Home Blog Page 36

Gaining Organizational Trust for Zero Trust

zero trust

The notion of Zero Trust – never trust, but always verify – has been gaining momentum for more than a decade. With so much of our lives and businesses rooted in the digital world, there is more sensitive data at risk and subsequently more large-scale cyberattacks and security breaches than ever before. The movement to incorporate remote work capabilities in a post-COVID world has only added to the fear of vulnerability. As a result, we’re seeing an increased shift to Zero Trust among organizations of all sizes.

By Andy Sobotta, Chief Information Security Officer, Bridgestone Americas

However, as a cybersecurity professional who is part of a large corporation, I know that I am not able to operate in isolation. I cannot simply change protocol and security methods, as there are many decision-makers and stakeholders who need to be brought on board to make needed investments in people, processes, and technology to create a Zero Trust culture.

Check Out CISO MAG’s November Issue: Zero Trust, IAM & PAM: The New Cocktail for Mitigating Security Risks

In my role as CISO at Bridgestone Americas, I am responsible for leading information security and compliance strategy across the organization. We have more than 40,000 employees in eight countries, with additional offices throughout Latin America and the Caribbean. Zero Trust is a step we undoubtedly have to take to protect such a sprawling enterprise, but it’s also our size that makes this undertaking a bit daunting. So, we have taken several initial steps to make this transition a success.

By sharing our approach to implementing Zero Trust at Bridgestone, my hope is that you can use these insights to more effectively shape your own strategy and garner better buy-in. In my experience, the key is to invest the time to understand the business’s priorities and challenges instead of asking them to understand technology jargon.

Laying the Groundwork

To grasp why change is needed, stakeholders first need to understand the threat. Those not actively involved in cybersecurity often have a false sense of security. There are passwords and verifications required when they work, so it appears that documents and files are protected. Since I’m always looking for ways to make things more interesting, let’s take a look at the risks of traditional network access by using a wine cellar as an example.

In traditional network security, you can only access the wine cellar if you are given a key. If you have a key, you can access the entire cellar and all the wine (data). However, keyholders can be duped into allowing someone else to use their key, or they can be pickpocketed and the key stolen. Even those who are authorized to have a key might not have good intentions, copying their key to give others access, or taking wine that isn’t theirs to enjoy. You know, the good stuff.

Hopefully, this or some other metaphor helps stakeholders understand how their data is not quite as secure as they thought. Then, you can delve into why it matters. Most people comprehend the risk of unauthorized access to sensitive information but quantifying it will make your message more impactful. The 2017 Data Breach Study, conducted by Ponemon Institute and sponsored by IBM, found that the global average cost of a data breach is $3.62 million, and the average size of data breaches increased from the year prior by 1.8 percent to more than 24,000 records. Translation: a key in the wrong hands can mean a significant loss, a total wipeout of the cellar, or even result in someone changing the locks and holding your wine library hostage. A breach can be a devastating scenario for a business, and we can’t trust these old-fashioned keys.

As you lay the groundwork for a cybersecurity overhaul, be prepared for the name Zero Trust not to resonate well with people. It suggests that employees, and even executives, cannot be trusted; everyone is a potential threat. Certainly, that is the idea of it and exactly why Zero Trust works. However, renaming the process for your organization, or even avoiding a designated term altogether, may help you achieve more positive results.

It’s also important to help stakeholders understand that if they want the flexibility to work from any location, we need a new level of security. We need to devise a way to make the wine more accessible to the authorized people, but just as safe.

What Change Looks Like

Once stakeholders comprehend the need for change, we can then move on to explaining how things will change.

Going forward, every user must be authenticated, authorized, and continuously validated for security configuration. Translation: we’re replacing keys with a keypad. You can only get a code once you’ve proven your identity, and that code is specific to you for that visit. When you’re done, so is that code.

With Zero Trust, it’s important to minimize the impact should a breach occur. Translation: your code won’t give you access to the entire cellar, just to what you need. Don’t drink whites? You’ll only see the reds when you enter.

Zero Trust architecture requires continuous monitoring and validating that the user and their device have the right privileges. Translation: when you visit the cellar, the wine cellar manager is going to keep tabs on your visit to make sure wine selection is occurring as it should.

Achieving That Change

With a better understanding of the “why” and the “what,” you can delve into the “how.” In our world, it is natural to want to explain everything that will need to happen, at a technical level, to implement Zero Trust. I advise against this. Stakeholders are primarily concerned with how the change will affect them and their business process and how long it will take.

With an organization as large as Bridgestone, explaining the “how” is a massive undertaking, but it is in our interest to invest the time and energy to outline the pertinent process touchpoints for each group, whether segmented geographically or by business unit. This encourages acceptance and limits disruptions that individuals had not anticipated because of a lack of clarity.

Initiating the Change

In information security, we want to jump right in, but this is a process that warrants patience and planning.

