Home Blog Page 381

1.7M emails and passwords compromised in 2014 Imgur hack

Imgur

Image hosting site Imgur, which later metamorphosed into a ‘meme haven’ for social media users, has apparently been subjected to a massive data breach. The hack which occurred in 2014 stole data from 1.7 million users, and Imgur has just discovered the incident.

The incident came to fore after ‘Have I been Pwned’ founder, Troy Hunt notified the company. “He (Troy Hunt) believed he was sent data that included information of Imgur users. Our Chief Operating Officer received the email late night on November 23rd and immediately corresponded with the researcher to learn more about the potential breach. He simultaneously notified Imgur’s Founder/CEO and Vice President of Engineering. Our Vice President of Engineering then arranged to securely receive the data from the researcher and began working to validate that the data belonged to Imgur users,” Imgur stated in a blog spot.

The data is believed to be a fraction of Imgur’s user base which usually sees the traffic of 150 million monthly users. The affected data may only include email addresses and passwords of the users as the site never gathered personally-identifying information (PII) like real names, addresses or phone numbers of the users.

The site is still investigating the incident, “We have always encrypted your password in our database, but it may have been cracked with brute force due to an older hashing algorithm (SHA-256) that was used at the time. We updated our algorithm to the new bcrypt algorithm last year,”

“I disclosed this incident to Imgur late in the day in the midst of the US Thanksgiving holidays,” said Hunt in an interview with ZDNet. “That they could pick this up immediately, protect impacted accounts, notify individuals and prepare public statements in less than 24 hours is absolutely exemplary.”

According to him, 60 percent of email addresses were already in Have I Been Pwned’s database.

Trust the cloud and carry your umbrella

Cloud Security

This article featured in a CISO MAG’s edition.

Contributed by Akamai Technologies.

As more and more companies begin to comprehend the benefits of cloud computing, its adoption is probably highest than ever before. According to the research done by Intel security, in 2016, hybrid cloud adoption has increased by three times within the organizations surveyed. The same set of organizations predicted that in the next 15 months, around 80% of all information technology (IT) budgets will be dedicated towards cloud solutions. As the cloud foothold expands globally, so does the attack surface. With more organizations showing trust in cloud technology, security still features as a top challenge that they would face.

Many studies and research conducted across the years focus on understanding the true nature of threats that target cloud infrastructure. If you pay close attention to these, you will realize that cloud is hardly the target, it is what lies within. That is your data and applications. This is not a new problem, this has and will always exist.

As more and more sensitive data moves to the cloud every day, we seldom realize that with disappearing boundaries appear new privacy and data protection laws. Interfaces and APIs, shared technology and multi-tenancy nature, identity management, lack of adequate encryption, etc., are some issues that have featured long in the list. Compliance is an ongoing concern for top executives, security practices of cloud service providers (CSPs) are often reviewed on papers but rarely audited by experts. Market prominence and word of mouth publicity play an influencing role in choosing the cloud vendor and most often flexibility and cost are given preference over security. Technical measures alone aren’t subnormal.

Legal contracts need to evolve for cloud nuances and risks as well. One of the factors that has been constantly undermined but more prevalent now is the lack of skilled security resources. Many organizations delay moving to cloud due to lack of appropriately skilled cybersecurity workforce. In-house IT teams aren’t equipped with the right tools and knowledge to fight newer battles on newer grounds.

Conventional security practices don’t hold good as your perimeter now extends beyond your sight. While cloud expands the attack surface and overall risks, organizations must truly understand that as business owners, they are still responsible to ensure that risks are addressed. It is essential not only to embrace cloud for business but also for security, it must become an integral part of the organizational security culture. Unfortunately, many organizations either don’t cover cloud as part of their security policy or have merely listed it. Like any other aspect of security, cloud security continues to limp without the right support of necessary governance practices. The prudent man rule applies to us more than ever. We are responsible and accountable for the security of our businesses, whether in cloud or within company premises.

