Home Blog Page 384

Cryptocurrency mining presents new threat to business: Check Point

CryptoMining Scams

GLOBE NEWSWIRE: According to the latest Global Threat Impact Index by Check Point Software Technologies, cryptocurrency mining was an increasingly prevalent form of malware during October, as organizations were targeted with the CoinHive variant.

Following up on recent Check Point research that found that crypto-miners can fraudulently use up to 65 percent of an end-user’s total CPU resources without the end-user’s approval, the CoinHive variant entered the Index in 6th place in October. The malware is designed to mine the Monero cryptocurrency when a user visits a web page, without the user’s approval. CoinHive implants JavaScript, which then uses high levels of the end-users’ CPU, severely impact the machine’s performance.

As in September, RoughTed and Locky remained the two most prevalent threats. However, there was a new entry to the top three: the ‘Seamless traffic redirector’ malware. This malware silently redirects the victim to a malicious web page, leading to infection by an exploit kit. Successfully infecting the target allows the attacker to download additional malware.

Maya Horowitz, Threat Intelligence, Group Manager at Check Point commented: “The emergence of Seamless and CoinHive once again highlights the need for advanced threat prevention technologies in securing networks against cyber-criminals. Crypto mining is a new, silent, yet significant actor in the threat landscape, allowing threat actors to make significant revenues while victims’ endpoints and networks suffer from latency and decreased performance.”

October 2017’s Top 3 ‘Most Wanted’ Malware:
*Arrows indicate change in rank compared to the previous month.

↔ RoughTed – A purveyor of ad-blocker aware malvertising responsible for a range of scams, exploits, and malware. It can be used to attack any type of platform and operating system, and utilizes ad-blocker bypassing and fingerprinting in order to make sure it delivers the most relevant attack.

↔ Locky – Ransomware that started its distribution in February 2016, and spreads mainly via spam emails containing a downloader disguised as a Word or Zip attachment and then downloads and installs the malware that encrypts the user files.

↑ Seamless – Traffic Distribution System (TDS), which operates by silently redirecting the victim to a malicious web page, leading to infection by an exploit kit. Successful infection will allow the attacker to download additional malware to the target

The most popular malware used to attack organizations’ mobile assets saw one change from September, with Android ransomware LeakerLocker appearing in second place.

Top 3 ‘Most Wanted’ mobile malware:
Triada – Modular Backdoor for Android that grants super-user privileges to downloaded malware and helps it to get embedded into system processes. Triada has also been seen spoofing URLs loaded in the browser.

LeakerLocker – Android ransomware that reads personal user data, and then presents it to the user and threatens to leak it online if ransom payments aren’t met.

Lotoor – Hack tool that exploits vulnerabilities on Android operating system to gain root privileges on compromised mobile devices.

DHS hacks Boeing 757

Addressing the huge contingent gathered at the 2017 CyberSat Summit, Robert Hickey, the aviation program manager within the Cyber Security Division of the DHS Science and Technology (S&T) Directorate, revealed that DHS once successfully took controls of Boeing 757 airplane, while the passenger jet sat on the runway at Atlantic City airport, New Jersey.

He revealed the chilling details about the hack that was conducted last year while giving his keynote address at the summit. “We got the airplane on Sept. 19, 2016. Two days later, I was successful in accomplishing a remote, non-cooperative, penetration,” said Robert Hickey, aviation program manager within the Cyber Security Division of the DHS Science and Technology (S&T) Directorate. “[Which] means I didn’t have anybody touching the airplane, I didn’t have an insider threat. I stood off using typical stuff that could get through security and we were able to establish a presence on the systems of the aircraft.”

While the details of the hack are still kept under the wraps, Hickey revealed his team of DHS cyber sleuths achieved the feat by accessing the radio frequency communications of the plane. According to him the initial response from experts was, “’We’ve known that for years,’” and, “It’s not a big deal,” Hickey said.

Apparently, in March, earlier this year, “at a technical exchange meeting, he said seven airline pilot captains from American Airlines and Delta Air Lines in the room had no clue,” Hickey was quoted by Avionics.

“All seven of them broke their jaw hitting the table when they said, ‘You guys have known about this for years and haven’t bothered to let us know because we depend on this stuff to be absolutely the bible,’” Hickey said. “I want to suggest to you that there’s a different type of critical infrastructure, and that’s critical infrastructure that’s in motion, of which aviation is one of the third of that,” Hickey said. According to him, the other vectors were surface and maritime transportation. “And I look at all of those and say, ‘If we’re not looking at those from a different perspective, we’re going to miss the boat,’ no pun intended.”