Naturally, not every organization is as attuned to extensive processes. This is why I encourage companies to tailor the Zero Trust conversation and implementation to their organization’s culture. Zero Trust requires a thoughtful approach and widespread buy-in to protect your most precious data. Since technology is constantly developing, the Zero Trust model is not a final destination, but if you frame it right from the outset, you are more likely to achieve that most important of qualities along your journey – trust.


About the Author

Andy SobottaAndy Sobotta is Bridgestone’s Chief Information Security Officer (CISO). Sobotta is responsible for overseeing the protection of the company’s information technology assets, ensuring robust IT security architecture, operations, and compliance throughout the Americas. Sobotta has more than 20 years of experience as an information security executive, including nearly 10 years in the automotive industry. He most recently served as Chief Information Security Officer at Sensata Technologies, Inc., after four years as Senior Director of Global Information Security with Procter & Gamble. Andy also served as Chief Information Security Officer for Elavon/US Bank and was Chief Information Security Officer for Volkswagen of America.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

New Trojan ‘‘Android.Cynos.7.origin’’ Infects 9Mn Android Devices

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

Security researchers from Doctor Web have discovered a new Trojan that has infected over 9.3 million Android devices.

The Trojan, dubbed “Android.Cynos.7.origin,” is a new kind of malware that disguises itself as various mobile games on Huawei’s AppGallery marketplace.

Android.Cynos.7.origin Explained

Android.Cynos.7.origin steals information from a victim’s device, such as contact details, and displays unwanted ads. The researchers suspect that the Trojan is a modified version of the Cynos malware. The apps infected with Android.Cynos.7.origin ask users for permission to make and manage phone calls, allowing the Trojan to obtain more information such as location, mobile network parameters, and system metadata.

Also Read: How to Secure Your Mobile Apps

“The Android.Cynos.7.origin can be integrated into Android apps to monetize them. This platform has been known since at least 2014. Some of its versions have quite aggressive functionality: they send premium SMS, intercept incoming SMS, download and launch extra modules, and download and install other apps. The main functionality of the version discovered by our malware analysts is collecting the information about users and their devices and displaying ads,” the researchers at Doctor Web said.

Information Collected  

When the user grants permission, Android.Cynos.7.origin collects and sends the following data to a remote server:

  • User mobile phone number
  • Device location based on GPS coordinates or the mobile network and Wi-Fi access point data (when the application has permission to access location)
  • Various mobile network parameters, such as the network code and mobile country code; also, GSM cell ID and international GSM location area code (when the application has permission to access location)
  • Various technical specs of the device
  • Various parameters from the Trojanized app’s metadata

Also Read: How to Spot Malicious or Fake Apps

The Android.Cynos.7.origin was found in 190 games like simulators, platformers, arcades, strategies, and shooters. Some of these games target Russian-speaking users, and other games that target Chinese or international audiences.

“At first glance, a mobile phone number leak may seem like an insignificant problem. Yet in reality, it can seriously harm users, especially given the fact that children are the games’ main target audience. Even if the mobile phone number is registered to an adult, downloading a child’s game may highly likely indicate that the child is the one who actually using the mobile phone. It is very doubtful that parents would want the above data about the phone to be transferred not only to unknown foreign servers but to anyone else in general,” the researchers added.

Apple Files Lawsuit Against NSO Group for State-sponsored Surveillance

Apple sues NSO Group

Israel’s cyber intelligence and surveillance company NSO Group is once again in a legal row.

On November 23, 2021, Apple stated that the company has filed a lawsuit against NSO Group and its parent company to hold it accountable for the surveillance and targeting of Apple users.

“The complaint provides new information on how NSO Group infected victims’ devices with its Pegasus spyware. To prevent further abuse and harm to its users, Apple is also seeking a permanent injunction to ban NSO Group from using any Apple software, services, or devices,” Apple said.

NSO Group is a developer of spyware for mobile devices. The firm is known for the development of Pegasus software that targets mobile phones to gather information and provides authorized governments with technology that helps them combat terror and crime.

Background

In August 2021, NSO Group was trending on all media platforms for misusing the Pegasus spyware. Pegasus was at the core of a major surveillance campaign reported by 17 media organizations led by the Paris-based group, Forbidden Stories and Amnesty International.

Per reports, 50,000 phone numbers, primarily belonging to journalists, government officials, and human rights activists across the globe, were put under surveillance, violating the basic human right of privacy.

Apple expressed, “NSO Group creates sophisticated, state-sponsored surveillance technology that allows its highly targeted spyware to surveil its victims. These attacks are only aimed at a very small number of users, and they impact people across multiple platforms, including iOS and Android.”

“State-sponsored actors like the NSO Group spend millions of dollars on sophisticated surveillance technologies without effective accountability. That needs to change,” said Craig Federighi, Senior Vice President of Software Engineering, Apple.

Cybersurveillance Research

As an appreciation to research companies like Citizen Lab, Apple has announced a funding of $10 million towards organizations pursuing cybersurveillance research and advocacy.

“Mercenary spyware firms like NSO Group have facilitated some of the world’s worst human rights abuses and acts of transnational repression while enriching themselves and their investors,” said Ron Deibert, director of the Citizen Lab at the University of Toronto.