Good news is that there is a silver lining behind the cloud. As the trust and mindset matures, security practices and awareness have grown as well. Many organizations worldwide actively carry out and participate in raising the cloud security awareness as well as standardizing the best practices to adopt for securing the cloud computing environment. Security executives should pay close attention to the following:

Security policy and governance framework: establish strategy and practices to support cloud security.

Empower security practitioners to be decision makers for cloud resources.

Audit the security controls: Don’t rely on the proof of cloud vendor’s security measures alone, have experts test and audit it. Third-party assessment is usually more beneficial. Audit them regularly.

Invest in building security skills: Train right and hire right. Many organizations now find managed security services as a valuable option to bridge the security skill gap by letting experts handle their security.

Redefine technical measures: Implement more robust technical measures such as storing encryption keys separately in the hardware. Companies like Akamai have pioneered this by building and securing separate key management infrastructure.

Focus on sensitive data: It is your priceless possession. Classify it and clearly define roles and accountability for safeguarding sensitive information stored in the cloud.

Insure your legal rights: Have the right legal and contractual clauses especially designed for cloud infrastructure. Ensure that it covers clauses regarding data security and privacy compliance.

Invest in the right tools: Beat the cloud with the cloud and not a sickle. A number of organizations find cloud security solutions to be effective, scalable and beneficial to their businesses. Costs should not be a challenge in the long run.

Redefine traditional risk assessment: Generic or traditional risk assessment frameworks have proven to be partially effective for cloud deployments. Risk assessment should consider cloud as an integral asset.

According to Gartner, 2017 will see a growth of 18% in the worldwide public cloud services. The expansion is inevitable and as security professionals, we all need to be ready for a rainy day. Do your due diligence, trust the cloud and carry your umbrella.

Demystifying Dark Web: An Organizational Point of View

From Data Breach to Darknet

This article featured in a CISO MAG’s edition.

Contributed by Souti Dutta, Lead Threat Analyst – SOC Services, Paladion

The Internet has become an “essential fixture” in people’s life. Apart from posting captured moments on Instagram, tweeting life’s experiences on Twitter, and browsing funny cat videos on YouTube, the Internet can allow you to travel beyond its surface to the deep, dark corners of the virtual world. Such corners are generally termed as the Dark Web.

In recent years, there has been an upsurge in interest and curiosity for the Dark Web. Frequent headlines on the existence of hidden marketplaces that serve as hotbeds of drugs, arms trafficking, fraud, hacking, etc., or the supposed freedom (anonymity) on the Dark Web have lured the common man into these dark virtual alleys.

The Dark Web has coexisted within the Deep Web (a segment of WWW that is opted out from being indexed and unavailable through regular search engines like Google, Yahoo, etc.) for years. It is a digital space, particularly, for carrying out malicious activities with the cloak of anonymity.

Is the Dark Web a growing concern for enterprises? 

A study has estimated that only 0.03% of sites on the internet fall under the Dark Web category, which are 30,000 or less sites. However, its growing popularity, ease of access and mass adoption have created serious concerns among security practitioners.

Anyone possessing a free piece of software like Tor can gain access to the Dark Web anonymously. In corporate environments, where thousands of employees access various IT resources, even a single exposure to the Dark Web can bring down defences. Below is a summarized list of risks accessing the

Dark Web using tools like TOR can bring:

Exposes an organization to malware and botnet attacks: Individuals/groups that operate ‘Exit Nodes’ or ‘TOR relays’ on a TOR network can abuse it by turning it to a malware distribution point without the knowledge of the employee using it. Thus, leaving an organization network susceptible to malware attack via received responses (wrapped with malware) from such rogue nodes. The Dark Web maintains CnC communication with the organization, which creates further risk.

Exposes an organization to DDoS attacks: If employees turn their hosts into nodes, which participate in the global Dark Web (e.g. Tor nodes) network, it can elevate the risk of bandwidth exhaustion or DDoS-like situation. The corporate network relaying large volume of Dark Web traffic is the primary reason for either high bandwidth consumption or bandwidth saturation.

Allows employees to bypass security controls: Traffic to the Dark Web is always wrapped in encryption, so monitoring of network traffic between the originator and the destination host is hard to crack. This means employees can freely view illegal sites, purchase contraband goods using corporate resources with ease, etc. In addition, it allows employees to circumvent several security controls without any extra effort.

