Home Blog Page 369

Zingbox and Nuvolo create healthcare partnership to mitigate IoT cybersecurity threat

Internet of Things

GLOBE NEWSWIRE: Zingbox recently announced the availability of IoT Guardian’s integration with Nuvolo’s medical device cyber security platform. The integrated platform combines the ability to discover, secure, and optimize IoT devices together with a modern, cloud-based, single system of record for medical device inventory data. The integration addresses one of the biggest hurdles faced by healthcare providers today; how to streamline workflows to monitor, secure and optimize clinical assets. The combined solution delivers the seamless blending of a rich device data model with dynamic device profiles to identify threats and reduce risks.

“The integration of Zingbox and Nuvolo solutions deliver the benefits of real-time discovery, security and optimization of connected medical devices with the trusted source of medical device contextual data, workflow and orchestration,” said Xu Zou, CEO, Zingbox. “Our two companies deliver a simple deployment capability that addresses a pervasive and growing cyber security threat plaguing the healthcare industry.” 

Today, cyber security for network connected medical devices is one of the biggest threats affecting the healthcare industry as it continues introducing more devices to environments to support operations and patient care. According to Gartner, by 2020, the number of connected medical devices requiring hardening will increase by 45%.1 Zingbox’s own threat report reveals imaging systems account for more than half of all security issues related to connected medical devices. Many healthcare providers today rely on a guesstimate of devices deployed, unknown underlying security issues as well as multiple systems of record possessing non-standard naming conventions, fields, forms and location IDs that are outdated and potentially induce unwarranted risks.

“This integrated platform delivers an extraordinary set of capabilities to identify IoT threats and vulnerabilities, enable a rapid and informed response and proactively identify other at-risk devices in advance of being exploited. The enabler for these essential capabilities is access to contextual medical device data and orchestration capabilities that initiate, track and manage remediation activities in response to a threat. Trusted and reliable enterprise capability in these areas has not been attainable until now,” said Tom Stanford, CEO, Nuvolo. “The bi-directional integration with Zingbox offers a true enterprise solution that is easy to implement and reduces risk and liability for the healthcare system.”

Israeli startup Vulcan Cyber announces $4 million seed round

Startup Funding

Israeli cybersecurity startup Vulcan Cyber has raised $4 million seed funding from the YL Ventures. Among other investors was Giora Yaron, chairman of the Executive Council of Tel Aviv University.

Vulcan is known to work on decreasing vulnerability remediation gap, wherein it helps organizations to not only detect, but also timely address vulnerability with the resources provided to them to properly fix every weakness before the hackers jump to action, reducing the response time in resolving security issues to mere hours.

“Enterprises today are experiencing a state of continuous risk exposure,” said Yoav Leitersdorf, managing partner at YL Ventures, who led the Vulcan Cyber funding round. “This exposure is a board-level concern. The speed of change, innovation, the volume of constant probes and attacks has simply outpaced the tools and skilled resources IT security teams have. For many teams, it simply feels like they’re in a never-ending storm of crisis and reactive activities.”

Founded earlier this year, Vulcan is currently in limited availability and will be widely available in late 2018. “The team at Vulcan has the right vision to deliver IT security teams unprecedented insight and the ability and confidence needed to successfully eliminate exposure and risk. Vulcan has the potential to be transformative for enterprises, taking them from a state of continuous exposure to continuous protection,” Leitersdorf added.

Router malware targets at 500K networking devices worldwide, FBI issues warning

FBI, FatPipe MPVPN zero-day

The United States Federal Bureau of Investigation (FBI) has issued an alert suggesting that computer routers that connect U.S. homes and businesses to the Internet may have been infected by a foreign malware linked to Russian hackers. “The FBI recommends any owner of small office and home office routers power cycle (reboot) the devices. Foreign cyber actors have compromised hundreds of thousands of home and office routers and other networked devices worldwide. The actors used VPNFilter malware to target small office and home office routers. The malware is able to perform multiple functions, including possible information collection, device exploitation, and blocking network traffic,” the alert stated.

The size and scope of the VPNFilter malware may be significant. The malware can target routers manufactured by several makes, and the agency is currently unaware of the initial infection vector. According to the FBI, the malware can render small offices and home routers inoperable as well as collect user information while passing through the router. “Detection and analysis of the malware’s network activity is complicated by its use of encryption and misattributable networks,” it stated.

It asked the users to reboot the devices to temporarily disrupt from spreading as well as to identify the infected devices. “Owners are advised to consider disabling remote management settings on devices and secure with strong passwords and encryption when enabled. Network devices should be upgraded to the latest available versions of firmware,” it suggested.

