Home Blog Page 371

Cisco router flaw is the weak link that caused Iran cyber attack

CISCO

A flaw in the routers of Cisco Smart Install Client was misused by a group of cyber miscreants to bring down Internet services on a global scale. Over 200,000 router switches across the world were affected by this attack, of which 3500 were from Iran, according to the country’s official news agency IRNA. According to Iran’s IT Minister Mohammas Javad Azari-Jahromi, Europe, India, and the U.S. were among those countries affected by the attack. The screens of the hacked machines had an image of the U.S. flag with the message “Don’t mess with our elections.”

On April 5, 2018, Cisco’s Talos Intelligence group announced on its official blog, “As part of the Cisco Talos investigation, we began looking at how many devices are potentially vulnerable to this attack. The results were extremely troubling. Using Shodan, Talos was able to identify that more than 168,000 systems are potentially exposed via the Cisco Smart Install Client. This is an improvement from the reported numbers in 2016, when fellow cyber security firm Tenable reported observing 251,000 exposed Cisco Smart Install Clients. There may be variations in methodology between the scans, but this still represents a substantial reduction in available attack surfaces.”

The IT and networking company also acknowledged the existence of ‘specific advanced actors’ aiming at Cisco switches by taking advantage of the vulnerability in the routers. They also mentioned in the blog that these cyber heists are believed to have been carried out by nation-state actors, similar to those mentioned by United States Computer Emergency Readiness Team. The IT service-provider is taking all necessary steps and has advised its customers of the situation and all helpful measures to be taken. Cisco’s Product Security Incident Response Team (PSIRT) had issued a red flag in 2017 on the vulnerability of the active scanning design of Cisco Smart Install Clients. They had even released an open source tool to aid in identifying any tools that use the same protocol.

 

 

 

4 cybersecurity questions energy companies need to ask themselves

Energy

They are giants standing with their heads held high looking over the vantage point, possibly thinking they are still beyond reach but the sniper in his hoodie has already locked his target on them. The energy sector is not immune to cyber threats and the industry is coming to terms with this fact. The latest attack on a U.S. pipeline network on April 2, 2018 has raised concerns on the risk management scenarios of this industry. The U.S. department of Energy formed the Office of Cybersecurity, Energy Security and Emergency Response aka CESER in February 2018 to supervise the hovering cyber threats. The General Data Protection Regulation (GDPR) and the Directive on Security of Network and Information Systems (NIS) to be implemented in Europe, even accepted by Britain, is expected to empower and mobilize a strong cybersecurity infrastructure.

But is it up to snuff? The energy sector too needs to do its bit and ask itself these questions:

How robust is their data fortress?

Energy companies are generating and transmitting data like any other organization and every bit of it is crucial. Maintaining the confidentiality along with balanced and untampered flow of information requires well-defined data fortification. It is imperative to identify gaps in data security, check the operational support system and prepare guidelines to handle emergencies.

Who is monitoring your control systems?

Maintaining the grid stability especially for the digitally connected network requires well-integrated cybersecurity components. Many companies choose to outsource these network operation services. When choosing a service provider, they must take into account its expertise and experience. There’s also an insider threat looming over your critical data sharing and other operations. Your risk management strategy has to cover all these facets. The energy sector like its finance counterpart had been averse to technology for a long time, hence their traditional architecture still isn’t able to accommodate latest Information and Communications Technology (ICT) components.

Is there a balance between technical and human cyber competence?

An effective information security infrastructure requires not only advanced technology and equipment, but also an equally knowledgeable workforce. In most cases, the detection of a cyber-threat is the make or break factor. If the threat is detected at the right time, you can save the situation or the likelihood of your data being breached. You need a proficient cybersecurity partner or an able in-house team to help analyze, identify, and thwart off any threat before it endangers your business operations.

Are your aware of your cyber acts and rights?

There are lot of them being enacted now and there are some already in place. For the energy sector the devices used as well the technology infrastructure come with certain applied security standards. It is important that your cybersecurity team be acquainted with these components and their interoperability features and limitations in different environments because in some cases you might be operating according to international regulations.