Becoming the data exfiltration point: The ‘Exit Nodes’ are susceptible to sniffing attacks, so if non- encrypted data is out there, it can be captured and utilised in a malicious way. Internal  hosts participating in Dark Web activities can get infected with malware that exfiltrates data, leaving the organization susceptible to data theft.

Employees turning rogue insiders: A recent study noted a new trend among cybercriminals where they spend considerable resources to recruit insiders. The primary goal behind such recruitment is to steal data, plant malware, enhance domain knowledge, etc.

Loss of reputation: Organizations can be held responsible for any illegal activities carried out on the Dark Web especially hosting of Dark Web network nodes, which are involved in transporting illegal data or in activities such as hacking, DDoS attacks, spying, etc.

Blacklisting: An organization found hosting Dark Web nodes can risk its IP being added to an Internet blacklist, which can lead to unnecessary restrictions from various service providers.

Limiting Access to Dark Web from Inside the Business Network

Preventing access to the Dark Web and detecting instances can be a real challenge. There are currently no readymade solutions to monitor and stop such attempts. So, the solution lays in a combination of security best practices, technology, user awareness, and a refined security policy on usage of the Dark and Deep Web and associated applications. We’ve listed a few recommendations below:

Stop internal users from downloading, installing/running Tor: Tor (and other similar applications such as I2P) is the key to gain access to the Dark Web. Users should not have access to the Tor website from where they can acquire the installer or a portable version of the application. So, by deploying application whitelisting and limiting access rights, it is possible to prevent running such applications. Controls on USB ports should also be implemented to prevent running any portable instance of such applications.

Maintaining a known Dark Web/Tor node list: The primary reason behind maintaining a list of known Tor nodes is to limit any outbound traffic to the Dark Web. An explicit outbound connection deny to all such IPs (Exit Nodes) will minimize the live traffic destined to the Dark Web. It is also necessary to device an internal list of hosts who were involved in generating traffic to those IPs / nodes. It is also necessary to keep the node IP list relevant and updated. One can utilize available feeds to capture such IPs.

Outbound traffic containing self-signed certificate data: Dark Web is a known consumer of self-signed certificates (certificates not created by recognized certificate authorities). Such certificates allow data encryption between clients, nodes or servers. Hence, blocking such outbound SSL traffic will not only meet the best practice requirements, it will actively limit exposure to the Dark Web.

Clear Policy on Dark Web/Tor usage: Along with implementing security controls, it is important to ensure the corporate security policy talks about accessing the Dark Web and usage of proxy software (Tor). The updated security policy should clearly state the imposed limitations and prohibitions on the access of the Dark Web using proxy software over the corporate network and resources.

User Awareness: Organizations should conduct sessions where employees and partners that use IT services should understand the risks related to the Dark Web.

Conclusion

The curiosity around the Dark Web is obvious but if this discovery is made on a corporate network, it can make an organization vulnerable to cyber attacks. Employees unwittingly use the Tor network as a proxy to circumvent blocked sites, etc. It is important for employees to be educated about the risks such proxy software can bring to the organization to prevent risks the Dark Web can bring.

Organizations should also monitor all virtual activities by employees regardless of seniority or technical expertise within the corporate environment to ensure optimal cybersecurity.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Price List of Cybercrimes [INFOGRAPHIC]

initial access brokers

There are several moldering clichés surrounding the Dark Web, with the most common one signifying an iceberg with its tip as the surface internet, the shallow water surface as the Deep Web, and the unknown deep waters as the Dark Web. Let’s save the debate on the magnitude of the Dark Web for some other time.

By now, we all know the Dark Web is the underground internet which involves several illegal activities. And, most of these through special market sites which are often called the ‘darknet sites’. Here, illegal products like drugs and firearms, and even contract killers are available, all ready to be at your disposal for a few Bitcoins. Among a few other illegal products that are listed on the Dark Web is the price list of several cyberattacks, provided as a service. All you need to do is add your attack to your cart.

Add attack to cart

Click here to view the infographic on a full screen!

