Home Blog Page 34

“We Lack in Human Preparedness”

Most security incidents are caused due to human weaknesses and the lack of preparedness and awareness.

In an exclusive video interview, Brian Pereira, Editor-in-Chief, CISO MAG, discusses human preparedness with Jawad Kazim, CISO at a leading MSSP in New Jersey.

Speaking about his experience as an external auditor, Kazim says organizations have excellent firewalls, antivirus, and other tools. But they lag in human preparedness. And this can be corrected through training and awareness.

He speaks about the preparedness of humans and the “human firewall.” He says governance is critical too, coming from the highest office in the organization.

Kazim also updates us on the state of cybersecurity in Pakistan, and the initiatives the government and universities have taken to spread awareness.

Kazim is an experienced Information Technology Audit Manager with a demonstrated history of working in the banking industry. He is skilled in Cyber Security, audit and humanity sciences. And his experience spans multiple continents. He is currently serving a leading MSSP in New Jersey. And previously, he worked as a Manager IT/IS audit (Information Security) for a leading bank in Pakistan.

CISO MAG Experts Series

CISO MAG interviews CISOs and cybersecurity experts from all parts of the world. Do read their opinions or watch their videos on cybersecurity awareness and incident response by following the links below.

“The State of Readiness Will Always Be in a Flux”

For Dr. Imtiaz Abdul Kader, CEO, Perfected Execution, there are two core elements to cybersecurity awareness and readiness. One is the training and the skills, and the other is partnerships within the industry.

“Security is Everybody’s Business”

Everyone in the organization is a security leader and is responsible for security, says Dr. Frank E. Ofori, Cyber Security Specialist and former U.S. Army Veteran.

Expert’s Take: Why Organizations Fail to Prepare for Cyberattacks

Le Nguyen Truong Giang, a Global Security Operations Lead and Security Transform Consultant, speaks to CISO MAG about cybersecurity awareness, resilience, and failure to prepare for cyberattacks.

“Being Compliant Gives Organizations a False Sense of Security”

Ditmar Tavares, Senior Cybersecurity Consultant, Mariner Innovations, explains where organizations fall short in their awareness about threats that target their business and employees.

Cybersecurity Awareness Month 2021: Here’s What the Experts Have to Say


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

More stories from Brian

U.K. Govt. Fines Clearview $22.6 Mn Over Privacy Violations

U.K. fines Clearview

From bringing up PSIT Bill to strengthen the IoT devices security to collaborating with other countries to boost cybersecurity, the U.K. government is in full action to thwart growing security incidents in the country. Recently, the Information Commissioner’s Office (ICO) in the U.K. imposed a potential fine of £17 million ($22.6m) on Clearview AI Inc for violating data protection laws. The agency also issued a provisional notice to Clearview stating to stop the processing of users’ personal data in the U.K. and to delete any data in its possession.

Clearview AI is a facial recognition platform that provides software to companies, law enforcement, universities, and individuals.

Background

The penalty comes after a joint investigation by the ICO and the Office of the Australian Information Commissioner (OAIC) that revealed Clearview had violated privacy laws by harvesting users’ sensitive information without their consent and unfair methods. The investigation found that Clearview leveraged users’ images, data scraped from the internet, and their biometric details for its facial recognition platform.

Customers of Clearview are provided an image to the company to carry out biometric searches, including facial recognition searches, on their behalf to identify relevant facial image results against a database of over 10 billion images.

Also Read: Australian Privacy Regulator Slams Clearview AI for Breaching Users’ Privacy

“The images in Clearview AI Inc’s database are likely to include the data of a substantial number of people from the U.K. and may have been gathered without people’s knowledge from publicly available information online, including social media platforms. The ICO also understands that the service provided by Clearview AI Inc was used on a free trial basis by a number of U.K. law enforcement agencies, but that this trial was discontinued and Clearview AI Inc’s services are no longer being offered in the U.K.,” the ICO said in a statement.