Regina police website hacked; displays pro-IS message

Regina police station hacking, hacking, email and passwords hacked

CISO MAG Desk: Days after a New Jersey school district’s website was hacked displaying messages in support of the Islamic State (IS), Canada’s Regina, Prince Albert Police Service’s site temporarily displayed a pro-IS message after the site was apparently hacked by pro-IS supporters. The hacker group also claimed for several other online attacks.

The cops immediately removed the message and restored the site. Apparently, the scenario is very frequent for the police site, and occurs “probably at least once a month,” stated a police spokesperson, Les Parker, who works on the website.

“Of course, they’re not successful, but it’s something that’s attempted and it’s usually done from out of the country, so a lot of times I don’t think we’re targeted specifically for who we are, but it’s just the nature of hosting a website,” he said. “There’s random attacks that happen.”

Chief Evan Bray added that “a general concern for us at all times, not just with our website but all of our databases. We have a lot of sensitive and important information that we maintain, so a lot of work goes into the security of databases and of our website,” he said. “We know we have had attacks before, however because of the different types of stop-checks that we have to ensure that that doesn’t happen, we’ve been able to prevent any sort of a problem with our website. But it’s something in this day and age that you’re not surprised to hear.”

Earlier this year, several United States government websites were hacked by hacker group Team System DZ which allegedly has ties to the terrorist organization, Islamic State. The page displayed anti-Trump slogans and threats. The hacked websites included Ohio Department of Rehabilitation and Corrections, Casino Control, Ohio First Lady, Office of Workforce Transformation, Office of Health Transformation, Inspector General, Ohio governor, and Medicaid.

Every visitor to the website was greeted with an Arabic symbol with a pitch black page with an Islamic prayer played in the background. Also, a line appeared on every page, that said, “Hacked by Team System DZ.” The text on the landing page read: “You will be held accountable Trump, you and all your people for every drop of blood flowing in Muslim countries”, and “I Love Islamic State.”

Enterprises risk all in massive IoT and OT security compliance time bomb

ForeScout Technologies, an Internet of Things (IoT) security company, has revealed new findings about the impact IoT and operational technology (OT) are having on organizations and the cybersecurity dilemmas they are causing within security and Line of Business (LoB) teams.

The survey conducted by analyst firm Forrester Consulting on behalf of ForeScout. surveyed 603 IT and LoB decision-makers that are directly involved in their organization’s network, data and endpoint security processes. Participants were asked about challenges with IoT security and overall awareness of devices on their network. Organizations were located the US, UK, Germany, France, Australia and New Zealand, and had employee counts of 2,500 or more.

It revealed that security and LoB leaders are experiencing high levels of anxiety due to IoT/OT security concerns, largely due to the negative business ramifications a security failure can have on critical business operations. Furthermore, the majority of these organizations (82 percent) struggle to identify all of their network-connected devices, and when asked who is primarily responsible for securing IoT, IT and LoB leaders did not have a clear answer or delineation of ownership.

“The survey results demonstrate a dynamic shift in the way organizations are starting to think about security and risk as it relates to IoT. Each new device that comes online represents another attack vector for enterprises and it only takes one device to compromise an entire network and disrupt business operations, which can impact the bottom line,” said Michael DeCesare, president and CEO at ForeScout. “Securing IoT is not just a cybersecurity issue, it is a business issue and operating at any risk level is too much. Enterprises need full visibility.”

According to the survey results collected from over 600 global enterprise businesses, 77 percent of companies agree that the increased usage of connected devices creates significant security challenges. As a result, 76 percent of respondents said IoT-related anxieties are forcing them to rethink their IT and LoB security strategies.

“Businesses can already see the benefits of connecting devices to the network that were not traditionally connected to improve their business processes and functions,” according to the commissioned Forrester Consulting study, Fail To Plan, Plan To Fail. “Technological advancements have given rise to a deluge of new types of connected devices — i.e., Internet of Things (IoT) — which, in turn, introduce new security threats that enterprises are ill-equipped to combat and even recognize. With increased funding and a new security strategy focused on visibility and compliance, companies can begin taking strides forward to reduce their anxiety about IoT and regain confidence that their networks are secure.”

According to the study, IoT is causing a new level of complexity and the potential for negative business impacts if a security failure occurs. Survey results show that over half of the respondents (54 percent) stated that they have anxiety due to IoT security, with LoB leaders having higher amounts (58 percent) compared to their IT counterparts (51 percent). Understanding the magnitude that a breach can have on enterprise operations and not receiving high-level assurances from IT that their devices are secure, can cause higher levels of anxiety in LoB leaders than IT. In addition, overall distress is due to added costs and time needed to manage these devices as well as a lack of security skills.

