Home Blog Page 351

Few minutes with Adi Dar

Adi Dar

Adi Dar, CEO and Founder of Cyberbit, is an experienced cybersecurity leader and chief executive who has repeatedly led the development and launch of successful products and services in highly competitive markets. Previously, as CEO of ELOP, Dar led the company’s growth to over $500M annual revenues and 1,800 employees. During this period, Dar also served as an Executive VP at Elbit Systems, Israel’s largest defense company, as well as a chairman and board member in numerous companies across the UK, Singapore, Belgium, India, and Israel.

CISO MAG had an opportunity to sit down with him and discuss some pressing issues related to cybersecurity.

You have stressed a lot on merging IT, OT, and IoT to create an effective cybersecurity strategy. What are the challenges with regards to that? 

Now that IT and OT networks are converging, cybersecurity must also converge and deliver both security and continuous operations. This requires a very steep learning curve as keeping OT networks functioning smoothly now also requires protecting them from cyber threat that can disrupt or even halt operations.  From my experience the only way to have an effective cyber security solution in these converged networks is by introducing a fully integrated IT-OT system that can monitor, detect, and respond to threats on both the IT space as well as the OT one.

A lot of security leaders talk about skill gap in the industry. Do you think certifications and more awareness about cybersecurity is bridging that gap slowly?

Certifications are certainly an important part of bridging the growing skill gap – they create the standardization and build the demand. A natural part of the cybersecurity industry maturing is establishing formal education, training, and certification programs. This is certainly a fast-growing area. We see proof of it every day at Cyberbit as colleges, universities and technology training institutes are rushing to open up new cybersecurity training centers. In the past there was really no way for companies to know what skills and experience a candidate had, so certifications will make sure there is an agreed upon minimum standard that all professionals should have.  Certification programs will also help more new people enter the profession in an efficient manner. Our customers can use the Cyberbit Range not only to train, but to test graduates and verify that they can actually carry out everything they learned in a real-world setting. This gives potential employers reliable verification that new recruits have hands-on experience needed to perform well under pressure. But more than anything I’d say that the industry has begun to understand that investing in the human resource – in the cyber security professional is not less important, and in many cases by far more important than continuing to buy additional tools. Without the cyber experts knowing how to effectively operate these technologies – you’ll never be able to actually secure your networks

What are the things you should keep in mind while recruiting cybersecurity professionals?

The most important thing to keep in mind while recruiting cybersecurity professionals is to keep an open mind and be creative. The old recruiting paradigm of writing up a highly detailed job description that enumerates the ideal training and experience you seek doesn’t work for cybersecurity today because the candidate you describe simply doesn’t exists. If you get lucky you may receive one or two such resumes, but it will never be enough to keep your SOC fully staffed with skilled, reliable security analysts. Instead of hoping you will receive dozens of resumes from candidates with the perfect training and experience, look for creative new ways to grow your team.

Student Outreach

The first thing I would recommend may be obvious, but it is worth repeating. Establish and maintain good active relationships with colleges and technical certification institutes that offer cybersecurity and IT training programs in your area. Offer free guest lectures and mentoring on cybersecurity and consider starting an internship or student job program. This is a wonderful way to identify and establish relationships with talented young students before they graduate and help them get some real, hands-on experience before they officially enter the job market.

Look Within

Of course, you should advertise open positions externally, but you probably have a lot of potential talent already inside your organization. Try to identify talented, ambitious employees who would be interested in further developing their careers by retraining in cybersecurity. This is an exciting opportunity for employees to move into one of the fastest-growing technology fields and is a promising career development path.

Grow Your Own Team

The demand for cybersecurity pros is growing much faster than the supply. This means that employers need to be proactive and become part of the solution by developing their own training programs. Depending on the size and needs of your organization, you can build your own on-site training institute to certify and onboard new security analysts and offering ongoing training for experienced team members on the latest cyber threats.

 

Palo Alto Networks to acquire cloud security startup RedLock

The cybersecurity firm Palo Alto Networks recently announced its intent to acquire cloud threat defense startup RedLock in an all-cash deal worth $173 million.

Founded in 2005, the American multinational cybersecurity company, Palo Alto Networks, covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection. The company stated that the new initiative will help security teams respond faster to the critical threats by replacing manual investigations with automated and real-time remediation.