The spyware has been termed as a direct abuse of human rights and violation of federal laws.

In October 2021, the U.S. Commerce Department’s Bureau of Industry and Security had announced a ban on the export of cybersecurity tools and solutions that are used for espionage and surveillance.

The Facebook-NSO Lawsuit

In October 2019, Facebook sued NSO Group for violating the Computer Fraud and Abuse Act. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp-installed mobile devices in April and May 2019.

Would the Orwellian approach abate or exacerbate? Only time will tell.

E-Skimmers Prey on Online Shoppers Amid Black Friday and Cyber Monday

e-skimming attacks , Chinese e-commerce scammers

While online shoppers are excited to grab the lightning deals, opportunistic cybercriminals are preying on exploits to compromise websites and steal data. The U.K. government has recently warned about Magecart actors targeting online businesses via e-skimming attacks.

The National Cyber Security Centre (NCSC) in the U.K. stated that cybercriminals exploit unpatched vulnerabilities in various e-commerce websites and inject malicious codes. It has identified over 4,151 compromised online shops up to the end of September and alerted retailers to these security vulnerabilities.

Also Read: How to Stay Digitally Safe This Black Friday and Cyber Monday

Hackers E-Skimming on Black Friday and Cyber Monday Deals

In e-skimming, hackers initially exploit a vulnerability in software used at the checkout page on shopping sites and deploy a malicious code that diverts payments and steal details of unsuspecting customers. Magecart hackers mostly perform e-skimming attacks. The attackers either sell the stolen card data on the darknet or use it to make fraudulent purchases.

E-Skimming Attack

Most of the affected e-commerce sites have been compromised via a known vulnerability in Magento – a popular e-commerce platform that allows websites to create their own online store.

Also Read: 3 Common Online Frauds to Watch Out in 2022

The NCSC stated that small online retailers could increasingly be targeted during the Black Friday and Cyber Monday shopping days. The agency urged online businesses in the country to update their software to avoid financial and reputational damage.

How to Mitigate E-Skimming Risks

  • Perform regular updates to payment software
  • Install patches from payment platform vendors
  • Implement code integrity checks
  • Keep anti-virus software updated
  • Monitor and analyze weblogs
  • Always have an Incident Response Plan

In addition, online businesses must boost their overall website security to prevent malicious code injections and hacker intrusions.

Commenting on the ongoing attacks on e-commerce businesses, NCSC Deputy Director for Economy and Society Sarah Lyons said, “We want small and medium-sized online retailers to know how to prevent their sites from being exploited by opportunistic cybercriminals over the peak shopping period. Falling victim to cybercrime could leave you and your customers out of pocket and cause reputational damage. It’s important to keep websites as secure as possible, and I would urge all business owners to follow our guidance and make sure their software is up to date.”

The Chancellor of the Duchy of Lancaster, Steve Barclay, said, “On Black Friday and Cyber Monday, the hackers will be out to steal shoppers’ cash and damage the reputations of businesses by making their websites into cyber traps. It’s critical, with more and more trade moving online, to protect your business and your customers by following the guidance provided by the National Cyber Security Centre and British Retail Consortium.”

Being Compliant Gives Organizations a False Sense of Security

While cybersecurity awareness is improving within organizations, they are failing with threat protection because they are unaware of the threats they are facing in the context of their business and employees. In a video interview with Brian Pereira, Editor-in-Chief, CISO MAG, Ditmar Tavares, Senior Cybersecurity Consultant, Mariner Innovations, breaks this down for us and elaborates on the areas where organizations are falling short.

Tavares sees organizations changing their awareness, thanks to the incidents reported in the news. He says most of them are taking steps to be more secure. He breaks down cybersecurity awareness into two portions: being aware of the field, which he considers “pretty good” as everybody knows what it is and what they are concerned about.

The second part of it seems to be a problem — how well organizations know about the treats they are facing, specifically based on what they do, the risk that they are introducing with the actions they take, with the data they are collecting — or even with the social media posts their employees are doing.

He believes risks are introduced with the third-party organizations they do business with. That is where most organizations are falling short. He wishes they knew what matches their needs, gaps, and what they need to do and tailor to their expectations.

CISO MAG Experts Series

CISO MAG interviews CISOs and cybersecurity experts from all parts of the world. Do read their opinions or watch their videos on cybersecurity awareness and incident response by following the links below.

“The State of Readiness Will Always Be in a Flux”

For Dr. Imtiaz Abdul Kader, CEO, Perfected Execution, there are two core elements to cybersecurity awareness and readiness. One is the training and the skills, and the other is partnerships within the industry.

“Security is Everybody’s Business”

Everyone in the organization is a security leader and is responsible for security, says Dr. Frank E. Ofori, Cyber Security Specialist and former U.S. Army Veteran.

Expert’s Take: Why Organizations Fail to Prepare for Cyberattacks

Le Nguyen Truong Giang, a Global Security Operations Lead and Security Transform Consultant, speaks to CISO MAG about cybersecurity awareness, resilience, and failure to prepare for cyberattacks.