MSSP Shopping: Use your corporate AmEx wisely

MSSP Shopping

This article featured in a CISO MAG’s edition.

Contributed by Chris Roberts, Chief Security Architect, Acalvio Technologies

It’s worth noting that many of the Managed Security Service Providers (MSSPs) out there have their own take on what you should look for when selecting one, however, almost all of them require you to register on their site before they end up telling you to select their services with the exceptions being IBM, Trustwave, and Digital Guardian. These providers happily hand over their selection criteria without demanding your name, rank, and serial number.

So, let’s set the scene. The following are questions I find useful in guiding companies through a solid MSSP selection process. I have learned to ask many of these questions by working with clients through the horror of migrations-gone-bad.

  • Have you conducted an extensive evaluation of your security requirements?
    • Garbage in, garbage out. No MSSP is going to be able to untangle your mess if you don’t even know what you have AND where it is. Get organized BEFORE you commit.
    • If it’s not being logged in your environment, the MSSP isn’t going to miraculously find and deal with it.
    • No, they are not going to work out that Gladys in accounting has a local XLS spreadsheet with all the credit card numbers on it. Find ALL your data before you say “I do.”
    • No, they wont protect you from stupid. MSSPs are not going to be a silver bullet; they are another pair of hands that WILL help you, but you must still help yourself otherwise the relationship is doomed.
  • Do you understand the security measures with which you must comply?
    • Handing over the controls does not mean “passing the buck” in the realm of compliance. At the end of the day, if the worst happens and you are breached, it is you, not the MSSP, that’s on the stand giving testimony as to what went wrong.
    • Whatever you are required to have in place, your MSSP also must have in place – at a minimum. MSSPs really should have more given that they are a consolidation of everyone’s data and therefore much more of a target.
    • If your compliance is due to an auditing or governing body in Q1 and your MSSP leaves it until March 31st to get you a letter of compliance (or something similar), it’s not going to work. Setting realistic goals and deadlines for how your MSSP reports compliance is crucial – especially if you have deadlines to adhere to. Remember, a lack of planning on your part will not constitute an emergency on theirs.
  • Have you established a reliable governance model?
    • What happens when the MSSP finds something? Who is on point, who is on triage, who is going to get the call at 3 AM and which one of you is going to call the lawyer, the compliance officer, and presumably the spin doctors?
    • How much does your MSSP have to declare? If you’ve got someone inside the organization breaking the law and they find the evidence, who calls law enforcement?
  • Have you determined which security requirements you expect the MSSP to put in place?
    • Just because you managed to get rid of your logs, your alerts, and your local SOC/NOC, it doesn’t mean you are off the hook. How far does your MSSP take an issue, are they simply first line support, are they a 1-2-3 tier SOC/NOC, or what are the limitations of their capabilities?
    • Do they know who to wake up in the DBA team at 4 AM when root has just dumped the HIPAA database out to an FTP server in Brazil?
  • What are your criteria for success? Although “a good night’s sleep” is actually a relevant criteria for success it’s probably not the one you want to use as the board-level metric for success. Let’s take a quick look at some others.
    • Security maturity. Does having the MSSP in place advance your security maturity across any of the core criteria? (If you are looking at this and wondering what the heck a security maturity model is then we probably need to talk). If you can, by integrating an MSSP into your solution stack, increase the overall maturity from “repeatable/defined” to something like “managed,” then this is something worth considering doing.
    • If you are looking at stability within the enterprise environment and consolidating the various logging and monitoring solutions, then again, this is something that should be considered. But, as we’ve pointed out earlier, an MSSP is not going to come in, wave the magic wand, and rid you of all your legacy logging gear overnight. The migration project and the integration of THEIR chosen solution will take time and effort so make sure you plan, plan again, ask more questions, check the plan, and only then, sign on the dotted line. The age-old saying of “measure twice, cut once” is very relevant when it comes to any forms of outsourcing.

Now we’ve established that you (hopefully) know what you are protecting and how you want it protected, and you have a plan in place for evaluating your future MSSP. Let’s go shopping with the corporate AmEx.