According to the ICO, Clearview has failed to comply with the U.K. data protection laws in several ways, including:

  • Failing to process the information of people in the U.K. in a way they are likely to expect or that is fair
  • Failing to have a process in place to stop the data from being retained indefinitely
  • Failing to have a lawful reason for collecting the information
  • Failing to meet the higher data protection standards required for biometric data (classed as ‘special category data’ under the GDPR and U.K. GDPR)
  • Failing to inform people in the U.K. about what is happening to their data
  • Asking for additional personal information, including photos, which may have acted as a disincentive to individuals who wish to object to their data being processed

Clearview Triggered Identity Threats: OAIC   

Earlier, Australia’s privacy watchdog, the Office of the Australian Information Commissioner (OAIC), stated that Clearview did not take any steps to stop collecting scraped images of Australians, generating image vectors from those images, and disclosing any Australians in matched images to its registered users. The agency stated the exposure of Clearview’s intrusive practices would certainly cause security concerns across various government officials.

Commenting on the proposed fine, the U.K. Information Commissioner, Elizabeth Denham, said, “I have significant concerns that personal data was processed in a way that nobody in the U.K. will have expected. It is, therefore, only right that the ICO alerts people to the scale of this potential breach and the proposed action we’re taking. U.K. data protection legislation does not stop the effective use of technology to fight crime but to enjoy public trust and confidence in their products, technology providers must ensure people’s legal protections are respected and complied with.

“Clearview AI Inc’s services are no longer being offered in the U.K. However, the evidence we’ve gathered and analyzed suggests Clearview AI Inc were and maybe continue to process significant volumes of U.K. people’s information without their knowledge. We, therefore, want to assure the U.K. public that we are considering these alleged breaches and taking them very seriously.”

Panasonic Concurs Breach Due to Third-Party Access to its File Server

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

Panasonic Corporation, a Japanese consumer electronics giant has concurred that a third-party accessed its file server on its network on November 11, 2021. A global press release states that through an internal investigation, it was established that some data on a file server had been accessed by a third-party during the intrusion. After detecting the unauthorized access, the company immediately reported the incident to the relevant authorities and implemented security countermeasures, including steps to prevent external access to the network.

“In addition to conducting its own investigation, Panasonic is currently working with a specialist third-party organization to investigate the leak and determine if the breach involved customers’ personal information and/or sensitive information related to social infrastructure,” the release states.

There has been a spate of incidents of premeditated attacks on huge consumer goods organizations. The IKEA reply-chain mail attack being the most recent incident. In all these incidents the level of breach and damage is yet to be ascertained and established. And a common pattern observed in these breaches is that the attacks have been active for a few months (with the attackers lying low and observing the system), but were discovered much later only through internal investigations as claimed by most company statements.

Could it be a control failure?

According to the Panaseer 2022 Security Leaders Peer Report, control failures are behind a growing number of security incidents at large organizations. The report reveals that an increase in tools and manual reporting combined with control failures are contributing to the success of threats such as ransomware, which costs organizations an average of $1.85 million in recovery.

The report states, “Currently, only 36% of security leaders feel very confident in their ability to prove controls were working as intended. This is despite 99% of respondents believing it’s valuable to know that all controls are fully deployed and operating within policy, and cybersecurity control failures are currently being listed as the top emerging risk in the latest Gartner, Inc. Emerging Risks Monitor Report. Attacks only succeed when they hit systems that haven’t been patched or don’t have security controls monitoring them.”

Frequent review of the security posture, installing updates and patches may be a small step in the right direction to secure your networks and systems to avoid the cyber sword dangling in the air.

 

Security Vulnerabilities Discovered in HP’s 150 Multi-function Printers

HP multi-function printers, Unpatched vulnerabilities

Adversaries exploiting unpatched vulnerabilities become a constant security concern for organizations. Cybersecurity researchers from F-Secure recently discovered multiple critical vulnerabilities in 150 multifunction printers (MFPs) manufactured by Hewlett Packard (HP).  The researchers stated the security flaws CVE-2021-39237 and CVE-2021-39238 could enable a remote attacker to take full control of the vulnerable devices, steal information, and further infiltrate networks to inflict other types of damage. The vulnerabilities, dating back to 2013, are now fixed after HP issued security patches.

