, Founder and CEO, CyberSN

A new year is upon us and many people have been asking for my insight in to the 2019 cybersecurity job market. Unfortunately, talent acquisition and retention statistics did not improve in 2018 and I do not see them improving in 2019. Job searching is broken and our industry lacks succession planning. We will not see these statistics change until these two problems are solved. 2019 will bring significant uptick in the types of roles detailed below. Remember to put agency staffing dollars in your budgets, you will not find these people on your own.

1. AI will influence threat intelligence roles

AI utilization is increasing by defenders and attackers. Attackers are leveraging AI for targeted attack reconnaissance, exploit discovery, attack automation and potentially attacking AI defense. Defenders are utilizing AI simulated attacks and data to better understand environments, attack avenues and threat profiles. Threat Intelligence roles will play a significant part in the AI intelligence validation, threat discovery iterations and risk management measures.

2. IAM roles will have significant impact on organizations

Identity Access

The continuation of high-profile, data-rich breaches in 2018 exposed over 22 million user credentials. Two-factor authentication and enhanced authentication mechanisms are the default configuration in 2019. Managing Identity and Access to accelerate business operations in the hybrid on-prem/cloud data, services and application model will be business critical role in 2019.

3. IoT and OT roles will become more critical

Internet of Things

The number of IoT and OT technologies in enterprises is likely to be more than traditional IT assets. Insert the adoption of 5G capable IoT/OT in the workplace increases attack surface, data volume and privacy issues. Roles focusing on IoT/OT DevSecOps, security architectures and threat detection will be an in-demand expertise in all critical infrastructures.

4. Continued increase in managed detection and response (MDR) and endpoint detection and response (EDR)

Endpoint Protection

Organizations are lacking the resources to provide the necessary prevention, detection, analysis, response and complete security hygiene for the endpoint. The gap in cyber endpoint expertise is needed in the across all industries and by the managed service providers companies are turning to for 24/7 cybersecurity coverage.

5. Existing cybersecurity regulations will have impact; new regulations and legislative activity are on the horizon

cybersecurity regulations

Year 2018 marked the effective date for the EU’s GDPR and served as a final push for compliance at many companies or the beginning of a compliance journey for others. The year 2019 will increase the focus on regulatory compliance as industries and C-level executives react to GDPR penalties resulting from complaints filed in 2018, the California Consumer Privacy Act becomes effective in 2020, and the introduction of a senate bill titled Consumer Data Protection Act includes strong penalties if privacy violations occur.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

German data breach: Need for stricter online security

Germany Data Breach

Four days into 2019 and Germany saw a massive data breach where personal data and documents of several eminent public personalities including the Chancellor Angela Merkel were published online. The event has been touted to be one of the most far-reaching data breaches the country has ever witnessed. The data that was published on a Twitter account called @_0rbit, included addresses, personal letters and copies of identity cards. The account has now been deleted.

The early investigation into the matter revealed that the attack “wrongful use of log-in information for cloud services, email accounts or social networks,” Interior Minister Horst Seehofer said in a statement.

According to him, the computer systems in the German parliament have not been compromised, even though he did not provide any other details about the breach. “”One bit of positive news is that government networks are apparently not affected by this or these hacker attacks. But it’s clear that we as the federal government … must do more to improve cyber security,” he said.

The motive behind the attack is still unclear. The investigating agencies are looking into all possibilities including leaks and espionage. A government source told Reuters that the it was unlikely that a single person has been responsible for the massive breach.

In connection with the incident, a 20-year-old man was arrested from his apartment in Hesse. According to reports, the suspect has confessed and has been in detention since Sunday. However, the police has not confirmed the confession and have scheduled a press conference.

The police also searched the apartment of Jan Schuerlein, a 19-year-old techie from Heilbronn. He took to Twitter to reveal that he was being treated as a witness in the investigation.

The incident has called for improved online security for German citizens. “”Such an attack must be used as a reason to very carefully examine if everything has been done to achieve the best possible security of data,”Germany’s digital coordinator, Dorothea Baer told the Handelsblatt newspaper. “It is legitimate to examine whether software manufacturers and platforms must be required to do more to ensure data security,” she told.

NCSC advises US firms to guard themselves from state-sponsored intruders

NCSC

The National Counterintelligence and Security Center (NCSC) recently launched a campaign to help businesses in the United States defend against evolving cyber threats from foreign entities. The Office of the Director of National Intelligence (ODNI) stated that the NCSC is sending its material dubbed “Know the Risk, Raise Your Shield,” that includes videos, posters, brochures, and flyers, to the private companies around the country to help them avert cyber-attacks.