IT and LoB respondents also cited budget constraints (IT 45 percent; LoB 43 percent) as the greatest barrier to investing in IoT security, followed by senior leadership skepticism. Without the added investment, security professionals continue to rely on their traditional security approach to protect IoT/OT (40 percent). This strategy prevents organizations from being able to identify all network-connected devices, which opens the door for greater security risk and potential compliance complications. In fact, if audited, 82 percent said they could not identify 100 percent of the devices connected to their network. Additionally, over half of respondents (59 percent) cited that they are willing to tolerate a medium to high risk level in relation to compliance requirements for IoT security. A true concern as 90 percent of companies are expecting to see their volume of connected devices increase over the next few years.

The study supports a clear disconnect between IT and LoB leaders, highlighting potential ownership issues around securing process-specific IoT/OT devices. When asked who is primarily responsible for securing IoT/OT devices on an enterprise network, 44 percent of IT respondents versus 36 percent of LoB respondents stated security operations center (SOC) professionals. However, LoB respondents were more likely than IT to prefer a dedicated LoB IT staff or LoB practitioner to be responsible. While most companies tend to keep security under the purview of IT, it is becoming more critical for collaboration amongst asset managers, LoB teams and the network teams that are adopting and deploying these connected devices. This is important for enterprises as they consider their IoT security strategy, including managing default security configurations and enabling proper visibility of all devices.

The survey also shows that a combination of top-down executive support, proper security tools and audits instill greater confidence in device visibility. In fact, 48 percent of all respondents stated that improving awareness and visibility of IoT devices is a top priority for improving IoT security and 82 percent of respondents expect their IoT/OT security spend to increase over the next one to two years. When considering the adoption of IoT security solutions, more than half of the respondents (55 percent) said integration with existing security systems was the most important criteria.

Ukrainian President signs law on cyber security

Ukraine is sprucing its cybersecurity forte by mandating several basic principles for ensuring a secure cyber haven in the country. President Petro Poroshenko has signed the law which “creates the foundations of a national system of cybersecurity as a combination of political, social, economic and information relations, along with organizational, administrative and technical and technological measures of the public and private sectors and civil society,” the press service of the head of state has reported. The president will coordinate activities in the field through National Security and Defense Council of Ukraine.

According to a report on Ukinform.net, “The law defines the legal and organizational foundations for ensuring the protection of vital interests of citizens, society and the state, the national interests of Ukraine in cyberspace, the powers and responsibilities of state bodies, enterprises, institutions, organizations, individuals and citizens, the basic principles of coordination of their activities, and also basic terms in cybersecurity.”

As per reports, the bill also summaries several vectors of mitigating cyber threats with a key focus on protecting critical infrastructure. The law also explores possibilities of partnering with private agencies and civil societies as well as takes into account several proposals from the European Union and NATO. “The legislative act was developed in compliance with the requirements of the National Security Strategy of Ukraine, which was approved by presidential decree No. 96 of March 15, 2016 on the decision of the National Security and Defense Council of Ukraine dated January 27, 2016, on the Cybersecurity Strategy of Ukraine,” the report concludes.

Cybersecurity jobs: A hot favorite among young Emiratis

CISO MAG Desk: This may come as a relief to the world which is marred by cybersecurity talent gap that youngsters from UAE are considering a career in information security more than anywhere else in the world. The trend was highlighted by a study titled, ‘Securing Our Future: Cybersecurity and the Millennial Workforce,’ commissioned by Raytheon, Forcepoint and the National Cyber Security Alliance about security practices in the new workforce and preparedness for cybersecurity careers among young adults in nine countries. The surveyed countries were Australia, Germany, Jordan, Poland, Qatar, Saudi Arabia, United Arab Emirates, United Kingdom and the United States. Around 3,359 individuals aged between 18 and 26 were surveyed in the study.

Among the respondents, nearly 67 percent youngsters from Middle East were more likely to consider a cybersecurity career, compared with 48 percent respondents in the region and 39 percent, globally.

Shahzad Zafar, Cybersecurity Director at Raytheon International Inc, in a release stated that with the data shows young people in the UAE are ahead of others in realizing the cyber-security threat. “We’ve found young people here are forward thinking and tech savvy,” he said. “They are active on social media and aware of the concerns of cybersecurity and the opportunities as a profession, which is still relatively new.
The figures show a sense of service. This is an important developing industry, and young people seem to be acknowledging that and are excited about getting involved in either protecting their homeland or in business.”

The study also highlighted that nearly 64 percent of young Emiratis had either attended or planned to attend cybersecurity job fairs, with a major chunk seeking out mentors in the space. Apart from these, youngsters from the Middle East were confident that their parents would guide them to pursue a career in cybersecurity with most of them stating that the first person to talk to them about cybersecurity was a parent.