Vulnerabilities in Detail

  • CVE-2021-39237 – This physical access port vulnerability affects certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers to potential information disclosure.
  • CVE-2021-39238 – This font parsing vulnerability affects certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed products to potential buffer overflow threats.

Cross-site Printing Attack

The security flaws could allow an attacker to launch a cross-site printing attack on the vulnerable printers’ network. The attacker would first need to trick a victim into visiting a malicious website. The cross-site printing attack involves tricking users from a targeted organization into visiting a malicious website, exposing the organization’s vulnerable MFPs. Once the victim visits the malicious site, the website automatically prints a document containing a maliciously-crafted font on the vulnerable MFP, giving the attacker code execution rights on the device.

Also Read: How Cross-Site Scripting Attacks Work and How to Prevent Them

“An attacker with these code execution rights could silently steal any information ran (or cached) through the MFP. This includes not only documents that are printed, scanned, or faxed but also information like passwords and login credentials that connect the device to the rest of the network. Attackers could also use compromised MFPs as a beachhead to penetrate further into an organization’s network to pursue other objectives (such as stealing or changing other data, spreading ransomware, etc.),“ the researchers said.

With HP being one of the leading providers of MFPs, many organizations worldwide are likely using vulnerable devices.

Mitigation

While there is no information on exploited vulnerabilities, F-Secure urged organizations to fix their vulnerable MFPs. In addition to patching, the company provided certain measures to secure MFPs against unauthorized intrusions. These include:

  • Limiting physical access to MFPs
  • Segregating MFPs in a separate, firewalled VLAN
  • Using anti-tamper stickers to signal physical tampering with devices
  • Using locks to control access to the internal hardware
  • Following vendors’ best practices for preventing unauthorized modifications to security settings
  • Placing MFPs in CCTV-monitored areas to record any physical usage of a hacked device when it was compromised

“It’s easy to forget that modern MFPs are fully-functional computers that threat actors can compromise just like other workstations and endpoints. And just like other endpoints, attackers can leverage a compromised device to damage an organization’s infrastructure and operations. Experienced threat actors see unsecured devices as opportunities, so organizations that don’t prioritize securing their MFPs like other endpoints leave themselves exposed to attacks like the ones documented in our research,” said F-Secure security consultant Timo Hirvonen.

Timo HirvonenExplaining on how organizations can mitigate the risks from rising vulnerability exploits, Hirvonen explained, “Organizations need to first get a handle on all their endpoints. Often, we see companies forget or overlook certain devices and endpoints, neglecting to update or even carry out basic cyber hygiene practices – which in the end leads to vulnerabilities as we have seen here.

In this case, in addition to patching, organizations can mitigate the risks by carrying out relatively simple techniques such as limiting physical access to MFPs, segregating MFPs in a separate firewalled VLAN, and following the security hardening guidelines of the vendor. These simple actions will make a huge difference to the overall security posture of the company.”

“PtaaS Offers a Faster and More Thorough Process of Vulnerability Discovery”

Eric Brinkman, Chief Product Officer at Cobalt

Not too long ago, in August 2021, Conti operators successfully targeted SAC Wireless, a U.S.-based Nokia Subsidiary, with a ransomware attack. After an internal investigation, SAC found a laundry list of vulnerabilities in their security system that the Conti hackers could take advantage of. These were vulnerabilities that could have been proactively identified and addressed before the data breach ever occurred.  

Enter Pen testing-as-a-Service (PtaaS). Through PtaaS, it is possible to pinpoint vulnerabilities – like the ones exploited in the Nokia attack – and stop cybercriminals before they even have a chance to exploit them.

