Home Blog Page 357

Malcolm Turnbull opens new cybersecurity center to boost Australia’s online resilience

Canberra

The Government of Australia recently opened a new headquarters of the Australian Cyber Security Center (ACSC) in Canberra. The fifth cybersecurity-focused center of the country is aimed to be a central hub for the cybersecurity information, advice, and assistance for Australians.

While speaking at the opening of the center, the Prime Minister of Australia Malcolm Turnbull said, “The center will help us to collaborate and find joint solutions to the most complex cybersecurity challenges now and into the future. This new facility will drive cyber resilience absolutely critical so that we can realize all of the promises of prosperity and opportunity in the digital age.”

“We must ensure that we use all of our ingenuity, all of our innovation, all of our ability to collaborate with others to ensure that we keep Australians safe online, and this center is a very bold step towards achieving that goal,” Turnbull added.

The new facility acts as a critical hub for the Joint Cyber Security Centers located in Australia. The other four cybersecurity centers are based in Sydney, Melbourne, Brisbane, and Perth, respectively. The Perth Joint Cyber Security Center (JCSC) was launched last month in the state of Western Australia with an aim to protect the country’s energy and resources sectors.

Turnbull also notified that the new center is in the wake of increasing cyber threats on public and private organizations in Australia. Under its Cyber Security Strategy program, the Australian government decided to establish five cybersecurity-focused centers in the country, which are intended to boost cybersecurity resilience by bringing industry, government, and law enforcement together to share relevant threat information under one roof.

62% of UK firms lack cybersecurity insurance: Survey

A recent survey from analytics software company FICO revealed that 62 percent of UK firms lack complete cybersecurity insurance.

According to the research, only 38 percent of UK firms surveyed have cybersecurity insurance that covers all risks. Telecommunications firms lag behind other industries regarding cybersecurity insurance, 17 percent of firms reported that they have no coverage. Most of the respondents stated that their premiums are based on an inaccurate analysis or unknown factors.

“Cybersecurity insurance has become a must-have for UK firms in a short period of time,” said Steve Hadaway, FICO general manager for Europe, the Middle East and, Africa. “But with that growth will come increased pressure on insurers to increase the transparency and fairness around how premiums are set. Businesses will demand that their investments in cybersecurity protection and the strength of their cybersecurity posture drive their premiums down.”

“Although UK organizations perform well in terms of the uptake of cyber insurance, the fact that fewer than 40% have comprehensive insurance demonstrates there is still some way to go for these firms to have a broad view of their security posture and how to present it for insurance,” said Maxine Holt, research director at Ovum. “It could also show that these companies have a current security posture that insurers are not prepared to cover comprehensively. We should not detract from the positive news here; 90% of UK organizations have elevated the importance of cybersecurity to a level that requires insuring, even if only partially.”

The survey, conducted by Ovum for FICO also discovered that the number of UK firms with cybersecurity insurance has risen in the past year. The findings of the survey are based on telephonic interviews with senior staff in the security and IT sectors of companies with more than 500 employees in the UK, the US, Canada, Brazil, Mexico, Germany, India, Finland, Norway, Sweden, and South Africa.

Police body cams can be tampered with: Researcher

Ransomware Attack on Azusa Police

A security researcher from technology company Nuix revealed that police body cameras are easy to hack and manipulate.

Speaking at the DEFCON hacker conference in Las Vegas, cybersecurity expert Josh Mitchell demonstrated how to manipulate a footage from police body cams. The researcher used Vievu, Patrol Eyes, Fire Cam, Digital Ally, and CeeSc cameras to showcase the hack program. The hacking process included deleting or altering footage or amending crucial metadata, including where and when the footage was shot. The researcher also stated that it could help the bad actors to track the location of police officers.

“I have uncovered that hacking and editing body camera footage is not just possible, but entirely too easy,” Mitchell told in a media statement. “These systems have multiple unsecured attack points and fail to have even the most basic security practices. One device allowed root telnet access without a password. I could replace videos on another device by simply using FTP to overwrite existing evidence files. The third device encrypted and password protected evidence files by using the file name as the encryption key. None of the devices I have tested digitally sign the evidence files. Furthermore, every device I have tested allows for unsecured firmware updates.”