The Seven Ps of MSSP

  • Broad portfolio of security services:
    • This might be one of those rare instances when you do want to put all your eggs in one basket. That sentence hurt to write but it’s going to be essential to find an MSSP that can consolidate your mess into something cohesive and usable. What you don’t want to do is add another layer of detachment into an already complex environment. It goes without saying that having a different MSSP for different areas within the enterprise is not going to work well, so compromise on things you can, select the MSSP that has the best overall architecture, solution, and services, and work with them across the entire spectrum.
  • Highly respected security intelligence and research professionals:
    • Part of the logic for getting an MSSP to look after you is that they do allow you to sleep at night but the only way that happens is if they are one step ahead of things. “One step ahead” doesn’t mean one step ahead of the bad guys, because we have a long way to go before we get there. What they should be is your eyes, ears, and early warning system, and for that they need good people—not just in the NOC/SOC watching your stuff, but good people with their finger on the pulse of the digital world. So select your MSSP accordingly.
  • Sophisticated back-end technology:
    • Your corporate AmEx is going to be a hit for the proverbial “six”, therefore, make sure you are getting your money’s worth. You want to make sure that your MSSP has not only the latest and greatest technology, but also a carefully selected a balance of reactive and predictive, proactive, preventative technologies to ensure the integrity of your environment as best as possible. And for once, give open source tools a chance here. Just because your MSSP has Oracle or IBM on the back-end, it doesn’t mean they are any good. Heck I’d go with a MicroCentre H/W with Hadoop and HBase any day if the coding and algorithms for detection and analysis were better, their client services shone, and they cared about you. Choose carefully and involve someone to help you ask all the nasty questions. Oh, and find an MSSP that works with multiple vendors, suppliers, partners, and solutions. That way you have the best-of-breed mentality at all times. The bottom line is to remember that the answer is not always Cisco or Palo Alto.
  • Excellent reputation:
    • This counts for a lot, but the focus here should be on satisfied clients. Don’t focus just on the ones they feed you but ones you can go out on your own and find. Time to brush off the OSINT skills and see who’s using them! Hit the conferences, hit the shows, and do your research. Yes, there will be unhappy customers, there always are. Keep in mind that a lot of them are unhappy probably because they believed in the magic wand. But do you own validation. This covers another point: reference clients. Find not only the happy ones but the annoyed ones, work out what is good, bad, and ugly before you do damage to the corporate budget.
  • Broad security infrastructure expertise:
    • This one almost goes without saying, but it’s in here because some clients have not done all their homework and get an MSSP to look after their log management, monitoring, and archiving, and then work out if they need a different MSSP to do their compliance, oh, and a third MSSP to do vulnerability assessment and remediation work. That’s never going to work. Best case, you have so much stuff going in so many different directions you sink into TPS reporting hell. Worst case, the vendor blame game happens when each of your MSSPs blames the other for whatever the problem du-jour is. Find an MSSP that can cover most or all your requirements, simple as that.
  • Robust, web-based management tool to improve visibility and intelligence:
    • Ok, so you’ve handed over all your data, your management, and basically given the front door keys to your chosen MSSP. How do you keep tabs on them, how do you now gain visibility into their world? What management, access, and controls do you and your team have? How easy is it to interface with both the humans and the chosen technology that is now protecting you? And, above all, when leadership and the board ask you to “justify and provide metrics” for your money, how are you going to do that with your new MSSP?
  • Financial stability:
    • Let’s keep this one simple. I don’t care if they are small up-and-coming or too-big-to-fail, everyone has a weakness when it comes to financial stability. Do your own risk analysis and go from there. You want your MSSP to be around longer than you are.
  • Your data is in their hands. How safe are they?
    • This is your data, it’s your a** on the line if it goes missing or ends up on a .RU website, so be aware of that when talking to your prospective MSSP. What PPCs do they have in place, what background checks, how often, what do they do with the people, the processes, the technology, how do they respond when you ask them all the nasty questions about how they keep people like me our of their systems? These days, attackers increasingly focus on vendors, partners, and 3rd parties as often they are easier and softer than walking through your front door.
  • Customer focused:
    • Nobody cares which restaurants or golf courses they took you too when the chips are down. The measure here is on a Sunday night over a holiday when all the red blinky lights start flashing, will you be able to get hold of enough people to keep you functioning, will you be able to recover inside the SLA timeframe and will your MSSP go above and beyond, not just because you have the biggest checkbook, but simply because to them you are more than just a number?
  • Global coverage (for that nice 24/7/365, even if Yellowstone goes critical type of coverage)
    • I’ll never understand why companies choose to put all their trust in an MSSP that has one data center 100 miles or less from Yellowstone or somewhere in California on a fault line or in the Gulf of Mexico etc. You get the idea. I told you to put everything in one place, but that one MSSP has to be distributed for your sakes. Get out the map, brush off the geography and geo-political analysis tools, and work out where your data’s going to be when the zombie apocalypse hits.