In a virtual interaction, Minu Sirsalewala, Editorial Consultant, CISO MAG, and Eric Brinkman, Chief Product Officer at Cobalt, discussed how identifying security vulnerabilities early is more important than ever. Brinkman also opined how PtaaS providers have become a critical component across all security programs.

As the Chief Product Officer at Cobalt, a PtaaS company, Brinkman leads product vision, enhancing the existing suite of offerings and identifying innovative ways to meet and exceed the needs of current and future customers.

Brinkman is a seasoned technology industry veteran with 15 years of experience driving and sustaining long-term product growth. Previously, as Senior Director of Product at GitLab, he founded the company’s first growth team, which evolved into a critical component of the company’s business approach. He built and managed product teams that innovated on widely successful GitLab product features and functionalities and developed new product areas such as Compliance Management, Design Management, Requirements Management, and Quality Management. Notably, Brinkman led the product team that secured GitLab’s placement on the 2020 Gartner Magic Quadrant for Enterprise Agile Planning Tools.

Excerpts from the interview follow:

What is the importance of preventive security measures? Can you explain why they have gained so much importance in the past year?

SolarWinds. Colonial Pipeline. Kaseya. Robinhood. Cyberattacks have been growing in frequency and intensity over the past decade, and they have only increased since the onset of widespread digital work. Now more than ever, organizations everywhere feel the pressure to implement comprehensive security strategies fast to avoid becoming the latest cyberattack headline.

The shift to, and complexities of remote work, have underscored the importance of proactive, preventative security measures. Organizations must know and secure their assets — only then can they find and fix vulnerabilities before an attacker breaches their systems.

According to a Cobalt survey of 600 IT security professionals, pen testing provides businesses greater protection against malicious attacks. In fact, 78% say that the more pen testing they perform, the more their organization’s attack surface decreases.

How is PtaaS changing the way DevOps manages security?

Security and software development professionals almost universally see pen testing as a vital component of the application and network security programs. However, few organizations can perform as much pen testing as they want or need due to budget limitations and inefficiencies in the traditional pen testing process.

The most common approach to pen testing today is engaging a third-party consulting firm with an IT practice to provide a pen testing team for a specific test project. These engagements provide valuable input, but security teams find them to be slow and expensive. Pen test-as-a-Service (PtaaS) has emerged as an innovative approach to cybersecurity threat detection and remediation.

PtaaS takes these benefits to the next level, allowing organizations of all sizes to manage a scalable, efficient pen test program with on-demand access to expert security talent and a modern SaaS delivery platform. PtaaS enables DevSecOps teams to secure their code faster, integrating security and development tools and real-time collaboration with pen testers.

How well is PtaaS integrated into the system as a best practice?

Organizations must stop viewing pen testing as a manual add-on to their security processes and instead integrate PtaaS into their technology stacks from Day 1, using it as a core component of their security systems. No one tool or tactic alone can provide the defenses organizations need to fend off cybercriminals; it takes a layered approach to create an effective security program.

PtaaS changes how pen tests can be integrated into the SDLC by allowing for programmatic access of vulnerabilities discovered during the pen test via native integrations or APIs to be placed in context with the teams tasked with fixing those vulnerabilities.

With businesses becoming more agile, how has traditional pen testing evolved to integrate with the complex technical environment?

In June 2021, Cobalt launched its public API that allows customers to easily integrate their pen test data into other tools within their technology stack, such as GitHub, Jira, and Slack, enabling streamlined workflows and a dynamic analysis of their security programs. This addition was a critical step in Cobalt’s mission to advance traditional pen testing by enabling teams to manage their data more easily and build a holistic view of their vulnerability and application landscape. This is just one example of how Cobalt is modernizing traditional pen testing.

What key factors are driving PtaaS adoption?

With a new cyberattack making headlines almost every day, organizations have never been more aware of the critical need for a comprehensive security strategy. No one is immune to cyberattacks; that is why proactive, preventative testing is critical for enhancing an organization’s security posture.

Business and security leaders are turning to PtaaS in droves because it offers a more efficient and cost-effective pen test process. They can closely monitor testing progress, as well as catch and remediate vulnerabilities quicker than ever before.