Cybersecurity Awareness Month 2021: Here’s What the Experts Have to Say


About the Interviewer

Brian Pereira

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

More stories from Brian

GoDaddy Discloses Security Breach; Data of 1.2 Mn WordPress Users Exposed

GoDaddy

GoDaddy, a domain name registrar and web hosting company, disclosed a data breach incident which exposed the data of 1.2 million customers.

A disclosure published by the company notified that in an incident discovered on November 17, 2021, an unauthorized third party had accessed the company’s Managed WordPress hosting environment.  The unauthorized access was immediately blocked on detection, and a forensic investigation was initiated.

“Using a compromised password, an unauthorized third party accessed the provisioning system in our legacy code base for Managed WordPress. Upon identifying this incident, we immediately blocked the unauthorized third party from our system. Our investigation is ongoing, but we have determined that beginning on September 6, 2021, the unauthorized third party used the vulnerability to gain access to our customer information,” stated, Demetrius Comes, Chief Information Security Officer, GoDaddy.

Customers Affected

The notification shared the following customer information:

  • Up to 1.2 million active and inactive Managed WordPress customers had their email addresses and customer number exposed. The exposure of email addresses presents a risk of phishing attacks.
  • The original WordPress Admin password that was set at the time of provisioning was exposed. If those credentials were still in use, those passwords were reset.
  • For active customers, sFTP and database usernames and passwords were exposed. Both passwords have been reset.
  • For a subset of active customers, the SSL private key was exposed. We are in the process of issuing and installing new certificates for those customers.

Interestingly, GoDaddy has a help page for “My website was hacked. What should I do?”, listing warnings and best practices to abide by.

The company also disclosed a breach last year, in May, and alerted some of its customers that an unauthorized party used their web hosting account credentials in October to connect to their hosting account via SSH.

GoDaddy’s security team discovered that incident after spotting an altered SSH file in GoDaddy’s hosting environment and suspicious activity on a subset of GoDaddy’s servers.

GoDaddy is one of the world’s largest domain registrars and a web hosting company providing services to more than 20 million customers worldwide.

In a blog post on krebsonsecurity.com, Brian Krebs blogged about how fraudsters redirected email and web traffic destined for several cryptocurrency trading platforms and the attacks were facilitated by scams targeting employees at GoDaddy.

How to Stay Digitally Safe This Black Friday and Cyber Monday

Black Friday

The onset of the festive season drives the retail market into a frenzy. After two years of being home-ridden and extra cautious due to the pandemic, people worldwide are finally venturing out and once again feeling the true spirits of the season and unrestrained celebrations. The enthusiasm to strike the best bargain at Black Friday deals is fueling online sales globally. Online retail spikes, with sales expected to go up from $34.36 billion in 2020 by 5.9% to $36.40 billion this year.

By Minu Sirsalewala, Editorial Consultant, CISO MAG

The retail sector is a soft target for cybercriminals, especially the small organizations and third-party services like logistic and delivery companies who experience incessant attacks. Scammers and cybercriminals are scouting for banking credentials and debit/credit card details, thriving in the online space given the retail fever and are waiting to prey with Hawk eyes. As security implementations for these organizations are neither affordable nor feasible, they are most vulnerable and easy prey to the financially motivated cyber hawks.

Per Adobe 2020 survey, the Black Friday 2020 revenue sits at $188.2 billion compared to 2019 revenue of $142.4 billion.

Common Digital Threats 

1. Phishing Attacks

Phishing attacks continue to be the most common threat in the security landscape. Cybercriminals are leveraging advanced phishing and social-engineering techniques to trick users and break into networks. There are constant baits in the form of emails, attachments, malicious links, and pop-ups that should be closely scrutinized for authenticity before being clicked.

2. Fake Deals

Scammers are “spraying and praying” where a barrage of attractive deal ads, messages, coupons, and fake websites are made available online to bait customers into falling prey to these scams. If it is too good a deal to believe, be alert and rule out a possible scam.

3. Data Skimming

Injecting e-skimmers or malicious JavaScripts on e-commerce sites to pilfer payment card details is commonly used by Magecart operators. Through this technique, the attackers gain access to users’ login information like usernames, passwords, payment card information like credit card numbers, and personal information like names, dates of birth, and email addresses.

4. Financial Malware

Cybercriminals often find new techniques to deploy malware and evade security scans. As per a report from Microsoft 365 Defender Threat Intelligence Team, adversaries are increasingly relying on HTML smuggling techniques in email phishing and malware campaigns to obtain access and infect a network or system with an array of malware variants. These include banking malware, ransomware, and remote access trojans (RATs).

Users unknowingly install malware onto their devices by clicking malicious attachments like images and links sent through special Black Friday online promotions.

Online Safety Measures for Black Friday and Cyber Monday

1. Watch Out for Fake Websites

Festive times are lucrative not only for the vendors but for imposters too. The appearance of fake websites selling non-existing products and tricking people into spending money is a common affair. A Check Point Research report revealed a 178% jump in the number of malicious shopping sites  — more than 5,300 sites each week in October compared to other months for 2021.