“We are thrilled to add RedLock’s technology to our cloud security offerings. The addition of their technologies allows us to offer the most comprehensive security for multi-cloud environments, including Amazon Web Services, Google Cloud Platform, and Microsoft Azure, and significantly strengthens our cloud strategy going forward,” said Nikesh Arora, chairman, and CEO of Palo Alto Networks.

RedLock, a Menlo Park-based security startup, claims to provides threat defense platforms across public cloud environments to help organizations ensure compliance, govern security, and enable security operations. According to an official report, the acquisition brings RedLock co-founders Varun Badhwar and Gaurav Kumar to the Palo Alto Networks management team.

“We are excited to join Palo Alto Networks to bring together the strength of our cloud analytics and their industry-leading compliance technologies to help security teams protect their organizations,” said Varun Badhwar, co-founder, and CEO of RedLock.

Palo Alto Networks had made two acquisitions this year. In March, the company announced its takeover of the cloud security platform Evident.io in a deal worth $300 million. And in April, it entered into a definitive agreement to acquire Israel-based Secdo.

 

Burgerville suffers massive breach, hackers collected customer data for a year

Popular burger chain from the Pacific Northwest region, Burgerville, is the latest victim of a data breach. The Vancouver-based food joint recently disclosed that any customer who had made a purchase from its 42 stores spread across the region between September 2017 and September 2018 using their credit or debit have had their financial data stolen in a hack. “On August 22, 2018, the Federal Bureau of Investigation (FBI) notified Burgerville of a cybersecurity breach impacting a number of the company’s systems,” the food chain joint stated in a release.

In mid-September, during the forensic investigation, the burger chain discovered what they had thought to be a brief intrusion was a massive breach and was still active during the time. Apparently, hackers had placed a malware on Burgerville’s network and continued to collect payment details of customers for a year. As an immediate step, the food joint sought third-party assistance in cooperation with the FBI to disable the malware.

“The organization responsible for this breach is believed to be Fin7, a sophisticated international cybercrime group. On August 1, 2018, the U.S. Department of Justice issued a press release announcing the apprehension of three members of this group who have been connected with launching cyberattacks on more than 100 companies across 47 states. The press release mentions that there was a wave of attacks on local businesses specifically in Western Washington, which includes Burgerville,” the release added.

The company explained that it doesn’t store credit card numbers of customers. It was the malware installed by the hackers that was acting up. Fortunately, no other allied third-party company has been affected in the attack, except the ones that were disclosed by the United States Department of Justice.

“Burgerville completed its remediation plan. The operation had to be kept confidential until it was completed in order to prevent the hackers from creating additional covert pathways into the company’s network,” it said, while concluding that, “This was a sophisticated attack in which the hackers effectively concealed all digital traces of where they have been.”

NYCEDC unveils plans to make NYC cybersecurity powerhouse

New York City

NYCEDC (New York City Economic Development Corporation) recently unveiled the plans to make New York City a cybersecurity powerhouse. The plans will be implemented under NYCEDC’s Cyber NYC program that envisions of making the city a global leader in the domain and creating 10,000 jobs within five years.

The entire initiative will cost around $100 million. New York City will invest $30 million and the rest would be raised through private funding. The robust initiative will include establishing a Chelsea-Based Global Cyber Center, a SoHo-Based Innovation Hub, a Facebook-CUNY Master’s Program, a Virtual Apprenticeship Program, and a Cyber Boot Camp for Underserved New Yorkers, Among Other Initiatives.

“New York City needs to be ambitious about cybersecurity because our future depends on it. Cyber NYC will fuel the next generation of cybersecurity innovation and talent, leveraging one of the world’s greatest threats to create a major economic anchor and up to 10,000 quality middle-class jobs,” said NYCEDC President and CEO James Patchett. “We’ve convened a world-class roster of partners to help us execute on this essential plan, which will help protect the industries and people that make this city the economic powerhouse that it is today.”

NYCEDC has selected corporate innovation expert SOSA to establish the Global Cyber Center whereas Israeli venture capital fund Jerusalem Venture Partners (JVP) will Hub.NYC, city’s first international cybersecurity investment hub. Academic institutions such as Columbia University, New York University, Cornell University, and City University of New York will also be involved in other initiatives.

