Home Blog Page 341

US Ballistic Missile Systems have poor cybersecurity practices: Report

Ballistic

An inspection of Ballistic Missile Defence Systems (BMDS) in the United States by the Department of Defense Inspector General (DOD IG) found serious unpatched vulnerabilities.

According to the report “Security Controls at DoD Facilities for Protecting Ballistic Missile Defense System Technical Information” published by the DoD revealed that the officials didn’t implement cybersecurity controls and processes to protect the BMDS technical information. The security audit stated the officials at BMDS are not following basic security practices like data encryption, antivirus programs, and multifactor authentication mechanisms at the BMDS facilities.

“We conducted this audit in response to a congressional requirement to audit the controls in place to protect BMDS technical information, whether managed by cleared Defense contractors, or by the Government. Cleared contractors are entities granted clearance by the DoD to access, obtain, or store classified information, to bid on contracts, or conduct activities in support of DoD programs,” the report stated.

The DOD suggested recommendations to data center managers at BMDS facilities to correct the identified systemic weaknesses found in the security audit report. “We recommend the development and implementation of a plan to correct the systemic weaknesses identified in this report at facilities that manage BMDS technical information,” the report added.

The recommendations suggested by DOD include mitigating the vulnerabilities constantly, implementing intrusion detection capabilities, and enforcing multi-factor authentication to access systems that process, store, and transmit the BMDS technical information.

The U.S. Government Accountability Office (GAO) recently conducted a study to evaluate the state of Department of Defense (DOD) weapon systems cybersecurity. The legislative branch government agency stated that most of the new weapons designed by DOD are vulnerable to cyber-attacks. GAO pointed out that DOD does not even know the full extent of the problems that existed in their weapons. In the report, GOA stated that it and others have warned DOD of cyber risks for decades, until recently, DOD did not prioritize weapon systems cybersecurity.

 

Avanan grabs $25 million to accelerate its cloud business

Startup funding

Enterprise security provider Avanan recently announced that it has raised $25 million in a Series B funding round led by the existing investors StageOne Ventures, Magma Venture Partners, and Greenfield Partners. The Israel-based company stated that it will use the new investment to accelerate the growth of its product platform.

Founded in 2014 by Gil Friedrich, Avanan provides security solutions for SaaS based email and collaboration platforms. The company claims that its technology allows companies to operate their data security systems on cloud applications and helps them secure the Office 365 suite, Google’s G Suite, Box, ShareFile, Slack, and other collaboration SaaS applications from phishing attacks, malicious content, and data leakage. Avanan’s multi-vendor platform allows its clients to choose security technologies from the leading vendors in the security industry.

“Companies that use SaaS-based email and collaboration platforms quickly realize that hackers find ways to bypass their security. Before Avanan, the options for additional security were limited to legacy email security vendors that tried to adapt their proxy solution to the cloud,” says Avanan CEO Gil Friedrich. “Avanan takes a completely different approach to how we secure our customer’s environments. By connecting directly to the cloud, we not only deploy faster, but we detect and block all the threats that proxies are unable to see due to their position outside the cloud. The difference to our customers is night and day.”

Speaking on the new investment move, Yuda Doron, Managing Partner at Greenfield Partners, a TPG Growth investment platform, said, “We invested in Avanan because we believe the unified multi-vendor security platform is a revolutionary solution in a market that has so many point solutions. We are in the midst of the mass adoption of SaaS based email and collaboration; every company will need to adopt a solution like Avanan, just like they needed to install antivirus on their Windows PCs.”

Raytheon and Saudi Aramco to form joint venture

The US-based defense firm Raytheon recently announced that it’s going to form a joint venture with Saudi Arabian Oil Company Saudi Aramco to develop cybersecurity services in the Saudi region.

According to the Memorandum of Understanding, the Saudi Aramco and Raytheon Saudi Arabia, a subsidiary of Raytheon Company, will develop and provide advanced cybersecurity software and hardware. They will also carry out research and development activities in the Saudi Arabia region. Saudi Aramco stated the latest venture will strengthen the cybersecurity capability of the company as well as its suppliers, customers, and affiliates. According to Raytheon, the agreement would continue to fuel its global growth in the areas of defense systems and platforms.