Also, depending on the industry that a company operates in, there can be varying degrees of mandates that require pen testing. PtaaS allows companies of all sizes to effectively meet these requirements.

What are the benefits of PtaaS?

PtaaS delivers all the benefits of manual pen testing in a unified platform with the added benefits of integrations and automation. As security threats continue to get increasingly more sophisticated, PtaaS offers a faster and more thorough process for security testing and vulnerability discovery.

Cobalt’s new “ROI of Modern Pentesting” report found that traditional threat detection, via a consulting firm, is no longer cutting it. Using old-school pen testing, most organizations (83%) test critical assets only annually, leaving notable gaps in their security posture for attackers to exploit. This could leave organizations vulnerable to attacks. PtaaS allows for more flexibility and lower costs, meaning organizations can test their assets more frequently, decreasing the risk of vulnerabilities going undetected.

Is there an overlap of the PtaaS model with the SaaS model?

Great question! Just as the name suggests, PtaaS is a modern approach to pen testing, implemented via the SaaS model. PtaaS allows for on-demand test scheduling, seamless integrations, and automated workflows. Its benefits also include direct pen tester collaboration and communication capabilities and more robust reporting.

Typically, what challenges do organizations face while adopting the PtaaS model?

I think one of the biggest challenges right now is awareness. Many organizations have yet to learn about PtaaS, so that education piece is crucial. Over the years, we have seen many companies do proof of concept contracts and then later expand and renew for multi-year contracts once they have experienced the benefits of PtaaS firsthand.

Could you share incidents where pen testing could have proactively identified and addressed vulnerabilities before a data breach ever occurred?

Finding vulnerabilities is important but fixing them is often where organizations with an immature DevSecOps culture fall short. Automated scanners typically throw off tons of alerts, but it can be overwhelming for a development team to know where to start, even if they were really motivated to fix them. Pen testing helps provide human judgment and can assist with prioritization. PtaaS is designed to integrate into the development process.

Checking your cybersecurity defenses regularly is imperative because it will give you the opportunity to pinpoint and prioritize vulnerabilities — like the ones we often hear about in the news — and the chance to stop cybercriminals before they even have a chance to exploit them.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

Over 300,000 Users Affected by 4 Android Banking Trojans

Android, Trojan, Android Banking Trojans

Security researchers from Threatfabric uncovered four different Android banking Trojans distributed via the Google Play Store between August and November 2021. The Trojans reportedly made over 300,000 infections via different kinds of dropper apps disguised as legitimate smartphone applications.

The Four Android Banking Trojans include: 

  1. Anatsa (also known as TeaBot)
  2. Alien
  3. ERMAC
  4. Hydra

Threatfabric analysts identified different droppers located in Google Play, designed to distribute specifically the banking Trojan Anatsa, which has advanced RAT and semi-ATS capabilities. Anatsa Trojan can perform classic overlay attacks to steal credentials, accessibility logging, and keylogging. The researchers also found multiple malware strains dropped by the Brunhilda threat actor group, derived from Hydra and ERMAC.

The List of Malicious Dropper Apps include:

  • Two Factor Authenticator (com.flowdivison)
  • Protection Guard (com.protectionguard.app)
  • QR CreatorScanner (com.ready.qrscanner.mix)
  • Master Scanner Live (com.multifuction.combine.qr)
  • QR Scanner 2021 (com.qr.code.generate)
  • QR Scanner (com.qr.barqr.scangen)
  • PDF Document Scanner – Scan to PDF (com.xaviermuches.docscannerpro2)
  • PDF Document Scanner Free (com.doscanner.mobile)
  • CryptoTracker (cryptolistapp.app.com.cryptotracker)
  • Gym and Fitness Trainer (com.gym.trainer.jeux)

These dropper apps have small malicious footprints that make them difficult to detect from traditional security scans and detections. “To make themselves even more difficult to detect, the actors behind these dropper apps only manually activate the installation of the banking trojan on an infected device in case they desire more victims in a specific region of the world. This makes automated detection a much harder strategy to adopt by any organization,” the researchers said.