The bigger concern that lingers is that according to Talos, the security arm of Cisco, nearly 500,000 affected devices may have been affected, as well the attack also sporadically spread in at least 54 countries. “More than half a million routers have been identified already as being compromised, so I think there are a significant number of devices that have been affected and it is difficult to estimate how many devices could be affected in the coming days or week,” Shuman Ghosemajumder, chief technology officer at Shape Security, told NBC News.

Talos stated that the devices affected by VPNFilter are Linksys, MikroTik, NETGEAR and TP-Link networking equipment in the small and home office (SOHO) space, as well at QNAP network-attached storage (NAS) devices.

Talos also pointed out that defending against the attack is very difficult due to the nature of the malware and affected devices. Most of these devices connect the computer directly to the internet. With no security in for the devices, having no built-in anti-malware capabilities, and also having publicly known vulnerabilities which are not convenient for the average user to patch makes it hard to counter and block.

We need increasing deterrence in cyberspace, says the new head of US Cyber Command

Cyberspace

Contributed by SecureWorld

Army Lt. Gen. Paul Nakasone is the new leader of U.S. Cyber Command and the top secret NSA, the National Security Agency.

After hearing the Secretary of Homeland Security warn digital foes about the use of cyber warfare at RSA, we wanted to know about the Lt. General’s views as he takes control of America’s cyber warfare capabilities.

Here are seven quotes he gave during his confirmation hearing that paint a picture of where he is coming from—and where the United States is going in cyber.

We need increasing deterrence in cyberspace

“I believe it is possible for actions in cyberspace to have a deterrent effect and contribute to the Nation’s overall deterrence posture. Effective deterrence requires a whole-of-government approach, however, and cannot rely solely on efforts in cyberspace. The current level and tempo of cyber attacks is not tolerable. Our adversaries see opportunity for strategic advantage through continuous activity in the domain. We must act purposefully to frustrate their intentions, increase their costs, and decrease their likelihood of success.”

Several red teams are defending Department of Defense systems against cyber enemies

“The Department has a robust, defense in depth approach that employs multiple capabilities at different levels in our networks and enables our defenders to generate tailored effects and mitigation strategies. Notably, the employment of DoD’s nine certified cyber red teams in a ‘persistent cyber opposing force (OPFOR)’ role, as well as the growing use of innovative ‘Bug Bounty’ programs in the Department, leads to the continuous testing and strengthening of our information networks’ defense.”

How to define U.S. cyber weapons

“Our network is our weapons platform.”

This is a ‘defining moment’ for the U.S. in cyberspace

“When I first started working cyber, operations were often just concepts, and when conducted, performed ad-hoc by technical specialists on loan from other organizations. Now, a mature and highly-capable Cyber force is built and in the fight, aggressively defending our network, conducting daily operations against adversaries, and strengthening the combat power and lethality of U.S. forces around the world. We are at a defining time for our Nation and our military. Near-peer competitors are posturing themselves, and threats to the United States’ global advantage are growing—nowhere is this challenge more manifest than in cyberspace.”

Big believer in agile

“I support the Agile approach to cyber capability development and support the Department transitioning from its traditional development process toward a more responsive and flexible approach. In today’s cyber environment, the traditional acquisition model delivers a solution to a problem too late to be operationally impactful.”

Who should defend privately owned critical infrastructure?

“This issue should not be viewed in a binary manner. We should look to help each other. For example, the Cybersecurity Act of 2015 facilitates the sharing of threat information in a bidirectional manner. While the responsibility for protecting privately-owned networks lies primarily with the system owner, the U.S. Government has the responsibility to defend national interests more broadly.”

China and Russia are America’s top cyber threats

“I consider China a strategic competitor, whose cyber capabilities pose a high threat to U.S. government and commercial networks. China is using its cyber capabilities to support intelligence collection against U.S. diplomatic, economic, and defense industrial base targets important to U.S. national security… China is a near-peer competitor in cyberspace.”

Russian: “As the most technically advanced potential adversary in cyber space, Russia is a full-scope cyber actor, employing sophisticated cyber operations tactics, techniques and procedures against U.S. and foreign military, diplomatic, and commercial targets, as well as science and technology sectors. Russia will likely continue to integrate cyber warfare into its military structure to keep pace with U.S. cyber efforts, and conduct cyberspace operations in response to perceived domestic threats. Also, Russian cyber actors’ have demonstrated the intent and capability to target industrial control systems found in the energy, transportation and industrial sectors.”

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same!

This article was originally published by SecureWorld.