So, now you have the criteria for both analyzing what you want vs. need, what you can integrate vs. hand over, and who’s going to work best for you without relying on the magic-8-ball, i.e. Gartner. Good luck, may the force be with you, and reach out to me if you have questions! J

One last thing, and this one’s a doozy. When you’ve read this, ignored all the bullet points, and chosen your MSSP based on which golf course they took you to, then 18 months later you want to exit them, I hope you previously worked out who owns “your” data when you leave.

Winter has come for HBO hacker

HBO

“Winter has come for Behzad Mesri,” said US Attorney Joon Kim. “He will forever be looking over his shoulder. And if he isn’t, he should be.” Kim was addressing Behzad Mesri, also known as “Skote Vahshat,” an Iran nationalist, who has been indicted by federal prosecutors for hacking into American television HBO, a few months ago, and, demanded a ransom of $6 million. The hacker had leaked the then unaired episodes and scripts of popular fantasy TV series, ‘Game of Thrones,’ and several other TV series.

The total volume of data stolen wasn’t revealed, but according to several news agencies, it was believed to be around 1.5 terabytes.

“He will never be able to travel outside of Iran without fear of being arrested and brought here,” Kim said to Reuters. He described Mesri as an “experienced and sophisticated hacker who has been wreaking havoc on computer systems around the world for some time.”

Computer fraud, wire fraud, extortion and identity theft are the crimes that have been charged against Mesri.

“Over the next couple of months, he successfully compromised multiple user accounts in order to obtain access to the media giant’s servers,” according to a report on BBC. “Through the course of the intrusions into HBO’s systems, Mr Mesri was responsible for stealing confidential and proprietary data including… scripts and plot summaries for unaired programming, including but not limited to episodes of Game of Thrones.”

Post the attack press reporters were greeted with a mail that stated, “greatest leak of cyber space era is happening. What’s its name? Oh I forget to tell. Its HBO and Game of Thrones……!!!!!! You are lucky to be the first pioneers to witness and download the leak. Enjoy it & spread the words. Whoever spreads well, we will have an interview with him. HBO is falling.”

The incident had put HBO in a fix over maintaining the secrecy of the plot of its most valuable property, “Game of Thrones.” The TV channel had already faced a similar issue back in 2016, when the first four episodes of the fifth season of the series were leaked, which led to the company’s decision of not sending any advance screeners before the original broadcast.

The hack was termed as “disruptive, unsettling, and disturbing” by HBO Chairman Richard Piepler. The channel issued a statement saying, “HBO recently experienced a cyber-incident, which resulted in the compromise of proprietary information. We immediately began investigating the incident and are working with law enforcement and outside cybersecurity firms. Data protection is a top priority at HBO, and we take seriously our responsibility to protect the data we hold.”

EC-Council CEO Jay Bavisi moderates session at GCCS 2017

GCCS 2017

Mr. Jay Bavisi, the Chief Executive Officer of E-Commerce Consultants Private Limited, and Chairman of the Board, EC-Council University, on November 24, 2017, moderated a panel discussion titled “Cyber Behaviour: Evolving Best Practices for Netizen” during the Global Conference on Cyber Space (GCCS) 2017 in Delhi, India. The two-day event is in its fifth edition and it was flagged off at Pullman Hotel, Aerocity, in New Delhi, on November 23, 2017.