Rise of Android Trojans

In a similar discovery, security researchers from Doctor Web uncovered a new Trojan that has infected over 9.3 million Android devices. The Trojan, dubbed “Android.Cynos.7.origin,” is a new kind of malware that disguises itself as various mobile games on Huawei’s AppGallery marketplace. Android.Cynos.7.origin steals information from a victim’s device, such as contact details, and displays unwanted ads. The researchers suspect that the Trojan is a modified version of the Cynos malware. Read More Here

IKEA Becomes Victim to Email Reply-Chain Attack

“PerSwaysion” Phishing Campaign Targets High-Ranked Professionals Across The Globe, IKEA email reply-chain attack

CISO Mag has been writing about increasing cyberattacks given the onset of the festive season and how to be vigilant and safeguard against these threat actors.

Reports on breaches and attacks continue to trickle in with renewed cyberattack techniques. The latest is the email reply-chain attack that was used to launch a phishing campaign.

IKEA a global furniture retailer has 422 stores operating in 50 countries. The furniture giant was targeted by a phishing technique called email storm by hackers to steal data.

How does a reply-chain attack work?

A SentinelOne blog explains hijacking an email reply-chain begins with an email account takeover. Hackers take over control of one or more email accounts through password spraying, or an exposed vulnerability, and monitor email threads for an opening to push the malware or malicious link in an ongoing correspondence. The mail exchanges being between known sources and participants, the malicious correspondence is rarely doubted and the malware goes undetected.

“The technique is particularly effective because a bond of trust has already been established between the recipients. The threat actor neither inserts themselves as a new correspondent nor attempts to spoof someone else’s email address. Rather, the attacker sends their malicious email from the genuine account of one of the participants,” blogs SentinelOne.

The blog explains, as the threat actor has complete access to the mail conversation, it customizes the attack to sit well with the content of the mail exchange and gives no reason for the recipient to doubt the origin. As the source is trusted, the victim is most likely to click the malicious email. Thereby successfully launching the phishing campaign.

The IKEA Case

The email storm or mail reply-chain was effectively used on IKEA employees. The malicious mails were part of previously exchanged mails and were more likely to be viewed and clicked for further correspondence. The company claims that no customer data was captured.  Not much has been shared on the security breach and further information is awaited.

Praveen Patil Kulkarni, Country Manager – Security Risk & Governance, Micro Focus opined, As companies innovate with digital acceleration, the threat landscape is also evolving Praveen Patil Kulkarni, Country Manager - Security Risk & Governance at Micro Focussimultaneously. Attackers are discovering new ways of data theft to use as bait to trick their victims, reply-chain email attack being one such effort. Over 400,000 new types of malwares are created every day, making it complicated for organizations to defend themselves with traditional anti-virus solutions.”

“Despite the billions of dollars spent each year on security solutions, threats still find their way into most organizations. In this scenario, CISOs must ensure layering their security solutions with threat intelligence, including conducting effective training for employees to detect phishing attempts, creation of comprehensive corporate policies to address acceptable user behavior, and deployment of enterprise-grade alternatives to the less secure consumer-focused tools. The capabilities of niche technologies like AI and analytics must be taken advantage of to strengthen the cyber resiliency quotient of the organization and ensure the adoption of a proactive approach to data protection.”

The Weak-Link

Constant security reminders, employee awareness programs and cybersecurity best practices are few initiatives that organizations are running to mitigate risks and prevent security incidents. But the weakest link – the human factor – continues to be a vulnerable source that can bring the entire system down. Employees or people are the softest, most lucrative target for all kinds of attack and most targeted. Industry experts have been emphasizing the importance of addressing the human factor and how the trend is disconcerting as it results in increased security lapses and breaches.