“We are excited about the joint venture which will support the Kingdom’s Vision 2030 by creating highly skilled jobs for Saudis in the cybersecurity sector and will support the foundation for Saudi Arabia’s economic development,” said Saudi Aramco Senior Vice President of Finance, Strategy & Development Khalid H. Al-Dabbagh. “Demand for cybersecurity services is expected to grow as companies move further into the digital space and embrace technologies such as the Internet of Things and big data. The partnership with Raytheon will help strengthen cybersecurity and enhance its infrastructure in Saudi Arabia and the broader region.”

“Cybersecurity is critical to national and global security,” said Dave Wajsgras, President of Raytheon Intelligence, Information, and Services. “This MOU is an important step in creating a joint venture that we see becoming the cornerstone of cybersecurity defenses in the region.”

5 Key Failures by Equifax: Congress Releases Report on the Mega-Breach

Equifax lawsuit

Contributed by SecureWorld

Congress has issued the most detailed report yet on the Equifax data breach, and it is full of lessons for IT security teams.

The report is 96 pages long, and here are the top highlights.

5 key Equifax failures, according to Congress

  • Overall failure at cybersecurity: “Entirely preventable. Equifax failed to fully appreciate and mitigate its cybersecurity risks. Had the company taken action to address its observable security issues, the data breach could have been prevented.”
  • IT management failure: “Lack of accountability and management structure. Equifax failed to implement clear lines of authority within their internal IT management structure, leading to an execution gap between IT policy development and operation. Ultimately, the gap restricted the company’s ability to implement security initiatives in a comprehensive and timely manner.”
  • Big data and legacy systems failure: “Complex and outdated IT systems. Equifax’s aggressive growth strategy and accumulation of data resulted in a complex IT environment. Both the complexity and antiquated nature of Equifax’s custom-built legacy systems made IT security especially challenging.”
  • Failure to maintain visibility across networks: “Equifax allowed over 300 security certificates to expire, including 79 certificates for monitoring business-critical domains. Failure to renew an expired digital certificate for 19 months left Equifax without visibility on the exfiltration of data during the time of the cyberattack.”
  • Failure at internal and external incident response: “A list of Equifax database owners did not exist. Therefore, Mandiant had to identify and verify database ownership before it was able to begin its analysis… After Equifax informed the public of the data breach, they were unprepared to identify, alert and support affected consumers. The breach website and call centers were immediately overwhelmed.”

Here is the complete report: https://oversight.house.gov/wp-content/uploads/2018/12/Equifax-Report.pdf

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Bitcoin: Part currency, Part revolution

Bitcoin

When the man known to the world as Satoshi Nakamoto not just unveiled a new currency but a new way to think about currency, our world was changed forever. What Bitcoin did to the world of cryptocurrency, or rather, to the world of economics is unparalleled. Bitcoin brought cryptocurrency limelight, and with it, a host of challenges. Bitcoin wasn’t the first cryptocurrency.

The history of cryptocurrency traces its roots back to the early eighties when cryptographer David Chaum had the idea of an anonymous cryptographic electronic money called ecash. According to him, electronic payment systems have a substantial impact on personal privacy as well as the nature and extent of the criminal use of payments. “Ideally a new payments system should address both of these seemingly conflicting sets of concerns. On one hand, knowledge by a third party of the payee, amount, and time of payment for every transaction made by an individual can reveal a great deal about the individual’s whereabouts, associations and lifestyle,” he wrote in his proposal for ecash.

Ecash would have properties like “the inability of third parties to determine payee, time or amount of payments made by an individual; ability of individuals to provide proof of payment, or to determine the identity of the payee under exceptional circumstances; and ability to stop use of payments media reported stolen.”

By 1989, he started DigiCash Inc, with ecash as its trademark. Thus ecash became the first ever cryptographic electronic currency and it was as secure and private as cash in the physical world. In 1997, Nicholas Negroponte, celebrated guru and Greek American architect, signaled his support to the currency by backing the venture and becoming Chaum’s first ever client. But DigiCash had a short lifespan and by 1999, Chaum sold his patents. “It was hard to get enough merchants to accept it so that you could get enough consumers to use it, or vice versa,” he said in an early interview with Forbes.