The elite panel consisted Mrs. Aanchal Gupta, Director, Facebook, Mr. Arvind Gupta, Founder, Digital India Foundation, Dr. C. Mohan, IBM Almaden Research Center, Dr. Dorit Dor, Vice President, Check Point Software Technologies, Prof. Jeanne Holm, Chief Technical Officer, City of Los Angeles, and Mr. Richard David Spearman, Director, Vodafone.

GCCS 2017 focuses on policies and frameworks for inclusivity, sustainability, development, security, safety and freedom, technology and partnerships for upholding digital democracy, maximizing collaboration for strengthening security and safety and advocating dialogue for digital diplomacy. The event is hosting over 50 ministerial delegates, more than 3000 industry delegates participating from nearly 120 countries, making it one of the biggest International conferences on Cyber Space.

The theme for the action-packed event is “Cyber4All” with four prominent sub-themes i.e. Cyber4InclusiveGrowth, Cyber4Digitalinclusion, Cyber4Security, and Cyber4Diplomacy.

 

Uber-SoftBank deal left in lurch after infamous hack

Uber

Two days after it was discovered that Uber paid hackers $100,000 to keep a massive data breach a secret, it has been reported that ride-service provider investors are enabled to sell their shares to SoftBank Group Corp. Reuters reported that a stock sale advertisement appeared in the New York Times, allowing the investors to sell their shares to the Japanese investor.

In October 2017, Uber had announced a preliminary deal for the SoftBank investment. After the hacking scandal, Softbank is yet to make a final decision on whether to renegotiate with Uber as it may seek better terms on the proposed multi-billion-dollar investment, Reuters reported.

Uber has been reportedly in talks with SoftBank Group for fresh investment worth up to $10 billion. On November 12, 2017, Uber had given a statement saying “we’ve entered into an agreement with a consortium led by SoftBank and Dragoneer on a potential investment.”

Rajeev Misra, CEO of SoftBank’s $93 billion tech investment fund, told Bloomberg that the company could walk away if Uber shareholders demand too much. “By no means is our investment decided. We are interested in Uber but the final deal will depend on the tender price and a minimum percentage shareholding for SoftBank”, he had said.

On November 21, 2017, Uber acknowledged that the personal information of about 57 million accounts was compromised in a hack that took place in October 2016. Immediately after learning about the data breach incident, the company fired its chief security officer Joe Sullivan and deputy Craig Clark for concealing the incident.

However, the former CEO of Uber Travis Kalanick, who still remains a significant shareholder, came to know about the breach within a month in November 2016, but he reportedly chose not to share the incident with fellow board members.

Saying that Uber will learn from its mistakes, Dara Khosrowshahi, the present Uber CEO revealed in a blog post that “the stolen information included names, email addresses and mobile phone numbers of Uber users around the world, and the names and license numbers of 600,000 U.S. drivers.”

Khosrowshahi said that his company has hired Mandiant, a cybersecurity firm owned by FireEye, to investigate the hacking incident.

Retail industry is leaving the backdoor open: Survey

Retail store

In the backdrop of Black Friday and the ensuing holiday season, security ratings firm SecurityScorecard released a survey highlighting how the retail industry often fails to manage critical security processes. The firm analyzed around 1,924 companies between January and October, 2017, for the survey. The study pointed out that the retail industry ranked fifth among the major U.S industries, where the bottom performers were the clothing retailers. “There were more poor performing clothing stores than poor performing department stores, car dealerships, food stores, grocery/pharmacy stores, wholesale retailers, office supply stores, and stores selling sports good combined.”

Another worrisome trend was that majority of credit card issuers scored a ‘C’ or below in network security and DNS health. “SecurityScorecard’s analysis revealed that not a single credit card issuer received an ‘A’ grade, indicating that every single card issuer could take steps to mitigate cybersecurity risk.”