Cryptojacking skyrockets to top of attacker toolkit: Symantec

Cryptojacking

Cyber criminals are rapidly adding cryptojacking to their arsenal and creating a highly profitable new revenue stream, as the ransomware market becomes overpriced and overcrowded, according to Symantec’s Internet Security Threat Report (ISTR), Volume 23.

“Cryptojacking is a rising threat to cyber and personal security,” said Tarun Kaura, Director, Enterprise Security Product Management, Asia Pacific and Japan, Symantec. “The massive profit incentive puts people, devices and organizations at risk of unauthorized coinminers siphoning resources from their systems, further motivating criminals to infiltrate everything from home PCs to giant data centers.”

Symantec’s ISTR provides a comprehensive view of the threat landscape, including insights into global threat activity, cyber criminal trends and motivations for attackers. The report analyzes data from the Symantec Global Intelligence Network, the largest civilian threat collection network in the world, records events from 126.5 million attack sensors worldwide and monitors threat activities in over 157 countries and territories. Key highlights include:

During the past year, an astronomical rise in cryptocurrency values triggered a cryptojacking gold rush with cyber criminals attempting to cash in on a volatile market. Detections of coinminers on endpoint computers increased by 8,500 percent in 2017. India ranks second in Asia-Pacific Japan (APJ) region, ninth globally in terms of crypto mining activities.

With a low barrier of entry – only requiring a couple lines of code to operate – cyber criminals are harnessing stolen processing power and cloud CPU usage from consumers and enterprises to mine cryptocurrency.Coinminers can slow devices, overheat batteries, and in some cases, render devices unusable. For enterprise organizations, coinminers can put corporate networks at risk of shutdown and inflate cloud CPU usage, adding cost.

“Now you could be fighting for resources on your phone, computer or IoT device as attackers use them for profit,” added Tarun. “People need to expand their defenses or they will pay for the price for someone else using their device.”

IoT devices continue to be ripe targets for exploitation. Symantec found a 600 percent increase in overall IoT attacks in 2017, which means that cyber criminals could exploit the connected nature of these devices to mine en masse. Macs are not immune either with Symantec detecting an 80 percent increase in coin mining attacks against Mac OS. By leveraging browser-based attacks, criminals do not need to download malware to a victim’s Mac or PC to carry out cyber attacks. India ranks among the top five countries as source for IoT attacks.

The number of targeted attack groups is on the rise with Symantec now tracking 140 organized groups. Last year, 71 percent of all targeted attacks started with spear phishing – the oldest trick in the book – to infect their victims. As targeted attack groups continue to leverage tried and true tactics to infiltrate organizations, the use of zero-day threats is falling out of favor. Only 27 percent of targeted attack groups have been known to use zero-day vulnerabilities at any point in the past.

The security industry has long discussed what type of destruction might be possible with cyber attacks. This conversation has now moved beyond the theoretical, with one in ten targeted attack groups using malware designed to disrupt.

Symantec identified a 200 percent increase in attackers injecting malware implants into the software supply chain in 2017. That’s equivalent to one attack every month as compared to four attacks the previous year.Hijacking software updates provides attackers with an entry point for compromising well-guarded networks. The Petya outbreak was the most notable example of a supply chain attack. After using Ukrainian accounting software as the point of entry, Petya used a variety of methods to spread laterally across corporate networks to deploy their malicious payload.

Threats in the mobile space also continue to grow year-over-year, including the number of new mobile malware variants which increased by 54 percent. Symantec blocked an average of 24,000 malicious mobile applications each day last year. India also featured amongst the top 10 list of countries where mobile malware was most frequently blocked in 2017. As older operating systems continue to be in use, this problem is exacerbated. For example, with the Android operating system, only 20 percent of devices are running the newest version and only 2.3 percent are on the latest minor release.

Mobile users also face privacy risks from grayware apps that aren’t completely malicious but can be troublesome. Symantec found that 63 percent of grayware apps leak the device’s phone number. With grayware increasing by 20 percent in 2017, this isn’t a problem that’s going away.