James Forbes-May, Vice President, Asia-Pacific, Barracuda James Forbes-May, Vice President, APAC, Barracuda Networks2asserted, “In the past year alone, we’ve witnessed a number of worrying trends threatening businesses in the region, including a huge 64% uptick in the number of ransomware attacks; with 81% of organizations in APAC, Europe, the Middle East, and Africa (EMEA), and the United States (U.S.) reporting having suffered at least one security breach in the last 12 months. Our research also shows that the average organization is targeted by over 700 social engineering attacks each year – and it’s not just CEOs or personnel in financial roles who are being targeted. In fact, 77% of Business Email Compromise (BEC) attacks are targeting lower-level staff across a variety of roles, and why? Because cybercriminals know that even with the strongest security strategy and safeguards in place, the weakest link is usually the human link.”

How to Prevent Credential Abuse Attacks?

Credential Abuse Attack, credential harvesting campaign

Strong login credentials are treated as the first defense against unauthorized intrusions. However, they also become a gateway for cybercriminals to penetrate critical network systems. Threat actors mostly obtain sensitive login information like usernames, passwords, or passcodes via data breaches and underground dark web forums. They often abuse stolen credentials to launch various cybercriminal activities, such as compromising a network or deploying ransomware.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is a Credential Abuse Attack? 

In credential abuse attacks, scammers leverage illicitly obtained credentials to break into user accounts by adding a list of compromised usernames and passwords to botnets. These botnets are designed to initiate the authentication process on targeted victim accounts. Once attackers get hold of a system or employee account, they move freely across the organization’s network by bypassing all security scans. Attackers further try to steal classified corporate data or exploit other accounts by leveraging one compromised account. They could also launch various attacks, including identity theft, phishing, impersonation scams, and other data abuse acts.

How Credential Abuse Attack Works 

credential abuse attack

Credential abuse attacks are easy to execute and have a higher success rate because most users reuse passwords for multiple accounts.

Also Read: What is an SQL Injection Attack and How to Prevent it?

How to Prevent Credential Abuse

Having strong credentials will not prevent data breaches and hacker intrusions. Continuous security measures can help prevent unauthorized users from accessing corporate accounts. Here are some actionable steps to protect online accounts against credential abuse attacks:

1. Multiple Authentication Process

Enable two-factor authentication (2FA) or multi-factor authentication (MFA) processes to avoid unauthorized intrusions. Organizations can also implement passwordless authentication processes like biometrics or behavioral patterns to verify the user’s authenticity.

2. Enable Secondary Password Procedure

Along with password, organizations can prompt users to provide additional security inputs like PIN, Passcodes, or a security question.

3. Enable CAPTCHA

Ask users to solve a CAPTCHA for each login trail to help prevent unauthorized or automated login attempts.

4. Identifying Leaked Passwords

Reusing passwords is one of the primary reasons for credential abuse attacks. Check whether your credentials or other personal data have been leaked in any data breach on the haveibeenpwned website. Avoid reusing leaked/breached credentials and update them regularly.

5. Responsible Disclosure

Notify users and employees about data leaks or unusual security events as they happen.

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

These are the Most Common Passwords of 2021

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

We cannot ignore the significance of strong passwords while talking about cybersecurity. Most internet users still use easy-to-guess credentials or reuse passwords, making a hacker’s jobs easy. Adversaries often steal credentials or crack passwords to break into users’ online accounts. Poor password management could result in serious data security issues for both users and organizations.

An analysis from NordPass revealed the most common passwords that people used for a long time. The company listed out the top 200 most common passwords in 2021 among 50 countries and detailed how many times a certain password was used and how long it would take a hacker to crack it.