“We’re convinced that New York City, the world capital of finance and media, will soon emerge as the new global hub for cybersecurity,” said Erel Margalit, Founder, and Chairman of JVP. “If the West Coast is the U.S technology hub, New York can become the international technology Hub in close partnership with Israel and the international community to build the next generation of cybersecurity companies to counter the new threats.”

Tech Mahindra partners with IAI to provide cyber solutions to governments and global enterprises

Indian outsourcing and consultancy giant, Tech Mahindra, has partnered with ELTA Systems Ltd., a group and subsidiary of Israel Aerospace Industries (IAI) to provide cyber solutions and services to government and enterprise customers in India and around the world.

The partnership will enable the companies to design and deliver Security Operation Centres (C-SOCs), Computer Emergency Response Teams (CERTs) and Forensic Laboratories, leveraging on automation and orchestration tools, AI and Machine learning analytics and technology. The partnership will also offer consultation, training and managed security services and develop technologies that meet the evolving challenges of the cyber domain.

CP Gurnani, Managing Director & Chief Executive Officer, Tech Mahindra said, “We are excited to partner with Israel Aerospace Industries (IAI). This strategic partnership will herald a new chapter in tackling the advanced global cybersecurity threats in today’s digital age, by developing a future-ready cybersecurity framework. Partnership with IAI will be a multiplier force for Tech Mahindra’s robust cybersecurity expertise world over.”

Tech Mahindra’s Security Operations Center (SOC) capabilities along with IAI’s broad suite of cyber intelligence & defence products, proven methodology and constant innovation will synergize to innovate and establish new services in areas of cyber intelligence, protection, monitoring, identification and integrated cyber resilience. The solutions will help governments, organizations and critical infrastructure to keep pace with emerging cyber threats.

Esti Peshin, VP and General Manager of IAI’s Cyber Division, said, “We are excited to collaborate with our strategic partner, Tech Mahindra, a company present in 90+ countries. We are confident that Mahindra’s experienced cyber security professionals will equip IAI with a sustainable competitive advantage, improving our ability to scale rapidly and prevent cyber-attacks with cutting-edge cybersecurity solutions.”

The partnership will endeavour to provide a holistic end-to-end approach that serves defence forces, governments, critical infrastructures and large enterprises with state-of-the art cyber security & monitoring capabilities.

Rajiv Singh, Sr. Vice President & Global Head of Cybersecurity unit of Tech Mahindra said, “IAI’s practical experience of protecting governments around the world from cyber-attacks, as well as hands-on and operational experience in cyber threat intelligence solutions, training, digital forensics, communication security and cyber security, will compliment Tech Mahindra’s  established cyber security practice. Together we will create elite Cyber Warriors and AI based defence capabilities to combat advanced cyber threats and cyber-crime faced by Government entities and Police forces”

He continued, “IAI’s advanced military grade cyber security capabilities combined with Tech Mahindra’s Intelligent SOC will deliver compelling cyber security solutions for Banking, Insurance, Telecom, Critical Infrastructure, Utility and other sectors across the globe”.

Understanding Weaponized DDoS Attacks

DDoS Attacks

Contributed by Rod Arthur

Modern cyber-attacks have become more sophisticated. Standard modern attacks are multi-stage attacks rather than infection by a single malware executable. DDoS (Distributed Denial of Service) attacks have evolved into weaponized instruments used to disseminate ransomware, as well as launch disruptive attacks against their targets. Attack vectors targeted for weaponization include mobile devices, documents, browsers, with the current favorite being IoT (Internet of Things) devices. Weaponization is the second stage of the intrusion kill chain, which is the sequence followed by an intruder to successfully attack a target. Weaponization involves developing malicious code and combining it with deliverable payloads (i.e. word docs, pdfs, etc.). The process can be simple or complex, such as developing a malicious payload, which can be a trojan, or an executable which performs an action on the target device.