In 2016, the profitability of ransomware led to a crowded market. India ranks fourth globally with eight percent of global detections of ransomware. In 2017, the market made a correction, lowering the average ransom cost to $522 and signaling that ransomware has become a commodity. Many cyber criminals may have shifted their focus to coin mining as an alternative to cashing in while cryptocurrency values are high. Additionally, while the number of ransomware families decreased, the number of ransomware variants increased by 46 percent, indicating that criminal groups are innovating less but are still very productive.

As attackers evolve, there are many steps businesses can take to protect themselves. As a starting point, Symantec recommends the following best practices.

For businesses:

  • Don’t get caught flat-footed: Use advanced threat intelligence solutions to help you find indicators of compromise and respond faster to incidents.
  • Prepare for the worst: Incident management ensures your security framework is optimized, measurable and repeatable, and that lessons learned improve your security posture. Consider adding a retainer with a third-party expert to help manage crises.
  • Implement a multi-layered defense: Implement a multilayered defense strategy that addresses attack vectors at the gateway, mail server and endpoint. This also should include two-factor authentication, intrusion detection or protection systems (IPS), website vulnerability malware protection, and web security gateway solutions throughout the network.
  • Provide ongoing training about malicious email: Educate employees on the dangers posed by spear-phishing emails and other malicious email attacks, including where to internally report such attempts.
  • Monitor your resources: Make sure to monitor your resources and networks for abnormal and suspicious behavior and correlate it with threat intelligence from experts.

Cybersecurity skill gap: Japan faces massive shortage of network engineers

Tokyo

The recent hack at cryptocurrency exchange Coincheck Inc highlighted the need for cybersecurity in the region. The cryptocurrency exchange Coincheck lost 58 billion yen ($530 million) in what was dubbed as biggest cryptocurrency heist ever recorded. The website had to halt sales of almost all the cryptocurrency. But the buck didn’t stop there. Japan’s finance regulator Financial Services Agency instructed the company to improve its operations and to submit an incident report.

One of the reasons cited for the attack was the country’s lack of software engineers. According to a recent Reuters report, “no matter how hard” Coincheck tried, “it simply couldn’t hire workers with the skills to seal gaps in security.”

“We were aware we didn’t have enough people working on internal checks, management and system risk,” chief executive Koichiro Wada told Reuters. “We strived to expand using headhunters and agencies, but ended up in this situation.”

Coincheck isn’t the only company that has been marred by the massive skill gap of network engineers in Japan. While the financial regulators have issued a warning regarding lapse in proper internal control systems to several cryptocurrency exchanges and ordered them to improve their risk management practices, “The resulting shortage risks blunting Japanese exchanges’ competitive edge as the country’s cryptocurrency industry matures, experts say. And it could leave the industry exposed to more thefts,” the report pointed.

According to the report, there are 32 exchanges in Japan, with more than a 100 in the line to join the legion. Due to dearth of engineers, the market may soon stagnate. The report also quoted Alexander Jenner, a headhunter at Computer Futures in Tokyo, who believed the crypto exchanges are growing so quickly that there is a possibility of many companies failing in the future.

According to an EC-Council Survey, “The skill gap in the cybersecurity industry spans all levels, from CISOs to security analysts. It appears that the shortage of skilled professionals is not a problem that will be solved in the conceivable future. Most CISOs have several job openings yet to be filled and CISOs and the others involved in the recruiting process are looking for prospects with relevant certifications and experience. A major hurdle in the recruitment process is finding the right fit both with culture, personality, and experience that matches the job.”

 

Washington to ramp up election cybersecurity with omnibus spending bill

Washington

Washington State plans to revamp its IT infrastructure and strengthen its cybersecurity framework with the $7.9 million it will receive from the Election Assistance Commission (EAC) this year. The omnibus agreement of the Financial Services and General Government Appropriations Bill has issued a funding of $380 million to the EAC for making disbursements to states for improving the management of elections for Federal office, also encompassing enhancing the cybersecurity and technology standards.