2. Check if the Site’s Connection is Secure

It is advisable to stick to familiar shopping sites and not get lured by new ads, emails, or text messages. Go with reputed names and not fly-by-night operators who appear only to scam users. A secure site’s URL should start with HTTPS and not HTTP. You might have to click on the URL to see the HTTPS. Another tip is to look for a little lock icon in the top left corner of your browser bar when you’re on the site.

3. Beware of Phishing Emails

Phishing continues to impact a high number of people. Beware of emails, attachments, links, and ads that may appear to be from renowned brands, e-commerce sites, and retailers but are fake. Verify the sender of the email by checking the email ID and re-read the content to check grammatical or spelling errors.

 Related story: How to Find a Phishing Email [INFOGRAPHIC]

4. Use Strong Passwords

Though asserted time and again, weak passwords continue to be a common threat and are easy to attack. Using a unique username and password is essential; one can use a password manager as it could be difficult to remember multiple passwords for different accounts. It is also recommended to have multi-factor authentication or two-factor authentication for an added layer of safety.

 5. Be Vigilant About Social Media Scams

Social media platforms like Instagram, Facebook, Twitter, and Pinterest are popular choices to send spam messages. People unknowingly forward and share links announcing great deals and bargains without crosschecking and are aiding in spreading the malicious links. These are amongst some of the most trusted platforms and are easy targets too.

 6. Avoid Public Wi-Fi

Public Wi-Fi networks are not secured and do not require secured authentication to log in and give direct access to any unsecured device on the same open network. It is a sea of opportunities for hackers to steal critical information such as login passwords, credit card info, and other personal and financial details. Public Wi-Fi can also be used to launch malware attacks and infect your device.

 7. Manage System Updates

Regular updates and patch management are the most simple and effective routines to follow to keep the system secured. Most common attacks are launched through bugs in the software and devices.

8. Use a Credit Card for Shopping Online

Using a credit card in place of a debit card, banking transactions, and direct payments are advisable. It allows a small window to cancel the transaction if it is fraudulent and stops further payment. It is also better protected in terms of authentication. Another tip: Request your bank to lower the credit limit on your card, so that if it is misused, the loss will not be on the higher side.

9. Monitor Bank Statements for Fraudulent Activity

Do not wait for the month-end or post-shopping season to check your financial transactions. It is advisable to keep a close eye on your online transactions and if you see any unauthorized activity, report it immediately.

Tessian a security company offers the following tips and advice for spotting malicious emails:

  • Inspect emails and text messages to look out for spelling errors; these are a sure sign that it is not from a legitimate source.
  • Take a few seconds to verify that the sender’s name and email address match up, especially if you are reading your emails on your mobile. Cybercriminals typically spoof a brand’s name in the hope that you’ll fail to inspect the email domain.
  • Be wary of business messages from unknown numbers or numbers starting with a local area code such as +44, as these are regularly associated with scam texts.
  • If in doubt, don’t click. You can follow up with the delivery company or retailer directly if you have a question that needs to be answered.

Be safe and make the most of the festive season. Do not let cyberthreats and attackers take the sheen off your celebrations.


Minu

About the Author

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

Cloud Computing Is the Future and Here Are the Latest Trends

Cloud Forensics

In today’s world of hyper-connectivity enterprises are investing in hybrid Cloud solutions, PaaS systems, augmented reality, and open-partner ecosystems. If the past has taught us anything, it is to never underestimate the growth potential of cybercriminals. The coronavirus pandemic revealed what attackers are capable of and Google is leading the race by launching its second Cloud region in India.

By Oriyomi Fowler, Head, Information Security & Network Operations; Dangote Industries Limited

The Cloud holds the world’s cyberinfrastructures and global economies in place and Gartner had predicted that public cloud services would hike by 17% in 2020. It takes minutes for companies to slip up and leak highly sensitive data due to gaps in Cloud data protection and applications, which means business owners remain worried about governance, security, and compliance issues when choosing Cloud vendors.

Cloud is the New Normal. And That Motivates Adversaries

Cloud technology intertwines with our everyday lives and helps share experiences as people, cultures, and worldwide events. It is the hidden medium used to define and understand the world we live in for the better. However, the global pandemic forced businesses to migrate towards remote working models.

This means the reliance on Cloud solutions rapidly grew, except the security aspect was neglected. European Cybergang DarkSide fell under the FBI’s radar when it launched the Colonial Pipeline Attack on May 7, 2021, and forced the organization to shut down its operations by infecting servers with ransomware. A group of researchers from the Royal Holloway, University of London, discovered how Telegram bots could be manipulated and force chats to get reordered, meaning adversaries could now steal plain text from encrypted messages and find ways to “hack” the app. Despite Telegram offering the best End-to-End encryption via secret chats, this proved how threats can find ways to exploit emerging Cloud apps and services. Cloud is not equipped to handle insider threats, since trusted employees can drop off malicious codes to infect systems. And this is just the beginning.