The information distributed to companies addresses a variety of subjects, including supply chain risks, economic espionage, social engineering, social media deception, spear-phishing, mobile device safety, and foreign travel risks. NCSC is also providing “NCSC’s 2018 Foreign Economic Espionage in Cyberspace” report, which highlights the nation-state threat actors, including China, Russia, and Iran. The report, released in July 2018, provides the latest information on foreign intelligence attempts to steal U.S. intellectual property, trade secrets, and proprietary data.

The ODNI statement also mentioned the recent indictments of foreign nation-state hacks by the United States, including the ones of China’s Ministry of State Security, the U.S.-China trade dispute, a North Korean-backed hacker for his role in the Global WannaCry 2.0 ransomware in September 2018, among others.

“Make no mistake, American companies are squarely in the cross-hairs of well-financed nation-state actors, who are routinely breaching private sector networks, stealing proprietary data, and compromising supply chains. The attacks are persistent, aggressive, and cost our nation jobs, economic advantage, and hundreds of billions of dollars,” said NCSC Director William Evanina.

“To enhance private sector awareness, we’re arming U.S. companies with the information they need to better understand and defend against these threats,” Evanina added.

The concerns about cyber-attacks from foreign hackers have been raised since Russian hackers interfered in the U.S. 2016 presidential election. In October 2018, the Microsoft Corporation stated that hackers linked to Russian military intelligence tried to hack the websites of two conservative think-tanks in the United States ahead of the November midterm elections.

Also, the content of voter databases of around 35 million US citizens is being peddled on a hacking forum. According to a report from threat intelligence firms Anomali and Intel 471, cybercriminals have obtained unauthorized access to the U.S. voter registration databases and put them for sale in dark web forums.

9 New Year’s Resolutions for CISOs

2019 Resolution
2019 Resolution

By Center for Internet Security

As CISOs, it’s our job to ensure all information, assets, and technologies are protected from cyber threats. Throughout the year some high priority items get pushed farther and farther down as new projects and threats develop. In an effort to help my fellow CISOs out, I’ve shared a list of what I’ll be working on in the new year in hopes that you’ll find it helpful in prioritizing your efforts in the year ahead.

1. Know your data

You can’t defend what you don’t know you have. As cloud technologies and mobile devices become workplace staples, it’s essential that CISOs consider all data for which they are responsible. Start by taking an inventory of all hardware and software your organization uses. Next, map out where data lives – whether that’s on a hard drive, in an application, or in the cloud.

2. Make an actionable crisis management plan

Productivity and Stress Concern Risk Managers While Working from Home

A crisis management plan must be actionable in order to be effective. Make sure the plan identifies which parties in the organization need to take action in a specific crisis scenario. Each role should also have specific tasks assigned, so everyone knows what to do when a situation arises.

3. Make cybersecurity relatable to employees

People are much more likely to take action when they understand what to do and why it’s important. Educating your employees about protecting their PII (personally identifiable information) can go hand-in-hand with education that protects organizational data. Many of the same skills will be useful, such as:

  • learning how to spot a phishing email
  • ensuring applications are up-to-date
  • knowing how to avoid potentially dangerous or vulnerable websites

4. Account for risk and burden in your controls

IoT devices

Many organizations rely on a combination of best practices and security guidelines to harden their systems and data. No matter how you set organizational controls, your method should account for risk and burden. We developed CIS RAM (Center for Internet Security Risk Assessment Method) to help organizations accomplish this. CIS RAM helps businesses implement the CIS Controls best practices in a risk-informed way with instructions, templates, and more.

5. Tools need a process and a process needs an audit

When developing tools, look at the processes behind them. Consider implementing DevOps – taking into account security from the start. DevOps brings together software development and IT teams to help build and test applications together. DevOps processes should be audited and reviewed to ensure they are both collaborative and efficient.

6. Vulnerabilities are only the fruit—find the root of the problem

cybersecurity

New software vulnerabilities are being discovered every day and will continue to be exploited by cybercriminals in 2019. Rather than chasing the latest threat, focus on implementing basic cyber hygiene and security best practices. Many data breaches are caused by known configuration flaws and security gaps. Implementing consensus-developed configuration standards like the CIS Benchmarks can go a long way towards your overall security posture.