Mitchell carried out his hack program without using any custom software. “The risks would be entirely dependent on the motivation of the individual to carry out the attack. I would say that the impact and ease of exploitation are very high,” he added.

The researcher also suggested various prevention mechanisms like digitally signing all evidentiary information and device firmware, randomizing all SSID and MAC information, and keeping software up-to-date in order to mitigate the potential vulnerabilities.

Exabeam raises $50 million to become SIEM market leader

Artificial Intelligence

Cybersecurity startup Exabeam recently raised $50 million in a series D round of funding led by Lightspeed Venture Partners. The other investors in the round included Cisco Investments, Norwest Venture Partners, Aspect Ventures, Icon Ventures, and Shlomo Kramer. The new funds will support the company develop its cloud portfolio and accelerate sales and channels for global expansion.

“Our investors have an amazing track record of investing in companies that truly are disruptive and typically become category leaders,” said Exabeam CEO Nir Polak. “Their experience with high-growth companies like MuleSoft, Nutanix, Zscaler, ForeScout – is invaluable to us in the advice and guidance they pass along to our executive team. The new funding will allow us to invest heavily in our new cloud solutions and reach even more enterprises around the world. We are on track to overtake Splunk and be the next SIEM market leader.”

Founded in 2013, San Mateo-based Exabeam helps organizations by providing security intelligence and management solutions to strengthen their information security. The Exabeam Security Intelligence Platform leverages big data, machine learning, and analytics to detect and respond to cyber threats. It’s one among the number of security information and event management (SIEM) platforms that analyze companies’ log data sources to flag abnormal activities.

“As a longtime investor in the cybersecurity space, I’ve always been excited about Exabeam’s approach and potential to deliver the next generation of security tech,” said Theresia Gouw, co-founder of Aspect Ventures, and a leading investor in cybersecurity. “It’s clear from the large increase in replacement wins with customers like ADP, Hulu, Safeway, Union Bank that Exabeam is consistently delivering industry-leading technology to the most demanding enterprises and government organizations in the world.”

 

Cloud computing remains top emerging business risk: Survey

BusinessWire: Cloud computing ranks as the top risk concern for executives in risk, audit, finance and compliance, according to the latest survey by Gartner, Inc. While cloud computing presents organizations with novel opportunities, a number of new risks — including cybersecurity disclosure and General Data Protection Regulation (GDPR) compliance — make cloud solutions susceptible to unexpected security threats.

In Gartner’s latest quarterly Emerging Risks Report, 110 senior executives in risk, audit, finance and compliance at large global organizations identified cloud computing as the top concern for the second consecutive quarter. Additional information security risks, such as cybersecurity disclosure and GDPR compliance, ranked among the top five concerns of the executives surveyed.

The top two fast-moving, high-impact risks — those which have the ability to cripple an organization quickly — are also related to information security threats. Social engineering and GDPR compliance were cited as most likely to cause the greatest enterprise damage if not adequately addressed by risk management leaders, according to Gartner. However, only 18 percent of the cross-functional executives surveyed currently considered social engineering to be a significant enterprise risk.

Executives should expect cybersecurity threats to affect organizations in unpredictable ways. Through 2022, at least 95 percent of cloud security failures will be the fault of the organization, according to Gartner. As more sophisticated tactics such as social engineering are engineered to compromise sensitive data, organizations should expand their cybersecurity team to address evolving digital risks.

“Executives are right to expand cloud services as part of their digital business initiatives, but they need to ensure their cloud security strategy keeps up with this growth,” said Matthew Shinkman, practice leader at Gartner. “Leaders should start by clearly identifying their most at-risk areas, which remain obscure to many large organization leaders.”

Increased Adoption Brings New Risks

Gartner forecasts cloud computing to be a $300 billion business by 2021, as companies increasingly adopt cloud services to realize their desired digital business outcomes. Through the use of cloud services, cloud computing provides the speed and agility that digital business requires. Adopting the cloud can also result in significant cost savings and generate new sources of revenue.

Results from Gartner’s Emerging Risks Report, however, reveal that companies continue to struggle with security. Despite record spending on information security in the last two years, organizations have lost an estimated $400 billion to cyber theft and fraud worldwide. As cybersecurity events and data breaches increase, it is imperative that organizations elevate IT security to a board-level topic and an essential part of any solid digital business growth strategy.