Data governance is no longer a topic that can be ignored as CIOs, CEOs, and CISOs and business owners are on the hunt for Cloud platforms that offer reliability, functionality, and the responsible access of public and private cloud data.

Cloud security misconfigurations are the leading causes of data breaches and over 265,000 accounts were found misconfigured out of the 1 million that were surveyed across Southeast Asia. Cloudstar became victim to a highly sophisticated ransomware attack this year and its systems went completely offline when hackers hijacked a critical flaw found in their services. Unauthorized access to Cloud data, Distributed Denial of Service (DDoS) attacks, lack of secure APIs, and sensitive data leaks are the top Cloud security threats being faced by global organizations. Horangi stressed that businesses that weren’t using Cloud security platforms were at risk of lacking architectural visibility and future data breaches. He stated that there are many tools available for conducting security audits of these services that enterprises should take advantage of.

Is Cloud’s Future Bleak?

Nobody can predict the future but with the explosiveness of IoT networks and 5G, Cloud does have one. Today’s data surges in high volumes and Cloud infrastructures will be better equipped to handle copious amounts of processing at lower rates. Software development takes place from many different angles and modular software development will be prioritized by Cloud vendors. There will be improvements seen in Cloud service offerings within SaaS, IaaS, and PaaS sectors and many researchers predict that Cloud Computing will be the leading technology in the future.

Cloud vendors will be focusing on cyber security while developing apps/services and that means businesses should expect to enjoy a greater sense of reliability and privacy. With the advent of automation and virtualization, data processed on the Cloud will not require human intervention and security reviews or audits are expected to be automated by Artificial Intelligence by a huge margin as well.

PENTAGON, the U.S. Department of Defense, recently canceled its $10 million contract on a Cloud computing project that was subjected to a legal war between Amazon and Microsoft. The JEDI or Joint Enterprise Defense Infrastructure deal fell apart due to the department’s evolving requirements, and it said in a press release how a brand new multivendor Cloud contract was in the works which were dubbed, the “Joint Warfighter Cloud Capability.” Although JEDI is no more, the military services will undertake a new direction and work towards protecting national interests via the acquisition of commercial enterprise cloud computing technologies. DOD is currently doing market research and seeing if other Cloud vendors could fulfill its latest project requirements since Cloud adoption in the military is a complex affair tied to completing critical missions and addressing geopolitical concerns.

Cloud Gaming is taking a quantum leap and Microsoft is on track to conquer the gaming segment by introducing the latest updates to its Xbox Game Pass Subscription Services. Amazon Luna integrated Twitch, a popular videogame streaming, and broadcasting website, and provided 4k resolution support at 60fps for modern games, thus competing directly with Google’s Stadia and Microsoft xCloud. A prime example of how Cloud revolutionized not just gaming but the video streaming services industry is YouTube, a tech giant that massively scaled up in the last decade and how it improved its user experiences.

Cloud’s future is not bleak. It is just getting started.

Promising Trends and Moving Beyond Data

The big three dominating the Cloud hemisphere are Google Cloud Platform (GCP), Microsoft Azure, and Amazon Web Services (AWS) but they are certainly not the only ones who are emerging. Vertical Cloud Service Providers and SaaS platforms will become a part of corporate budgets and enterprises will be focusing their spending on public cloud solutions. Early Cloud trends started with the virtualization of computing resources via IaaS but with Cloud 2.0 where apps are being built with platform services in mind.

Because decision making is a critical part of business, enterprise owners will be heavily investing in automation technologies for deployment on the Cloud, such as Machine Learning (ML), Artificial Intelligence (AI), and Robotic Process Automation (RPA). 5G advancements are interlinked with Cloud computing developments and in the future, businesses will enjoy more speed, scalability, responsiveness, and data storage. A whole new market will open for private hybrid Clouds and enterprises who want to stay on-premises will choose to place their chips in Cloud edge computing.

The Cloud Computing market is forecasted to experience a growth of $287 billion by 2021-25 and data shows that more than 30% of spending by companies will be focused on developing Software as a Service (SaaS) based applications. According to the Synergy Research Group, SaaS will be dominating the Cloud landscape in the upcoming years with Microsoft holding up to 17% of market shares and leading the way. Salesforce and Adobe will come in a strong second and third, with Oracle taking up to 6% of SaaS market shares in the industry. There will be a giant scope for expansion for born-in-the-cloud vendors and traditional enterprise software vendors. Particularly, Gartner data shows that Infrastructure as a Service market will experience annual revenue growth of USD 32.4 billion or more worldwide, with five vendors namely – Amazon, Alibaba, Microsoft, Google, and IBM – dominating this sector.

Apple’s recent acquisition of Xnor.ai marked advancement in the realm of TinyML which has been hailed as a giant sea of opportunity for mitigating cyber threats. Mark Gene, CEO of Cloud Elements commented that companies are now moving into an era of seamless app integrations in Cloud ecosystems. Enterprises are connecting many disparate apps and harmonizing business processes by leveraging Cloud frameworks. Cloud offers a myriad of features and goes hand-in-hand with the Internet of Things (IoT) with vendors are focusing their efforts mostly on data mobility and native integrations.