Read More

“Big data analytics as a cyber discipline is in its infancy”

Nik Whitfield
Nik Whitfield is the founder and CEO at Panaseer, the creator of a platform that automates the breadth and depth of visibility required to take control of cybersecurity risk, demonstrate ROI and drive robust cyber hygiene practices. A 20-year veteran in the industry, Nik has held leadership positions in various organizations has been recognized by the UK government and industry bodies.
In an interview with Rudra Srinivas, Nik talks about his vision behind Panaseer, importance of big data analytics, and much more.

What was your idea behind establishing Panaseer? How has been the journey so far?

Cybersecurity has become a big priority for enterprises, and rightly so given the challenges we face protecting our people and information. But what struck me, and the reason I founded the company, was that the people responsible for securing our data in the enterprise – the CISOs – didn’t have answers to the most fundamental questions of cybersecurity – What assets are we defending? How well controlled are they? How are they most vulnerable? As a result they were suffering a lack of confidence and control over cybersecurity risk, and this was starting to be recognised by the Boards of these  companies.

CISOs don’t have the luxury of relying on gut instincts anymore, it’s just not acceptable or feasible given the scrutiny they’re under. Like other functions in any enterprise, they need trusted data to drive their decisions and to justify their decisions.

The problem was how they could approach this, because it’s a complex and problem to solve, very manual and time consuming, and requires the analysis of many different systems.

I knew that, together with my co-founders, we had the know-how to develop a platform that could finally help organisations establish the ground of a company’s security posture – using real data which could be trusted and automated to give them live insight. We met with security chiefs of some of the world’s biggest financial organisations during the inception of Panaseer to make sure that we were addressing exactly what it was they were finding hard to achieve.

The journey so far has been incredibly exciting and dauting in equal measure. We are going head to head with the Silicon Valley tech giants – it’s David and Goliath. And just like the parable we have the innovation edge and focus, and our platinum brand clients are proof that this is what the market is looking for.  This has created real investor confidence, which led us through a successful Series A funding round earlier this year, with Cisco joining our mission.

It is widely believed that Big Data Analytics plays an important role in preventing cyber-threats.  How true is that assumption?

Big data analytics as a cyber discipline is certainly still in its infancy. To date it has been confined to the ‘threat detection’ space. It’s easy to understand how identification of bad things happening is appealing, but this misses the bigger, and more effective opportunity of prevention in the first place.

There are many opportunities for CISOs to use data to be more proactive in preventing threats from taking hold. For example, using data to raise the general cyber hygiene of an organisation is an underserved use case. An automated metrics and measurement programme can tell you a lot about how well your control infrastructure is deployed, configured and managed. Many organisations currently use point in time assessments, conducted manually or via questionnaires to assess their control status. No modern organisation can genuinely believe this is a sufficient frequency or fidelity of measurement to feel confident that a control infrastructure is operating as expected or needed (particularly considering regulatory reporting needs). This is exactly the space that Panaseer is leading.

Are machine learning and automation the future of cybersecurity?

Robust, data driven automation is absolutely the future and many forward-thinking CISOs are embracing it today. The main opportunity is the automation of risk decisions (decisions can be made at the speed of data and IT processes not spreadsheets and manual analysis) meaning higher return on investment from time-limited cybersecurity professionals.

I would put machine learning in the AI camp. It certainly has exciting potential, but the jury is still out on how much. The fact is that the market has seen a glut of security data analytics products that use maths to quickly identify the bad guys that are “inevitably” in your network and increase Security Operations Centre efficiency all through the use of Machine Learning or Artificial Intelligence (AI). It’s a problem that is ripe for data analysis innovation, but the realities are more challenging than advertised. The major factor here is that 90% of the effort required to make ML effective is in the sourcing, cleaning and organisation of the underlying raw data. This is why our product focusses on these aspects rather than the algorithms at this stage.