Each state is assured to receive nearly $3 million, along with added population-based funding. The state of Washington will be contributing nearly $400,000 from their own end too. In September 2017, the Department of Homeland Security had also identified Washington among the 21 states that were targeted by Russian Hackers during the 2016 U.S. presidential elections. The targets of this 2016 cyberattack were voter-registration systems while vote-tallying software were reported to have not been affected. The upgrades will involve take over by paper-based machines against electronic voting machines, along with new systems and technology to take care of post-election audits. Washington Secretary of State Kim Wyman said, “With this funding, we’ll be able to bring new resources and technology together to improve our ongoing cybersecurity efforts.” The state has around three months to share their funding disbursement proposal with the EAC.

The 2018 Financial Services and General Government Appropriations Bill has given due attention to cybersecurity requirements. The General Services Administration (GSA) has been sanctioned $100 million for Technology Modernization Fund. the Office of Personnel Management (OPM) has been issued $290.0 milliom of which $21 million will be dedicated to IT security improvements in the department, also necessitating OPM to work with Office of Management and Budget, U.S. Digital Service, and the Department of Homeland Security to strengthen data protection for the prevention of future breaches.

OOC partners with Information Technology Authority on cybersecurity

Oman Oil Company

A partnership was announced between the Information Technology Authority (ITA) of the Arab Regional Cybersecurity Centre of ITU and Oman and Oman Oil Company (OOC) on Monday, April 2, 2018. Signed at the OOC headquarters, this partnership will allow OOC and its subsidiaries to avail cybersecurity services provided by ITA. Engineer Bader ALI Al Salehi, the head of Arab regional cybersecurity centre who is also the DG of Oman National CERT at ITA, signed the agreement with Saleh bin Abdullah Al Musalhi, the director-general of Human Capital, ICT and Supply Chain at OOC.

“Signing this partnership agreement is part of the initiatives adopted by the centre to promote cooperation with the private sector, particularly to enhance cyber security within the critical national infrastructure industry (CNIs)”, commented Al Salehi. “The partnership agreement aims to enable CNIs to benefit from the cyber security services offered by the regional centre to enhance cyber security readiness at CNIs, as well as engage Omani companies to contribute to the delivery of cyber security services.”

With this partnership, OOC will be able to reap the benefits of expert cybersecurity training services, along with gaining grounding in technical and focused aspects of information security as per internationally recognized standards. They will also gain insights into risk analysis and detection mechanisms with guidance on how to deal with vulnerabilities and reduce the impact of cyberattacks, when they occur. “Choosing ITA as a strategic partner is aimed at further enhancing our collaboration as a company with the government sector, as well as to learn and train from the best expertise in the market,” said Al Musalhi.

Al Salehi also pointed out that the partnership has been signed at a crucial time when CNIs, especially the energy sector is at the center of the malicious designs of cyber invaders. This partnership encompasses cybersecurity training and awareness programs, cyber threat and notification aids, security assessment services along with the convenience for OCC and its ancillaries to attend the regional center events.

Matthew Masterson becomes DHS senior cybersecurity adviser

Department of Homeland Security

Matthew Masterson has been appointed the senior cybersecurity adviser for the Department of Homeland Security, the department announced in a statement on Monday, March 26, 2018. Prior to this, he was serving as the Election Assistance Commission Chairman from December 2014 till February 2018. Masterson, who held the office of election official in Ohio, was also chosen for the post of commissioner by ex-Republican House Speaker John Boehner and even nominated by Barack Obama in 2014.

Masterson’s parting from his last held post in the EAC wasn’t exactly received well by many people, including Democrats, state election officials, and security experts. His name was proposed for reappointment but was dropped later.

Christopher Krebs, acting undersecretary of Department of Homeland Security’s National Protection and Programs Directorate, said: “There are few who have Matt’s experience working with all levels of government and the private sector to protect our nation’s election systems. Matt is one of the most equipped to advise on this non-partisan issue and will be an asset to the organization. In a time where technology is constantly evolving, it is more important than ever that DHS maintains productive and trusted relationships with our partners.”