Cloud Computing is also playing a significant role in the digital transactions space and Zeta Cloud offerings are revolutionizing core banking services. Cloud-based hospitality services minimized their operational costs by scaling down and 30% of spending by companies daily week by simply scaling up, despite the modern pandemic. Responsible AI is an emerging trend that shows promise with regards to trust, transparency, risk, scalability, compliance, ethics, and safety, according to Gartner reports. Although progress has been slow in this domain, companies stated that their innovations were mission-critical to their future success since responsible AI models tended to be less biased in making sound operational decisions. Vendors are working on developing granular security policies for platforms and increased data storage limits via scalable containerization.  Flexible data recovery and backup methods are another focus area for on-premises and cloud environments.

CIOs feel that subscription-based models contribute to business acceleration and growth in this age of digital transformation. Businesses are opting to use cloud platforms as a service instead of investing in off-the-shelf storage and data migration solutions. All-flash storage is an upcoming innovation in Cloud backup and recovery services that ensures business continuity in the event of ransomware attacks.

The top 5 public cloud companies surpassed their market cap in 2021 and made collectively over $1 trillion this year. Shopify and Zoom grew by 1.7x in total revenue and Paypal rose to third due to a rise in the number of contactless payments thanks to QR Code scanning systems. IDC predicts that global investments in public Cloud services will double to over $500 billion by 2023 and Deloitte’s revenue earnings will not drop below the 30% margin throughout the mid-decade. Enterprises will be unifying work environments through the optimization of hybrid clouds and the need for flexibility in these changing circumstances is becoming apparent to them. FAANG stocks ruled the market and gave 24x returns since 2010 but are now being overtaken by MT SAAS stocks as of 2020 due to explosiveness in Cloud technology growth.

According to a Gartner Cloud End User Behavior study, Cloud computing will become a key business driver by 2025 and all organizations will follow a Cloud-first principle when managing their data and operations soon. The exception to these are legacy IT applications and mainframe desktops which need not be migrated to the Cloud. Distributed Clouds will be used to run large workloads and address broad compliance issues by the end of 2025. Cloud computing will no longer be an option but the foundation and cornerstone of future businesses, especially for SMEs.

The Verdict

“Cloud computing has a bright future –and it is powerful, expansive.”

The benefits Cloud vendors will bring to the table will serve both customers and hosts as enterprises will be turning towards hybrid Clouds increasingly.  More than 93% of enterprises have a multi-cloud strategy, with 87% accounting for hybrid clouds. These numbers are expected to go up in the coming years and PaaS segments will enable multi-cloud serverless offerings to clients. Edge Computing is becoming mainstream and public cloud vendors are adapting to multi-cloud strategies, with open-source companies basing their business models on future cloud developments.

Trends in technology are way different from how they were in the earlier days and businesses are shifting to remote working models overnight. To cope with the challenges of the pandemic and rising client requirements, enterprises are investing in the latest Cloud computing solutions to deal with disruptions in the technology industry.

Cloud computing is becoming a top choice for technological innovation as players from healthcare, manufacturing, education, and gaming move their traditional IT infrastructures to the Cloud. AI will play a massive role in running and maintaining Cloud data centers in the future and businesses will increase demands in moving traditional systems to Cloud without the need to use pre-installed software. More users will prefer to work on virtualized desktops run on Cloud since these give centralized security, in contrast to physical desktops, and the flexibility in features and services will encourage increased adoption of virtual cloud desktop services.

It can be safely said that Cloud is here to stay and not flatline in its evolution anytime soon.


About the Author

Oriyomi FowlerOriyomi Fowler is a Technology Architect ad an Information technology (IT) professional with more than 12 years of experience. He also developed and deployed an automated tool-based vulnerability management framework that continuously monitors and detects Cybersecurity threats. He is specialized in risk assessment, disaster recovery, system integration, voice and network security, private cloud (Hyperconverge Infrastructure), IT Governance. He is also a member British Computer Society (MBCS) and Project Management Institute (PMI) membership.

He is a Global Advisory Board Member in EC-Council and Executive Member CyberEdBoard Community

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Vestas Cyberattack Impacts Internal IT Systems

Vestas

Vestas Wind Systems, a Danish manufacturer, seller, installer, and servicer of wind turbines, was a victim of a cybersecurity incident and had to shut down its systems across various locations to contain the spread of the attack.

A popular name in the sustainable energy solutions industry, Vestas, has over 25,000 employees across multiple locations. In a brief media release, the company shared that on November 19, 2021, it had been impacted by a cybersecurity incident. It had to shut down its IT systems across multiple business units and locations to contain the spread of the attack. Post a preliminary finding, Vestas updated that the incident had impacted the internal IT infrastructure and that data has been compromised.

Vestas stated, “There is no indication that the incident has impacted third-party operations, including customer and supply chain operations. Vestas’ manufacturing, construction and service teams have been able to continue operations, although several operational IT systems have been shut down as a precaution. Vestas has already initiated a gradual and controlled reopening of all IT systems.”