“Retailers are a prime target for cybercriminals,” said Sam Kassoumeh, Co-founder and COO of SecurityScorecard in a statement. “Our analysis indicates that retailers continue to struggle with basic hygiene which leaves them vulnerable to attack. This includes both online and brick-and-mortar retailers. As we have seen with recent breaches, the lack of basic security controls and best practices can lead to a compromise of consumer data that can have a long lasting impact on customers. With the reliance on third parties, including cloud providers and payment processors, the potential for compromise has dramatically increased.  The primary mechanism that retailers need to deploy is continuous monitoring of their vendors and within their own IT infrastructure.”

“Properly assessing vendor risk, implementing continuous monitoring, validating or supplementing compliance evidence, ensuring protection of the PoS system, and improving increased cybersecurity awareness are all examples of steps that retailers may consider when improving their cybersecurity posture,” the report suggested. “Ultimately, as cyberattacks continue to steal the headlines and consumers become more educated on the potential risks of poor cybersecurity performance, the retail industry, especially its bottom performers, will require significant investments in cybersecurity to keep its doors–physical or digital–open from this holiday season to the next,” the report concluded.

How UK cops are becoming ethical hackers

United Kingdom cops

Article Contributed by Firebrand Training

In the United Kingdom, cyber crime is reported every 10 minutes, the Office for National Statistics revealed. As technologies used by cyber criminals outpace traditional law enforcement, it can be impossible to effectively prosecute criminals.

Cybercrime can be near impossible for a traditional police force to tackle. That’s why police officers across the country are receiving specialist cybersecurity training. They’re becoming ethical hackers.

To respond to the rise in cybercrime, 80% of police across the UK are now training their officers to become hackers by taking cybersecurity training, including renowned penetration testing and ethical hacking certifications.

Cybersecurity skills for frontline policing

Devices are regularly discovered at crime scenes that must be dealt with quickly by frontline police. Without the skills needed to assess and triage these devices, critical evidence is lost or ‘dead-boxed’ – stuck for months in a lengthy evidence process.

“Back in the day the officers would just turn up, pull the electric supply out of the computer, bag it, tag it and wait for the forensic investigation. This could take months before they retrieved meaningful information from the system,” adds Phil Chapman, Lead Cybersecurity Instructor at Firebrand Training.

For the frontline police investigating cybercrime – or any conventional crime scene which may contain digital devices – speed is key. Every second a computer is left unattended, it loses data stored in its memory cache. This cache could contain activity logs and internet history, potentially crucial evidence for prosecuting a criminal.

The process – which can take between two and 30 minutes – doesn’t require advanced hacking tools. The police at the scene simply need the knowledge and skills to access the data quickly. Once the cache is secured, police can image the devices to create identical bit-by-bit copies. These replicas can then be used to preserve evidence which would otherwise have been lost.

“It’s a case of learning the practical skills that we can utilise – no different to a finding a gun at a crime scene that we can make safe from the public and attribute to the criminal,” said DC Steve Mersh when interviewed on the BBC.

Learning to hack

UK law enforcement is gaining cybersecurity skills on courses designed to incorporate -+popular cybersecurity qualifications. Every week police arrive at centres across the UK to receive cutting-edge cybersecurity training from veterans usually responsible for training ‘ethical hackers’ and ‘penetration testers’ across the globe.

Training covers all aspects of information security, from hacking to encryption and cryptography. Police also get to grips with the entire hacking lifecycle, from information gathering to track-covering. Their curriculum even culminates in achieving recognised cyber security certifications, like the Certified Ethical Hacker.

To prove their skills, police are also put through time-sensitive, real-life simulated cyber crime scene investigations.

When interviewed on BBC Breakfast News, DC Steve Mersh said: “It’s a case of learning the practical skills that we can utilise, no different to a finding a gun at a crime scene that we can make safe from the public and attribute to the criminal.”

The future of law enforcement

“It’s what I see as the future of policing and although people don’t see it as the norm now, I think that it most certainly will be,” says DC Charlie Hare.

With rising rates of cybercrime globally, skills taught in these training programmes will eventually become mainstay training for every UK law enforcement officer – whatever their role.

As new threats emerge, there’s now an increased interest in Open Source Intelligence, Digital Currency and The Dark Web’s marketplaces. Clearly, law enforcement cannot stop learning.