Researchers create security framework to spruce up automotive cybersecurity

Automotive cybersecurity

Automotive cybersecurity is no longer an afterthought but something very similar to how organizations now consider information security. “20, 25 years ago people didn’t think of web browsers as needing security,” suggests Chris Valasek, one of the duo who remotely took controls of a Jeep Grand Cherokee in 2015, showing the world the need for automotive cybersecurity. “But now we know that a huge piece of end-user security is how secure the web browser is. This is where we are going with automobiles (…) Just like we saw with Microsoft and other software companies it’s an iterative process and it will get better over time. At one point Microsoft was the insecure operating system. Now they’re doing a really good job of it. So, it just takes time.”

Doctoral candidate at The University of Texas at San Antonio, Maanak Gupta and Ravi Sandhu, Lutcher Brown Endowed Professor of computer science and founding executive director of the UTSA Institute for Cyber Security (ICS) have now created an authorization framework for conceptual reviewing of key access control decisions and enforcement points for all kinds of interaction with the connected car. The proposed framework might be the key to determine what and where vulnerabilities of the car can be exploited. The team of ICS is now working on creating and using security authentication and authorization policies which would enable unauthorized access to the sensors of the cars.

“There are infinite opportunities in this new IoT domain but at the same time cyber threats will have serious implications in smart cars. Can you imagine if someone controls your car steering remotely, or shuts down the engine in the middle of the road?” Gupta said. “There should not be absolutely any open end to orchestrate attacks on these cars.”

Gupta also noted out that the authorization framework can also be applied to smart and driverless cars as these are not only driving the automotive industry of tomorrow but also highly vulnerable to cyber attacks.

“If we’re going to open the world to cars driven by machines, we must be absolutely certain that they aren’t able to be compromised by a malicious attack,” he said. “That it what this framework is for.”

In a first, Vermont passes law to regulate on data brokers

Vermont

Vermont has become the first state in the United States of America to pass a regulatory law on data brokers. According to the newly enacted bill (H.764) which has been passed into law without the approval of Gov. Phil Scott, seek oversight on how data brokers operate. Also, data brokers will have to pay a $100 annual fee to register with the state as well as comply with the new rules of the act.

One of the requirements imposed by the law is an annual $100 registration fee paid to the state. “While many different types of businesses collect data about consumers, a “data broker” is in the business of aggregating and selling data about consumers with whom the business does not have a direct relationship,” the draft bill suggested. “While data brokers offer many benefits, there are also risks associated with the widespread aggregation and sale of data about consumers, including risks related to consumers’ ability to know and control information held and sold about them and risks arising from the unauthorized or harmful acquisition and use of consumer information.”

The lawmakers have also “snuck in a little benefit for its residents that will remove the $10 fee required to freeze credit reports and $5 fee required to lift the freeze(…) The law also takes a very broad approach to defining data broker, which could open up a number of companies that make their bones in the data trade to new examinations of their business practice,” according to a Gizmodo report.

The law comes in the light of the recent breach at the credit reporting agency Equifax where the company potentially impacting approximately 145.5 million U.S. consumers. The stolen data included social security numbers, birth dates and addresses, and in some cases driver’s license numbers. The massive breach resulted in the stepping down of its CEO Richard Smith.

Hackers stole nearly $1.5 million from cryptocurrency startup Taylor

Cryptocurrency

Cryptocurrency startup Taylor recently fell victim of a cyber heist after hackers stole nearly S$1.5 million cryptocurrencies along with nearly seven percent of the total supply of its own TAY tokens.

The only tokens left with the startup are those belonging to the Founders’ and Advisors’ pool which were held in an inaccessible vesting contract. The company announced the incident though a statement recently.

At present the company is mulling on launching a “survival fund token sale,” or stop the project all together, stop working full-time on it, get funded by an angel investor or venture capital (VC) firm.

“It turns out we have been hacked and lost almost all of our funds. We now have only about US$25,000. To be honest, it doesn’t even pay this month’s bills,” Fabios Seixas, co-founder and CEO of Taylor, wrote. “This incident forced us to stop, step back and think about the future.”

The company has raised raised over  $1 million in its token sale earlier this year and was developing a “smart cryptocurrency trading assistant” that monitors major exchanges and performs technical analysis to find investment opportunities.

“We will probably not recover the stolen funds, but we have one of the most important assets a company can have: a strong community. This is the time for you, community member, to show your support towards such a difficult situation for all of us. We’re doing the best we can to overcome this unfortunate incident and grow even bigger and stronger, so your support is absolutely paramount to Taylor’s success,” the firm wrote in a statement. “We reassure that we will spare no efforts to find a way to mitigate the implications of this incident for every single legit token holder. We are not going anywhere!”

Cognitive security to drive the future of infosec

Altering certified PDF Documents, FIN7 Hackers

AI technologies and cybersecurity has already begun to drive the information security space forward. According to a study from ResearchAndMarkets.com the cognitive security market in IT and telecommunication is expected to reach $3.68 billion by 2023, with a compound annual growth rate of 30.36 percent.