The company is yet to share the type/nature of the attack, the extent of the compromised data and if there is any threat from the lost data.

“We are working together with our internal and external partners to contain the issue fully and recover our systems,” Vestas said.

Critical Attacks

Attacks on essential services and critical infrastructure continue to make news. Colonial Pipeline attack is a recurring reference point to amplify the severity of cyberattacks on critical infrastructure. Regulatory bodies and policymakers have time and again issued alerts to create awareness and implement robust security policies for better protection of critical digital infrastructures globally. A few months ago, the U.S. House Committee on Homeland Security had passed seven bipartisan security bills to bolster defense capabilities, enhance pipeline security, and defend supply-chain attacks targeting U.S. organizations and critical infrastructure.

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStan Mierzwa, M.S., CISSP, Director and Lecturer, Center for Cybersecurity, Kean University expressed, “With the international attacks on electrical power infrastructure, the threat actor motives could be a timely opportunity for those with accountability in this critical sector to review their Information Governance (IG) programs. Like other such efforts that partake in steps of continuous improvements, an IG driver should not be considered static, but more of living energy.  To many, the idea of an IG program may seem vague – so as a brief reminder, IG programs include the ways an organization maintains its security, works to comply with regulations and laws in the respective industry, and maintains ethical standards (Smallwood, R. F. 2020).”

See also: U.S.-Russia Summit: Biden Tells Putin “Critical Infrastructure Should Be Off-limits” to Cyberattacks

Intel Processor Vulnerability Could Allow Enhanced Privileges to Unauthorized Users

MediaTek, Intel Processor Vulnerability, chip

Researchers at Positive Technologies recently discovered a flaw in Intel processors. The CVE-2021-0146 vulnerability enables testing or debugging modes on multiple Intel processor lines. This could allow an unauthorized user with physical access to obtain enhanced privileges on the system.

The vulnerability affects the Pentium, Celeron, and Atom processors of the Apollo Lake, Gemini Lake, and Gemini Lake Refresh platforms, used in mobile devices, embedded systems, and IoT systems, such as smart home appliances, cars, and medical equipment.

The threat affects a wide range of ultra-mobile netbooks and a significant base of Intel-based Internet of Things (IoT) systems, from home appliances and smart home systems to cars and medical equipment.

 What are the vulnerability details?

The Intel website published the following vulnerability details:

CVEID: CVE-2021-0146

Description: Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS Base Score: 7.1 High

CVSS Vector: CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Positive Technologies researchers said, in exploiting this vulnerability cybercriminals can:

  • Extract the encryption key and gain access to information on a laptop
  • Conduct targeted attacks across the supply chain

One example of a real threat is lost or stolen laptops that contain confidential information in encrypted form. Using this vulnerability, an attacker can extract the encryption key and gain access to the information within the laptop.

The bug can also be exploited in targeted attacks across the supply chain. For example, an employee of an Intel processor-based device supplier could extract the Intel CSME firmware key and deploy spyware that security software would not detect.

As acknowledged by Intel, the bug, which received a score of 7.1 on the CVSS 3.1 scale, was identified by Mark Ermolov, Dmitry Sklyarov (both from Positive Technologies), and Maxim Goryachy (an independent researcher).

Why and how did this happen?

CISO MAG reached out to Mark Ermolov, Lead Specialist of OS and Hardware Security at Positive Technologies, for his take on the incident.

According to Ermolov, errors of this kind happen because vendors often don’t consider that the debugging tools integrated into their products are a possible attack vector.

“Vendors believe that the physical access required to operate them puts such attacks ‘out of scope’ in their security models. However, the reality is that modern platforms contain, in addition to the confidential data of users, the secret data of the manufacturer itself (the so-called Assets) — when extracting these assets, the entire system can be put at risk, including the personal data of users,” said Ermolov.

Also see:

Qualcomm’s MSM Chips’ Vulnerability Affects 40% of All Mobile Phones

What should manufacturers and users do?

In an official press release Positive Technology said: “To avoid problems in the future and prevent the possible bypassing of built-in protection, manufacturers should be more careful in their approach to security provision for debug mechanisms.”

To fix the discovered vulnerability, users should install the UEFI BIOS updates published by the end manufacturers of the respective electronic equipment (notebooks or other devices).

“This is a firmware update, but unfortunately Intel does not explain which subsystem the patch affects. This could be a processor microcode update, power management controller firmware, Intel CSME firmware, or UEFI firmware. We do not know at the moment how exactly the error is fixed, but we are convinced that the error cannot be fixed at a fundamental level, since it is embedded in the hardware. It’s most likely that Intel has made a fix that simply prevents our Proof of Concept from working (which we sent to them with step-by-step explanations),” said Ermolov. 

How has Intel responded?

Intel is releasing firmware updates to mitigate this potential vulnerability. On its threat advisory page, Intel recommends that users of affected Intel processors update to the latest version provided by the system manufacturer that addresses these issues.

Meanwhile, laptop manufacturers using these Intel processors have started publishing firmware updates, and you should check the Drivers and Downloads sections on their websites.