“Executives should promote risk awareness throughout the organization,” Mr. Shinkman stated. “A strong risk culture helps employees make the right decisions and mitigates poor outcomes.”

More detailed analysis is available to Gartner clients in the full report “2Q 2018 Emerging Risks Report and Monitor.”

 

Pentagon invites researchers to ‘Hack the Marine Corps’ bug bounty event

The Department of Defense recently ran a bug bounty program dubbed ‘Hack the Marine Corps’, a challenge focused on the Corps’ public-facing websites and services. The event was jointly created by the Department of Defense and HackerOne, vulnerability disclosure company based out of Las Vegas on the heels of the annual Black Hat and DEF CON conferences.

“Hack the Marine Corps allows us to leverage the talents of the global ethical hacker community to take an honest, hard look at our current cybersecurity posture,” said Maj. Gen. Matthew Glavy, Commander, US Marine Corps Forces Cyberspace Command in a statement. “What we learn from this program will assist the Marine Corps in improving our warfighting platform, the Marine Corps Enterprise Network. Working with the ethical hacker community provides us with a large return on investment to identify and mitigate current critical vulnerabilities, reduce attack surfaces, and minimize future vulnerabilities. It will make us more combat ready.”

The nine-hour program paid out $80,000 in prizes to the researchers for discovering 75 unique vulnerabilities. The researchers are also allowed to report any flaws they find through the HackerOne-managed Marine Corps vulnerability disclosure program until August 26, 2018, but without earning a prize.

The CEO of HackerOne Martin Mickos stated that HackerOne and the Marines would not reveal the details of the newly found vulnerabilities, which included usual website flaw suspects, authentication flaws, and cross-site scripting. “The key goal of these live hacking events is to have this collegial and social [atmosphere], although it’s also a competition,” Mickos said. “They may give advice … ‘don’t go there, look here.”

Tencent’s security researchers discover technique to hack Amazon Echo

A security team from Tencent Blade exposed new security vulnerabilities around smart speakers. Researchers Wu HuiYu and Qian Wenxiang gave a live demonstration at the DEFCON security conference on how to hack a smart speaker. The team used Amazon Echo smart speakers to present their attack program.

The researchers hacked the speaker by adding a malicious device embedded with an attack program.  “After several months of research, we successfully break the Amazon Echo by using multiple vulnerabilities in the Amazon Echo system, and achieve remote eavesdropping,” the researchers said in a media report. “When the attack succeeds, we can control Amazon Echo for eavesdropping and send the voice data through a network to the attacker.”

The researchers notified Amazon of their findings before the presentation, and Amazon has already pushed a security patch to fix the issues.

“Customers do not need to take any action as their devices have been automatically updated with security fixes,” an Amazon spokesperson said in a statement. “This issue would have required a malicious actor to have physical access to a device and the ability to modify the device hardware.”

Researchers have been exploring various vulnerabilities on IoT devices that can cause potential information security threats for organizations and individuals. In its new research, cybersecurity solutions provider Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines. The research findings were presented by Check Point’s researchers Yaniv Balmas and Eyal Itkin at DEFCON 26. They stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number. The researchers also showed how they were able to exploit security flaws in a Hewlett Packard all-in-one printer.

Check Point research reveals how hackers can intrude networks via fax machines

A new research from cybersecurity solutions provider Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines.

Researchers at Check Point stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number. The researchers also showed how they were able to exploit security flaws in a Hewlett Packard all-in-one printer.

The findings were presented by Check Point’s researchers Yaniv Balmas and Eyal Itkin at DEFCON 26.

“Many companies may not even be aware they have a fax machine connected to their network, but fax capability is built into many multi-function offices and home printers,” said Yaniv Balmas, Group Manager, Security Research at Check Point. “This ground-breaking research shows how these overlooked devices can be targeted by criminals and used to take over networks to breach data or disrupt operations.”

“It’s critical that organizations protect themselves against these possible attacks by updating their fax machines with the latest patches and separating them from other devices on their networks. It’s a powerful reminder that in the current, complex fifth-generation attack landscape, organizations cannot overlook the security of any part of their corporate networks.” Balmas added.

Describing the potential threat, the researchers said the attackers can send specially created malware coded image file via fax to the targeted networks. The vulnerabilities in the fax machine enable malware to decode and uploads to its memory, which can breach sensitive information or cause disruption across the connected networks.