App-DDoS Attack

The intent of DDoS attacks is to saturate the target with useless traffic to inhibit the availability of services provided by the target. The success of these attacks is due to the design of the internet. The internet is a mass of intertwined networks, services, content distribution networks, and DNS operated by government entities and private corporations. These organizations can unknowingly be involved in large-scale DDoS attacks. The March 2015 Great Cannon attack is an example of millions of web browsers becoming weaponized by injecting malicious JavaScript code into transiting TCP flows. The malicious code silently programmed the browsers to create a massive DDoS attack. The Great Cannon attack was an example of an Application Layer Distributed Denial of Service (or App-DDoS) attack, which are stealthy, sophisticated DDoS attacks using the “low and slow” approach making it difficult to detect as it does not generate high volumes of traffic. Application layer attacks can be effectively launched from a single attacking source. However, launched in a distributed manner, the effect is amplified. Attacks disguised as legitimate HTTP requests further makes detection challenging since the requests look proper from the protocol and traffic. A target server is saturated with legitimate looking GET and POST requests, consuming the server resources and denying legitimate users from accessing resources. HTTP is a favorite target of hackers as it is a dominant part of the internet. App-DDoS attack can blend with flash crowd traffic, further making it difficult for defense systems (such as traditional firewalls) to discriminate DDoS attack traffic from legitimate user traffic.

Weaponizing Documents for Potential DDoS Attack

Hackers usually consider the human element when targeting an organization. The “kill chain” concept is usually associated with network intrusions but not with the asymmetric DDoS threat. Using the Intrusion Kill Chain as a model, adversaries commonly perform reconnaissance (first phase of the Kill Chain) by collecting information about a target profile on the internet and exploring technologies the target uses. If the adversary gains the email address of the victim, the email becomes the gateway to the victims’ network or system. The attacker can weaponize (second phase of the Kill Chain) file types PDF, PPT, DOC, JPG, etc., typically using an automated tool to develop malicious code and sends the malicious payload (third phase of the Kill Chain) as an email attachment to the victim. Once the victim downloads the attachment by clicking on it, their system is exploited (fourth phase of the Kill Chain) and the malicious payload can be automatically executed. Once the Trojan is installed (fifth phase of the Kill Chain), the attacker can maintain persistence inside the environment). A command and control channel (sixth phase of the Kill Chain) is then established for the purpose of giving the attacker a “hands on keyboard” access to the compromised host. The compromised host is then used as a “hop point” (seventh phase of the Kill Chain) to compromise other systems.

In May, 2016 researchers from Sophos discovered a weaponized document serving the dual purpose of delivering ransomware to the system, as well as exploiting it for potential DDoS attack (https://www.invincea.com/2016/05/two-attacks-for-the-price-of-one-weaponized-document-delivers-ransomware-and-potential-ddos-attack/). While access to the system was denied to the owner, it was simultaneously denying service to another victim. The weaponized document was sent as a spear fishing email which upon opening launched Microsoft Word and initiated embedded macros, which enabled elevated privileges for the malicious document to execute an encoded VBscript. The script created a malicious binary which was a ransomware of the Cerber family. The binary made changes to the screensaver via registry and also appeared to be carrying out a DDoS attack by flooding the subnet with network traffic using UDP packets on port 6892. The spoofed source address could direct response traffic from the subnet to interrupt host operations. The multipurpose malware distributed ransomware and simultaneously carried out a Distributed Denial of Service attack. Weaponized deliverables are typically disguised as client application files and can be delivered to unsuspecting recipients, creating backdoors in the infected system to incorporate it into a botnet.

Mobiles as Cyber Attack Surface

Increase in smartphone usage as well as proliferation of mobile applications has enlarged the attack surface of cyberspace. Smartphones function much like computers and connect to the internet from anywhere as well as download files and applications, some of which can be malicious. As the usage of mobile devices increases, so does the effectiveness of using them to launch distributed attacks such as a mobile botnet attack. In September of 2015, researchers from CloudFlare reported a DDoS attack using up to 650,000 smartphones, peaking at over 275,000 http requests and resulted in 4.5 billion hits toward a designated website. Smartphones make an enticing target for hackers as a larger number of users own smart devices then PC’s. Once a smartphone is compromised by malware, it will send traffic toward a specific host (victim) once it receives a DDoS attack command. The proliferation of mobile technologies have led to a new type of DDoS attack, known as Low-rate DDoS. Low-rate DDoS sends attack traffic to the target on a random basis, making it harder to detect among normal traffic.