AI is largely marketing hype applied to a small subset of machine learning techniques so don’t be fooled by how a product is branded. At best, the algorithms embedded in products perform highly specialised analysis in a single field and have been trained on large volumes of data. This is a far cry from general AI, which is a system that can perform any generalised task and answer questions across multiple domains – we are a long way near that.

How has GDPR changed the landscape of the businesses in Europe? Was transition post GDPR easy?

GDPR needs to be looked at in two parts. The first phase was the market panic of the last two years by organisations that worried about becoming complaint – there was a huge wave in activity in going through the various processes to achieve compliance before the deadline.

We are now in the second stage, post GDPR, where organisations are sitting in wait to see how it will be implemented – how harsh the penalties will be for non-compliance and whether they need to reinforce defences to avoid the likelihood of being breached.

Unfortunately, when it comes to data breaches, it’s not a case of if but when, so the overriding priority for the CISO must be ensuring they are diligent, not negligent in protecting the organisation. For years industry doctrine has advised a layered approach to security – think of the many layers of onion skin protecting the core. However, many companies end up focusing their efforts on the outside layer of defence, meaning their security network is more like an egg – hard on the outside and soft and mushy on the inside.

As a young company, what is your organization doing with regards to cybersecurity awareness among employees?

We have a really open culture, so awareness is discussed every day. There are some simple things we do – fostering a culture of openness so we can discuss it and having it as an agenda point in all hands and leadership team meetings. We also ensure all new recruits are trained on a simple set of standards, such the Cyber Essentials. We also have a Slack channel dedicated to reporting suspicious activity, such as the many phishing emails we receive.

Where do you think cybersecurity as an industry is going in 2019?

It’s going to need to go back to basics and refocus on doing the fundamentals well, as that’s ultimately what delivers ROI. As no company can be 100% secure, there must be clarity on acceptable levels of risk and investment in the fundamentals of cybersecurity. Knowing, on any day, what assets you’re protecting, how they’re controlled, and how they’re vulnerable – in a robust, automated, data driven way – will crucially help protect against the vast majority of attacks.

Facebook reports another data breach

Facebook copyright complaint

Facebook recently reported that it has suffered a data breach that exposed 6.8 million users’ private photos to third-party application developers. The social networking giant announced that its internal team discovered a photo API bug that allowed third-party apps to access users’ photos for 12 days between September 13 to September 25, 2018. The company declared that it has fixed the issue, but some third-party apps may have had access to a wider set of photographs which were uploaded/shared on the Facebook Stories.

“Currently, we believe this may have affected up to 6.8 million users and up to 1,500 apps built by 876 developers. The only apps affected by this bug were ones that Facebook approved to access the photos API and that individuals had authorized to access their photos,” Facebook said in a post.

Apologizing to the users, Facebook said that it’s introducing advanced tools to identify the applications affected by the bug. It also stated that it’s notifying the users who’re impacted by the bug via an alert on Facebook.

“We’re sorry this happened. Early next week we will be rolling out tools for app developers that will allow them to determine which people using their app might be impacted by this bug. We will be working with those developers to delete the photos from impacted users,” the post added.

Facebook has already faced severe criticism over privacy issues this year. The company drew fire for not handling misinformation and election manipulation on the platform too well. In October this year, Facebook announced that its team has discovered a security breach that has affected nearly 50 million users globally.

The vulnerability existed in the basic ‘View As’ feature which was often used to show how the account looks like to the public. The vulnerability in the code and a combination of three bugs allowed the hackers to penetrate the accounts.

 

Cymulate and Symantec join hands for shared research on email-based attacks

Symantec

Symantec Corporation recently announced a partnership with breach and attack simulation platform provider Cymulate to jointly research on the email-based threats. Cymulate claims that it helps companies prevent cyber-attacks with its advanced security solutions. Its Breach & Attack Simulation (BAS) platform enables organizations to unveil simulations of multi-vector cyber-attacks and provides solutions to mitigate the incident. The joint research allows both the companies to share and research on the information about how cybercriminals use malicious emails to infect organizations’ network systems.