Check Point recommended organizations to install updated firmware for their fax devices and place them on a separated network system to minimize the security risks.

 

Election hacking, now a child’s play

Election hacking

Election hacking is now a child’s play, or at least that is what Democratic National Committee (DNC) of United States is trying to show at the DEFCON in Las Vegas. Inspired by last year’s DEFCON’s Voting Village, where attendees got to penetrate several models of voting machines and find flaws, DNC wants to step things up this time where kids as young as eight years old will be tasked with hacking target replicas of election results reporting sites, as it was too puny and easy for grownups (read adult hackers). “These websites are so easy to hack we couldn’t give them to adult hackers — they’d be laughed off the stage,” Jake Braun, a former White House liaison for the U.S. Department of Homeland Security, told ABC News. “They thought hacking a voter website was interesting 20 years ago. We had to give it to kids to actually make it challenging.”

The kid who will come up with the best defense strategy will be awarded $2500, of which DNC will be sponsoring $500. “Kids will hack into replicas of the Secretary of State election results websites for thirteen Presidential Battleground States, manipulating vote tallies and election results,” organizers explained to Common Dreams.

This isn’t a rather kitsch ploy but a message which DNC and DEFCON trying to convey. “For anyone who knows anything abt DefCon, or r00tz, they know that no one would encourage kids to hack real elections. The point of this exercise is: 1. Help get these young hackers involved in civic engagement at an early age. 2. Demonstrate how easy it is to change election results online as has been done for real in ukraine and Ghana and 3. Learn from creative social engineering ideas these kids think of that none of us would we prefer to sensitize the public to this at DEFCON when there isnt a real election or during a real election night.” DEFCON wrote on a thread of tweets.

Convincing organizations to say “Yes to InfoSec”

credential phishing campaigns

Contributed by Cloud Security Alliance

By Jon-Michael C. Brook, Principal, Guide Holdings, LLC

Security departments have their hands full. The first half of my career was government-centric, and we always seemed to be the “no” team, eliminating most initiatives before they started. The risks were often found to outweigh the benefits, and unless there was a very strong executive sponsor, say the CEO or Sector President, the ideas would be shelved.

More recently, as a response to the security “no” team, IT staff started several “Shadow IT” projects. People began using cloud computing systems and pay-as-you-go strategies on a corporate credit card to quickly develop and roll-out projects before anyone in security could get a word in.

These “beg forgiveness” aspects hamstrung security on several projects, especially if a data leakage incident occurred or breach was in progress. What’s more, we weren’t unique in seeing shadow projects. These projects increasingly become the norm as IT staff looking to move initiatives forward come up against cybersecurity professionals hell-bent on maintaining security and, who know that in the event of a breach, heads could easily roll. Most likely theirs.

Tired of being seen as the “no” team? Here are three ideas that could reshape the value of security to your company as a whole:

Demonstrate Trust

Trust messages needs to come from outside of the department, even if it’s ghostwritten or created internally. Be it the CTO, CFO or CEO, there needs to be a bit of understanding that risk comes in many forms, and the Security Department takes all of those into account before approving or denying projects.

Many compliance frameworks have an HR or training domain, and some security departments successfully use this for mandatory training for topics like phishing. When a non-infosec colleague clicks on a fake attack, the trust point may be reiterated with a reminder of example fines and the costs. Breach notifications or PCI violations aren’t cheap after all.

Show Security as a Business Enabler

Share a couple of department wins, where the security team found involvement early in the process and added value to the program deployed. Look for examples like oAuth or Single Sign On (SSO) simplifying a portal’s usage or a project where business continuity planning or encryption helped pass an acceptance audit.

Demonstrating that security builds team success and is no longer the “no” department pays dividends.

Provide Educational Incentives

Lastly, extend the educational aspect beyond testing for ignorance. See if your organization offers reimbursement or even bonuses for security certifications, and stand-up internal lunch-and-learn or video conference preparation sessions. If your organization doesn’t provide an across-the-board financial incentive, maybe fund a raffle for five of the folks who pass the test to receive a spot bonus.

Hopefully, you’ll find these as an opportunity to impress upon the rest of the corporation the importance of the CISO’s office. There’s a long history of “no;” without efforts on the infosec staff’s part, that image will linger well past its truth.

This article was originally published here, and is posted here with permission.