According to NordPass, the top 10 most used passwords worldwide which could be cracked in less than a minute were:

  1. 123456– used 103,170,552 times
  2. 123456789– used 46,027,530 times
  3. 12345– used 32,955,431 times
  4. qwerty– used 22,317,280 times
  5. password– used 20,958,297 times
  6. 12345678 – used 14,745,771 times
  7. 111111 – used 13,354,149 times
  8. 123123 – used 10,244,398 times
  9. 1234567890 – used 9,646,621 times
  10. 1234567 – used 9,396,813 times

Most Affected Countries

Weak passwords will certainly increase the number of data breaches. According to NordPass, the most severely affected countries by data leaks include the U.S., Canada, France, Russia, Germany, Poland, and Australia. While averagely affected countries include Chile, Sweden, Norway, Spain, Finland, Ukraine, Japan, Philippines, and New Zealand. The countries with low data breach impacts were Mexico, Colombia, Brazil, Nigeria, South Africa, Saudi Arabia, Turkey, India, Indonesia, and China.

Also Read: 6 Practices to Strengthen Your Password Hygiene

Other Findings

  • Most people love using their own name as a password.
  • The dolphin ranked number one among animal-related passwords in many countries.
  • Liverpool might be the most popular team globally, judging by how many times it has been used as a password.
  • Ferrari and Porsche are the most popular car brands when it comes to bad passwords.
  • Swear words are quite often used as passwords. Reportedly, men use swear words as passwords more often than their female counterparts.
  • In the U.S., more women (222,287) used “iloveyou” as a password than men (96,785).

Mitigating the Risks via Password Hygiene

We cannot predict data breaches and cyberattacks, but we can strengthen our data security by following certain password hygiene measures. These include:

  • Using two-factor or multi-factor authentication
  • Using passphrases instead of passwords
  • Avoiding the reuse o0066 passwords for business and personal accounts
  • Regularly updating passwords

Having a strong password is important for effective data and online security. With the rising concerns over data breaches and hacker intrusions, users must be vigilant and practice necessary password protection measures to avoid cyberthreats.

Israel Cuts Off 65 Countries from Cyber Export List Citing Misuse of Hacking Tools

Israel restricts export of cybersecurity tools

Apple has sued Israel-based NSO Group for state-sponsored surveillance, and now Israel has limited the number of countries that can buy the hacking and surveillance tools from the region.

According to reports, Israel has come down stringently on the local companies that are authorized to sell cybersecurity tools and pruned the list from 102 to 37 countries.

With the NSO group legal row becoming muddier, the Israel Ministry of Defense has clipped 65 countries from the current cyber export list where sales of hacking and surveillance tools were allowed. Western European countries, Canada, and the U.S. form a part of the updated restricted regions list.

“The new list will significantly complicate matters for Israeli cybersecurity companies, especially those selling offensive cyber tools, to operate in countries with totalitarian regimes or with a record of violating human rights. The Israeli cybersecurity sector currently generates $10 billion in annual revenue, with offensive cyber believed to be responsible for 10% of those sales. Some 13% of all cybersecurity companies operate from Israel, with 29% of all investments in the sector being directed to Israeli companies,” reports suggest.

In October 2021, the Commerce Department’s Bureau of Industry and Security (BIS) in the U.S. had announced new policies to control the export of cybersecurity items to regions with despotic practices. Russia and China are the more popular names that are associated with such authoritarian practices.

These cybersecurity tools warrant control because these tools could be used for surveillance, espionage, or other actions that disrupt, deny, or degrade the network or devices on it.

Atlantic Council, an American research group on international affairs, in its report on proliferation of surveillance technology, expressed, “While offensive cyber capabilities are helpful for law enforcement and border protection, the dual-use nature of many of these capabilities provides opportunity for malicious employment as well, especially when the capabilities are sold to authoritarian actors. Israeli NSO Group/Q Cyber has achieved much unwanted notoriety for its Pegasus spyware, which provides authoritarian governments around the world the capability to spy on journalists, political opposition, and activists. Beyond human-rights violations, cyber capabilities sold to even regional partners of the United States and NATO may be used against the United States and NATO in the future.”

Surveillance and espionage for national security have donned a new mask and taken the form of malicious intrusion. With countries banning the use of security tools and limiting cross regional exchange of cyber surveillance services due to abuse, we can expect that despotic or totalitarian regimes will be discouraged and not be allowed to resort to cyber espionage for their personal gains.