7. Make third-party risks tangible

Between different applications, cloud providers, and “as-a-Service” offerings being used by organizations worldwide, it’s important for CISOs to take into account third-party risks. Identify which data and software reside with each third-party provider and delineate who is responsible for which security tasks. Then, communicate with your providers to develop a “shared security responsibility” model. This will give you greater peace of mind and a clearer picture of your third-party security risks.

8. Teach employees to become more security-minded

Employees

Employees everywhere – at schools, small business retailers, even your local ice cream shop – need to be aware of cybersecurity. Much the way that everyone learns basic security drills in case of fire or flood, employees should know what to do when a cyber incident occurs. Make sure you communicate what employees should do if they receive a suspicious email or download a malicious file.

9. Make 2019 about governance

UDP port 2019 is known as “about” – but what’s 2019 about? For CISOs, governance will be key. We must have the determination and drive to implement security controls throughout our organizations. These controls should help determine how data is managed, how to deploy security best practices, and how to respond to various cyber threats.

A shared responsibility

CISOs take on massive responsibilities to secure data and systems, but they’re not alone. By working with IT, software development, and indeed the entire organization to implement best practices, we can all resolve to be more secure in the coming year.

This content was originally published here and is posted here with permission.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

“No silver bullet to effectively mitigate emergent IoT threats”

Abhinav Biswas

Abhinav Biswas, the Alt. CISO for Electronics Corporation of India Limited (ECIL), Dept. of Atomic Energy, Govt. of India, has a wide range of agile experience, starting from the days of embedded systems, moving to web application Penetration testing & Vulnerability Assessments, followed by Data-Centre & Infrastructure Security and then to the latest trend of Cloud Risk Management amalgamated with Governance & Compliance.

He is currently responsible for protecting ECIL’s information assets in conjunction with maintaining CIA of enterprise services spread across all metro cities of India. In a discussion with Rudra Srinivas of CISO MAG, Biswas discusses challenges he faces in his role, measures businesses can implement to tackle security threats, and emergence of Internet of Things.

As a security leader, what are the challenges you face while implementing new security strategies and products?

There are number of challenges one faces when developing or implementing new security strategies or products. Below are the ones I faced:

  • Constantly expanding Threat Landscape of ECIL’s enterprise IT services with new Attack Vectors like Ransomware, Mass-scale Distributed Denial of Service (DDoS), Novel Spear Phishing etc. which further increases the lack of systematic security & emergency preparedness.
  • Timely application of Endpoint security patches still remains a critical security vector where numerous factors come into play like up-front upgradation costs, training, efficacy, ease of use, change management issues etc. Establishing a completely Automated Security Patch Management system is a big challenge.
  • Lack of proper skilled human resources for efficient SOC operations & proactive threat hunting requirements. Most SOC operations in ECIL have been Reactive in nature.
  • Difficulty in benchmarking APT & Anti-Ransomware solutions based on in-premise POCs conducted by top global vendors.
  • RFP creation process of SIEM (Security Incident & Event Management) systems specific to ECIL requirements. Non-Availability of standard SIEM evaluation framework.
  • Change Management issues in implementing Digital Signatures & Certificates using USB-tokens/smart-cards and integration issues with SAP ERP system.

According to you, in what aspects are Indian businesses lagging behind with regard to the cybersecurity management?

Lack of proactive security and emergency preparedness can be a big issue. Though big companies have Business Continuity Plans (BCP) & Disaster Recovery (DR) Plans implemented as part of InfoSec Policy, but they are not imbibed in their work culture. Most Indian CISOs will admit that in case of a breach, lack of proactiveness has always led to panic and caused delay in taking the right action.

If big companies are ill-prepared to face the cyber threat, small and medium enterprises (SMEs) are sitting ducks because most of them are not prepared at all. They have no processes or systems in place nor do they hire dedicated cyber professionals.

Lack of rigid Bring-Your-Own-Device (BYOD) policy is another challenge. While companies can ensure that their official devices are well-protected, they do not have much control over personal devices. We also don’t see indigenously developed security products and technologies. Trusting foreign vendors with imported hardware security products is question of national security because of the rise of embedded trojans & Stuxnet-like attacks.

What is your organization doing to give its employees a thorough understanding of the vulnerabilities of their systems?