Masterson plans to work toward enhancing the election security with regards to IT and cybersecurity. With the tainting of 2016 U.S. presidential elections by Russian hackers, stern cybersecurity measures are being adopted by EAC to prevent any interference in the upcoming midterm elections, to be held in November this year. President Trump passed a bill that provides around $400 million funding for strengthening the cybersecurity infrastructure and voting mechanisms.

Energy Transfer Partners reports cyber breach

Energy Transfer Partners cyber breach

A crucial U.S. pipeline network was the target of a cyber invasion on Monday, April 2, 2018. In a notice to its shippers, Energy Transfer Partners LP clarified that an Electronic Data Interchange (EDI) for their Panhandle Eastern pipeline system had been attacked by cyber crooks. This data interchange was handled by third-party Energy Services Group LLC for Energy Transfer. The company had to reportedly shutdown the system following the invasion although there was no news of impact on the flow of natural gas through the pipeline system.

However, later in the evening, they announced that it was safe to transfer files through the EDI platform, as the situation was under control. Energy Transfer spokeswoman Vicki Granado said, “This situation has not impacted our operations. We are handling all scheduling in house during this time.” She also confirmed that no data or operations were affected by the attack. Texas-based Energy Transfer is one of the biggest natural gas pipeline operators in the U.S., with investments in almost all types of energy portfolios. The company’s natural gas pipeline units encompass Panhandle Eastern Pipe Line Co., Transwestern Pipeline Co., and Rover Pipeline LLC.

Meanwhile, a joint alert from the FBI and Homeland Security Department issued in the month of March 2018 announced that critical sectors of the U.S. like the energy, nuclear, commercial facilities, water, aviation, and manufacturing were becoming the new targets of Russian cyber trespassers. This attack has once again brought Russia in the frame for carrying out cyber invasions to impact the U.S. economy.

Philippine’s financial institutions cautioned after Malaysia Central Bank counters cyber attack

Philippines

On March 27, Bank Negara Malaysia thwarted a cyber heist aimed at carrying out fabricated money transfers through the SWIFT messaging network. As a preventive measure post this incident, the Philippine Central Bank sent across a cautionary notice to all local financial institutions. A similar incident had sent a rude shock to the Central Bank of Bangladesh in 2016. It was a larceny of $81 million that raised questions on the rising power of hackers.

Although there were no financial losses during this cyber attack and payment services or bank operations were not impacted, the warning cannot be ignored. The Philippines Central Bank administers 45 commercial banks and they cannot afford another percussion similar to the Bangladesh Central Bank heist. The funds of the heist were directed into the accounts of Rizal Commercial Banking Corp (RCBC), a manila based firm which was fined $20 million by the Philippines Central Bank.

“We issued a general alert reminder as soon as we got BNM advisory to be extra careful over the long holiday. Although banks already do that as SOP (standard operating procedure),” said Bangko Sentral ng Pilipinas Governor Nestor Espenilla. The Governor also mentioned that information sharing is an enhanced defensive protocol against cyber-crime.

Saks and Lord & Taylor lose five million payment cards information to hackers

Lord & Taylor

Retail chains Saks and Lord & Taylor are the new sufferers of cyber waggery. The Hudson’s Bay Company that owns both these retail firms announced the cyber breach in a statement, “We have become aware of a data security issue involving customer payment card data at certain Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores in North America. We have identified the issue, and have taken steps to contain it. Once we have more clarity around the facts, we will notify our customers quickly and will offer those impacted free identity protection services, including credit and web monitoring.”

According to a cybersecurity research firm Gemini Advisory, a mischievous hacking ring by the name of JokerStash announced the sale of five million stolen payment cards information on dark web. Verification with different financial organizations led to the confirmation that the data belonged to Saks and Lord & Taylor. There is a confirmation of 125,000 payment cards data being stolen, however, there are no clear estimations available. Hudson’s Bay has specified that there is no threat to their online sales from any of the outlets. It is being assumed that the data theft was carried out by implanting a malware at the cash register systems of the stores.

JokerStash, which also goes by the name of Fin7, has already invaded some serious invasions which include names like Omni Hotels & Resorts, Trump Hotels, Chipotle and more. This cyber breach has added to the wounds of Hudson’s Bay already going through tough times.