Weaponization of IoT

The proliferation of IoT devices has increased the attack surface and a malicious actor can weaponize an IoT botnet from their basement. Using the Mirai botnet attack of 2016 as an example, IoT botnets are capable of high volume impacts. The combination of IoT and DDoS results in devastating cyber-attacks using armies of compromised IoT devices. These DDoS attacks are made possible by the proliferation of exploitable devices coming on line, such as cameras, smart meters, baby monitors, internet cameras and more. The 2016 Mirai botnet attack which overwhelmed DNS provider Dyn was an example of the destructive power of IoT enabled attacks. The attack was the largest to date on record, generating a throughput of 1.2 terabytes per second, with the sheer volume of the attack making cloud provider DDoS mitigation economically unfeasible.

The problem is many of these IoT devices contain default usernames and password combinations which are rarely changed by the consumer and are easy to exploit. Further, IoT devices are developed with security as an afterthought. Secure IoT device development as well as customer education (i.e. changing default passwords) may help to increase resiliency against IoT device attacks.

Tesco Bank slapped with $21.4 million fine for 2016 cyber-attack

Tesco Bank

Britain financial and regulatory watchdog, Financial Conduct Authority (FCA), has slapped Tesco Bank with £16 million ($21.4 million) fine for the cyber-attack the bank suffered in 2016. According to the regulatory body the Bank failed exercise due skill, care and diligence and protect account holders at its bank from a foreseeable cyber-attack, which occurred for over 48 hours in 2016. The regulatory body pointed out that hackers had exploited deficiencies in Tesco Bank’s design of its debit card and in its financial crime controls.

Nearly £2 million was stolen from nearly 9000 customers using counterfeit cards, with nearly 40,000 accounts being compromised in the attack. As an immediate remedy Tesco froze online transactions for its nearly 136,000 account holders, which resulted in several customers unable to pay their bills.

“Those deficiencies left Tesco Bank’s personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours and which netted the cyber attackers 2.26 million pounds,” the FCA said in a statement.

The incident was FCA’s first ever fine for failing to safeguard cyber infrastructure. The fine is also to make other lenders more vigilant toward cyber-attacks and consider it as a top priority. “The fine the FCA imposed on Tesco Bank today reflects the fact that the FCA has no tolerance for banks that fail to protect customers from foreseeable risks,” said Mark Steward, executive director of enforcement and market oversight at the FCA. “In this case, the attack was the subject of a very specific warning that Tesco Bank did not properly address until after the attack started. This was too little, too late. Customers should not have been exposed to the risk at all”.

Tesco Bank once again apologized for the incident and agreed to pay up the said fine. “We are very sorry for the impact that this fraud attack had on our customers. Our priority is always the safety and security of our customers’ accounts and we fully accept the FCA’s notice,” said Gerry Mallon, Tesco Bank chief executive. “We have significantly enhanced our security measures to ensure that our customers’ accounts have the highest levels of protection. I apologise to our customers for the inconvenience caused in 2016.”

ManTech names Adam Rudo Senior Vice President and General Manager of Security Solutions Business Unit

GLOBE NEWSWIRE

Cybersecurity firm, ManTech, has appointed Adam Rudo as Senior Vice President and General Manager of the company’s Security Solutions business unit (SSBU), part of ManTech’s Mission, Cyber and Intelligence Solutions (MCIS) Group.

As General Manager of ManTech’s SSBU, Rudo will plan and drive the unit’s mission-critical work for the U.S. Intelligence Community. He joins ManTech from General Dynamics IT, where over a period of 13 years he rose to leadership of the company’s Intel division as Senior Vice President, responsible for revenue commitments, growth objectives, retention and customer satisfaction. Prior to General Dynamics, Rudo worked for Lockheed Martin.

“As a leader with a proven record of supporting the needs of our nation’s Intelligence Community, Adam Rudo will hit the ground running at ManTech,” said Rick Wagner, President of ManTech’s MCIS Group. “His leadership, customer and technical experience providing IT solutions and direct mission support to these customers uniquely positions him to lead our Security Solutions Business Unit.”

Rudo replaces Paul Gentile, who will support the transition of his responsibilities before retiring on January 4, 2019.