We have taken following steps to make our employees aware of vulnerabilities:

  • Conducting in-house training programmes by security experts to educate and transform the SOC staff into a skilled workforce
  • Increasing the frequency of Red team & Blue team exercises & drills.
  • Carrying out security/vulnerability awareness training programs for regular employees supplemented with quarterly internal audits of all end-user systems.
  • Hosting Monthly Security Bulletin Report on the Intranet and sharing Audit reports of vulnerable systems with CISAG, DAE and CERT-In for remediation & further actions.

How cybersecurity requirements in the nuclear facilities differ from the ones in other sectors?

 First of all, control and instrumentation (C&I) systems in nuclear facilities typically have much longer life cycle than commercial IT systems and the innovation cycles is also very different from those in conventional Information & Communication technology (ICT). Therefore, these facilities require technologies which can provide long-term support for Industrial Control Systems (ICS) networks, in an era where threat landscape is dynamically changing.

In nuclear facilities, generally operations team assume security just by ensuring obscurity of protocols, isolation of networks, and, may be, assuming disinterest in potential attackers because of isolated installations, which in turn creates false perception of security.

Inspectability, the capability to monitor a system’s internal state, is the backbone of traditional security tools. Most desktop security tools observe the behaviour, output, and code signature patterns of system processes. This is how virus scanners identify malware and how integrity checkers identify modifications to important system files. Similarly, network intrusion detection systems rely on the ability to inspect network traffic. Forensics and reverse-engineering tools too require the ability to inspect code and binaries both statically and dynamically, as they run on a system. Embedded systems and C&I systems like PLCs, RTUs etc used in nuclear facilities are much less inspectable than desktop computers due to lack of tools and suitable interfaces.

The surge of the Internet of Things (IoT) is forcing many businesses to reconsider their approaches to cyber risk management. How the emergence of IoT devices is changing the cybersecurity landscape?

With the advent of IoT, we are drifting into an era of ubiquitous surveillance where security, privacy and trust are going to be much bigger challenges. After the revelations of Edward Snowden, we can’t trust anything digital. The sensors of the digital world are fuelled with our PII (Personally identifiable information). Our purchasing patterns, browsing patterns, driving habits, eating habits, health indicators like heartbeat, blood pressure, places we visit etc., every data is being collected by Smart IoT devices and there’s a lack of transparency between data being collected and what it is being used for.

Ransomware will soon hit IoT market as well and because the sensors of IoT devices are the gates of our digital data, attackers will try to gain control of it. Emergence of IoT devices will also increase the attack surface of business enterprises because the attackers can exploit smart home/office devices for privilege escalation & indirect intrusion into corporate networks. There’s no silver bullet that can effectively mitigate the emergent IoT threats, as we can’t apply Security by Obscurity principles in IoT. We can’t say our IoT product will be secure because it uses proprietary protocols, indigenous hardware or air-gapped networks. So, we will need to think Security by Design. Also, Security cannot be an afterthought. It has to considered and implemented in all stages of IoT product lifecycle starting from planning, design, development, implementation, verification, validation, deployment to operations.

India’s NSE announces technology partnership with IIT Kanpur

National Stock Exchange India

The National Stock Exchange (NSE), the leading stock exchange of India, recently announced a partnership with Indian Institute of Technology Kanpur, a leading technology college in the country.

The partnership aims at developing cybersecurity solutions that can strengthen the security posture of NSE as well as companies in Indian financial and capital markets ecosystem. To develop cutting-edge solutions, NSE would leverage the capabilities of IIT Kanpur’s C3I center (Cyber Security and Cyber Defense of Critical Infrastructures) that is involved in research on cybersecurity and cyber defense of critical infrastructure.

“This is a great opportunity for NSE to collaborate with the academia to augment its position as a thought leader and leading adopter of cutting-edge technologies in the field of cyber security. NSE is proud to associate with IIT Kanpur in this endeavor and help in enhancing the cyber security posture of India’s capital markets. This partnership will significantly bolster our established cyber security practices and defense strategies. This collaboration will also contribute immensely to the capital market ecosystem and assist our members in adopting best in class industry practices,” said Vikram Limaye, MD & CEO at NSE.

Speaking on the new partnership initiative, Prof Abhay Karandikar, Director, IIT Kanpur said, “The C3I center at IIT Kanpur has developed cybersecurity products with cutting edge technologies and this is a great platform to adapt and launch it for the Indian capital markets. IIT Kanpur’s ongoing work in the Critical Infrastructure domain will enable it to make the capital market space much stronger to defend against cyber-attacks. NSE, being an institution of national importance and a part of the critical infrastructure of India, this engagement will ensure greater confidence for investors in the Indian capital markets.”