For starters, cognitive security is the application of AI technologies spinning around on human thought processes to detect threats as well as securing digital and physical systems. “The increasing shift toward the use of cognitive security services for data storage of confidential and private data of an organization and the rise in employee mobility contribute to the need for cognitive security in IT & telecommunication,” ResearchAndMarkets.com stated in a release.

According to the research, the upward trend is driven by the spurt of cyber attacks, increasing migration toward the cloud, the proliferation of connected devices and the increasing popularity of bringing your own device (BYOD). While the major restraints were lack of common security platform, awareness about security solutions and the price of security solutions.

“With the increasing adoption of the cloud-based services in various business platforms, such as enterprise business, has led to the need to secure the information of organizations. The implementation of cloud-based cognitive security by small and medium enterprises is increasing rapidly and fuels the growth of the market,” the study points out. “Cognitive security is widely being adopted across diverse set of industries for the protection of crucial information that includes public safety and utility companies. An increase in the adoption of the cloud-based services and the Internet across the IT & telecommunication sector, the need to protect the data has rapidly increased.”

With opportunities in analytics, growth of machine learning and AI, cognitive security may soon retell the story of tomorrow.

Hackers siphoned $15 million from Mexican banks, withdraw most of it

Central Bank of Mexico

The central bank of Mexico recently notified that Mexican banks have suffered massive breaches where hackers may have siphoned $15 million from different banks through fraudulent transfers. The bank declined to name the banks but informed that there three banks, a broker and a credit union. It is still unclear how thieves managed to the pull the money out in cash.

Alejandro Diaz de Leon, the Governor of Bank of Mexico informed that authorities were still deciphering the activities of cyber criminals and are investigating the matter. According to him, preliminary estimates suggest irregular transactions amounting to $15 million. Some of which hasn’t been withdrawn and can still be recovered.

“Perhaps, some financial institutions perceived the attacks in Bangladesh as something very distant,” said Alejandro Diaz de Leon. He was of the opinion that several Mexican banks had poorly invested in cybersecurity. “But criminals look for vulnerability and once they see it they are going to exploit it.”

According to a Reuters report, “there were cash withdrawals from dozens of banks around the country shortly after hundreds of fraudulent transfers.”

Meanwhile, the Mexican central bank would be creating a cybersecurity unit to avert cyber attacks in the future. “The central bank said in a notice in the government’s daily gazette that the new unit would design and issue guidelines on information security for the country’s banks, which are supervised by the central bank,” stated a Reuters report.

All about Network and Information Systems Directive

4 in 10 Companies Expose Unsafe Network Services Online, network and security

As the European Union braces for some shelling with its GDPR can(n)on, there’s something for the Digital Service Providers and businesses, especially those in online operations, as well. The Directive on Security of Network and Information Systems (NIS), that precedes GDPR, will come into effect on May 10, 2018. The directive aims to create an even standard for network and data security for all member states.

What do we need to know about NIS?

The Directive on Security of Network and Information Systems (NIS) is meant for Operators of Essential Services (OESs) and Digital Service Providers (DSPs) within the EU along with Britain. The major commandments of this cybersecurity legislation are putting into practice pertinent information technology and networking systems, raising the risk management mechanisms to identify cyber potential threats, and adopting security measures to minimize or eliminate the impact of breaches without hampering service continuity. There’s also an additional ordinance of sending out an alert regarding any security breach which might culminate into something dangerous.

OESs include energy, finance and banking services, healthcare, transport and digital services, while DSPs are everything related to the Internet such as search engines, cloud computing, and ecommerce services.

What are the exceptions?

Digital Service Providers with annual turnover of less than 10 million, also considered as small and micro businesses, need not comply. Although the directive also applies to offshore businesses providing services within EU, they will enjoy some flexibilities.

Other things to know about

  • CSIRTs – Computer Incident Response Teams will be created under the NIS directive in all member states to help organizations get a clearer perspective about this new legislation and also the latest cyber threats.
  • NCAs – The EU member states are required to create National Competent Authorities to aid as the information center for organizations during any emergency or for clarification purposes.
  • Cooperation Group – In association with the EU Agency for Network and Information Security (ENISA), the member states have formed a Cooperation Group to promote adoption of effective cybersecurity measures among member states.

Indeed, there are penalties for not adhering to the NIS Directive as decided by the member states. The need to monitor and even provide entrée to the security measures being adopted by these service providers is also being discussed, though DSPs might get some relaxation in this regard. While the fame of Facebook is clouded by data privacy issues in the United States, it seems the clouds will soon start hovering over its European peaks too. Till then users need to be careful about the date being shared and the means of sharing it.