US Army’s Future Command prepares against attacks from flying bombs

U.S. Military Personnel and Veterans

United States Army’s new Futures Command (AFC) are leaping step forward in combating threats from flying bombs. The said flying bombs are drones, and Futures Command recently hosted a Hack-a-thon where developers and hackers, and participants from all backgrounds, including academic, military and commercial startups were tasked with finding innovative ways to hack a drone. “These are basically flying bombs,” Jay Harrison, AFC’s command innovation officer, told KXAN. “That is something that we’ve seen around the world.” The Hack-a-thon was in collaboration with Department of Defense’s National Security Technology Accelerator Program. “The speed with which those technologies are available, the ability of bad actors to get their hands on those technologies very quickly,” Harrison said, “we have to counter that dynamic with our own innovators.”

“If we are going to solve problems differently, we have to get outside of Washington, DC and find talented people in great ideas where they sit. And that means Austin, Boston, Omaha, Denver, Los Angeles, and that’s why Army Futures is here and MD5 is here. Because we have to go where the talent is and the truth is we’ve got great top tier universities here in Texas. UT Austin is right here, Texas A&M just down the road,” said Morgan Plummer, Managing Director with The National Security Technology Accelerator. “We’ve got a phenomenal venture start up community here and we are trying to take advantage of both of those communities to pull those ideas, that tech and talent back into the Department of Defense. If we can’t do that, we are just not going to be able to solve problems as fast as we need to,

Several teams also won cash prizes and the opportunity to develop their solution with the U.S. Department of Defense.

Earlier this year, citing cybersecurity concerns in the commercial off-the-shelf (COTS) drones, the Department of Defense banned the United States Marine Corps from using them.

“The DoD Inspector Normal discovered that the DoD has not carried out an enough course of to evaluate cybersecurity dangers related to utilizing COTS Unmanned Aerial Programs,” had stated a policy memo signed by the Deputy Secretary of Protection Patrick Shanahan.

In 2017, PacSec researcher Jonathan Andersson developed a hardware that was capable of hijacking drones. Dubbed as the Icarus, the hardware module only needed to be with the range of a drone to hijack it with commands. A video posted by Kaspersky Labs showed the Icarus taking control of a drone mid-air within 11 milliseconds of launch. In fact, the device could affect any radio-controlled device which used the popular DSMx radio platform.

Security breach exposes 50 million Facebook accounts

The largest social networking site, Facebook is the latest victim of a cyber-attack. On Friday, the networking giant announced that its team has discovered a security breach that has affected nearly 50 million users globally.

The vulnerability existed in the basic ‘View As’ feature which was often used to show how the account looks like to the public. The vulnerability in the code and a combination of three bugs allowed the hackers to penetrate the accounts.

“It looks like when Facebook built the ‘View As’ feature, they did this by making it a modification of how Facebook would work if actually viewed by that other user,” said professional web app hacker and cybersecurity researcher Thomas Shadwell to Forbes. “Which of course means if there’s a mistake they might end up sending the impersonated user’s credentials to the user of the ‘View As’ feature.”

The Forbes also report explained that “If a user, via View As, impersonated a friend who themselves had a friend who had a birthday, the feature would also show a box prompting them to post a “happy birthday” video. Thanks to an error made by Facebook in July 2017, the video provided the user with one of those precious tokens.”

As the immediate step, Facebook has turned off the feature and has reset 50 million affected accounts and nearly 40 million others to stay on the safer side. Ironically though, the actors behind the breach have not been identified, nor has the security team of the platform figured out if any of these accounts were misused.

Even more alarming being the fact that there are several hosting tutorials on YouTube on how to hijack a Facebook Account using similar methods used by the hackers in the incident. Many of those continue to exist on the video sharing platform.

Beau Woods, a cybersecurity fellow at the Atlantic Council, said in an interview with The Telegraph told that “it was likely the vulnerability had already been identified by other attackers in the fourteen months since it was introduced. I would say that the 50 million is maybe the tip of the iceberg. It’s not uncommon to have multiple adversaries over time, varying in sophistication, and it’s just the clumsiest one that alerts the palace guards.”

With GDPR in place, it is also reported that Facebook could be fined as much as $1.63 billion by European Union privacy watchdogs.