“This partnership will enable Cymulate and Symantec to share critical information about real-world attack patterns, for example how attackers use custom crafted emails and files to bypass security products and infect organizations worldwide. Based on the insights, Symantec can now combine information from these simulated attacks with real-world data to provide a solution which remains one step ahead of the attackers,” said Jane Wong, VP Product at Symantec Corporation.

Symantec recently acquired Appthority and Javelin Networks to strengthen its mobile and enterprise security products and services. Symantec stated the acquisitions reinforce the company’s commitment to protect its clients against emerging threats.

The acquisition allows Symantec to use Appthority’s technology to analyze mobile apps for malicious threats and other vulnerabilities. Founded in 2014, Javelin Networks focuses on protecting enterprises from Microsoft Active Directory (AD) attacks. The buyout helps Symantec to integrate Javelin Networks’ technology into its endpoint security platform to prevent online intruders.

Google Cloud extends cybersecurity partnership with Palo Alto Networks

Google Cloud, Google Cloud Confidential Computing

Google Cloud, a cloud service platform from Google, recently declared that it’s extending the partnership with Palo Alto Networks to help organizations scale cloud services and accelerate cloud adoption.

Palo Alto Networks, an American multinational cybersecurity company, covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection. The extended cooperation allows Palo Alto Networks to use the Google Cloud Platform (GCP) for providing continuous enterprise security solutions to its clients.

“This partnership makes us a Google Cloud customer, allowing us to run important cloud-delivered security services at scale and with the benefits of Google’s AI and analytics expertise,” said Varun Badhwar, SVP Products & Engineering for Public Cloud Security at Palo Alto Networks. “We’ll also be working with Google Cloud to offer organizations moving to Google Cloud additional visibility, compliance and security capabilities they need to prevent cyberattacks.”

Google stated the partnership enables Palo Alto Networks to run its Application Framework and GlobalProtect cloud service on the Google Cloud Platform. Google claims that its Cloud Platform provides secure, durable cloud storage, and artificial intelligence tools.

Recently, Palo Alto Networks acquired cloud threat defense startup RedLock in an all-cash deal worth $173 million. The company stated that the new initiative will help security teams respond faster to  critical threats by replacing manual investigations with automated and real-time remediation. RedLock, a Menlo Park-based security startup, claims to provide threat defense platforms across public cloud environments to help organizations ensure compliance, govern security, and enable security operations. According to an official report, the acquisition brings RedLock co-founders Varun Badhwar and Gaurav Kumar to the Palo Alto Networks management team.

Further, Palo Alto Networks had made two other acquisitions this year. In March, the company announced its takeover of the cloud security platform Evident.io in a deal worth $300 million. And in April, it entered into a definitive agreement to acquire Israel-based Secdo.

Kubernetes security startup Tigera raises $30 million

Start up funding

Tigera, a Zero Trust network security startup, recently announced that it has raised $30 million in a Series B funding round led by Insight Venture Partners along with the participation of existing investors Madrona, NEA, and Wing.

The enterprise software company that provides security and compliance solutions for Kubernetes platforms stated the new funds will be used to accelerate its growth to meet the rising demand of its Kubernetes security platforms.

“Kubernetes is gaining momentum within every progressive enterprise,” said Ratan Tipirneni, president and CEO of Tigera. “These businesses cannot get their applications to production without strong security controls and the ability to prove compliance. As a result, we are being pulled into several hundred projects and will use this funding to meet that demand.”

Tigera offers Zero Trust network security and continuous compliance to enterprises that have adopted Kubernetes platforms. The company claims that its software has become omnipresent in the Kubernetes ecosystem and is being used by global companies including Amazon Web Services, Microsoft Azure, Google Cloud, and IBM Cloud to manage their Kubernetes Services.

Speaking on the new investment, Jeff Horing, the co-founder and managing director of Insight Venture Partners, said, “Tigera is uniquely positioned in the security market as a vast majority of enterprises have chosen to use the open source platform Kubernetes. The market is growing rapidly both with the adoption of Kubernetes and also with enterprises now ready to go to production – and security and compliance are top of mind. We welcome Tigera to our portfolio and look forward to helping them scale their business.”