Another good news on the issue was that “most millennials believe that cybersecurity is important, with 83 percent surveyed saying it’s “important, very important or extremely important” to increase cybersecurity awareness programs in the workforce and formal education programs. Most also reported an increase in such programs, with 70 percent somewhat or strongly agreeing that their high school or secondary education prepared them to use technology safely, securely, ethically and productively in the workplace, up from 55 percent in 2013,” the study stated.

Dr Tod Laursen, interim president of Khalifa University of Science and Technology, in an interview with the Gulf News, stated, “We highly value cybersecurity as a subject to prepare young people to navigate through today’s environment of threats and capitalise on opportunities in the field by providing a solid cyber-related curriculum. The results of Raytheon’s survey underline the progress being made and we are confident that we will see more and more young Emiratis pursue promising careers in cybersecurity.”

Behavioral anomaly detection tools to boost cybersecurity in manufacturing sector

third-party risk

Globe News Wire: SecurityMatters is proud to announce that they will work with NIST’s National Cybersecurity Center of Excellence (NCCoE) for their latest cybersecurity project, “Capabilities Assessment for Securing Manufacturing Industrial Control Systems”, focused on counteracting cyber attacks against ICS devices that are crucial to manufacturing processes. SecurityMatters’ passive anomaly detection solution, SilentDefense, will be used in the NCCoE practice guide along with other technologies to demonstrate cybersecurity capabilities for the manufacturing sector.*

“We are excited and honored to have the opportunity to work on a program that will define best practices for securing manufacturing environments in the United States,” said Dennis Murphy, Lead ICS Security Engineer at SecurityMatters. “Our mission has always been to advance cyber resilience in the critical infrastructure and manufacturing industries, and this project is the perfect opportunity to achieve just that.”

This NCCoE project aims to provide detailed information to establish anomaly detection and prevention capabilities within the manufacturing ICS environments. Behavioral anomaly detection tools like SilentDefense provide manufacturers with a significant security component, along with additional benefits unrelated to security issues.

The results of this project will form a NIST Cybersecurity Practice Guide, a four-part series detailing practical steps needed to implement example solutions for cybersecurity challenges. The NCCoE will also map these results to the NIST Cybersecurity Framework to provide standards-based security controls for manufacturers.

*While the example implementation uses certain products, including SecurityMatters, NIST and the NCCoE do not endorse these products. The guide presents the characteristics and capabilities of those products, which an organization’s security experts can use to identify similar standards-based products that will fit within with their organization’s existing tools and infrastructure.

Paradise Papers rocks the world

paradise papers

CISO MAG Desk: The ‘Paradise Papers’ findings released by the US-based International Consortium of Investigative Journalists (ICIJ) have opened a can of worms. ICIJ is the same organization that was behind Panama Papers sensational exposures. The major cyber breach has been reported from Appleby, a multi-national offshore law firm known for its tax planning services.

The leaked documents, dubbed Paradise Papers were released on November 6, 2017, and consist of 13.4 million records including emails, loan agreements and bank statements that contain sensitive financial information pertaining to highly prominent and influential figures. Out of 13.4 million records, 6.8 million documents came from a cyberattack on Appleby files. The Appleby files were obtained by the German newspaper Süddeutsche Zeitung and shared with the ICIJ along with 95 media firms to maximize the exposure of the leaked information.

The Paradise Papers exposures have been compared to the 2015 Panama Papers leak which exposed millions of documents from the Mossack Fonseca law firm.

In October end, Bermuda-based firm Appleby, that represents wealthy clientele, released a statement saying “We are disappointed that the media may choose to use information which could have emanated from material obtained illegally and that this may result in exposing innocent parties to data protection breaches,” continues Appleby, adding that it reviewed its cybersecurity and data access arrangements and is confident that its data integrity is secure”.

The thunder of Paradise Papers disclosures has been felt in India as well as it has named 714 Indians for evading taxes. High profile names include Bollywood actor Amitabh Bachchan, corporate lobbyist Niira Radia, Minister of state for aviation Jayant Sinha.

The long list of international leaders and celebrities on the list includes Britain’s Queen Elizabeth II, Colombian President Juan Manuel Santos, Canadian Prime Minister Justin Trudeau’s chief fundraiser Stephen Bronfman, individuals linked to the U.S. President Donald Trump, singers Bono and Madonna, and US Commerce Secretary Wilbur Ross among several others.

Mark Sangster, Vice President and industry security strategist at cybersecurity company eSentire told SC Magazine ” The parallels of Paradise Papers to Panama Papers breach are obvious, however beyond the shock factor of the leaked data itself, what’s more alarming is the depth and magnitude of this breach. Law and accounting firms should raise the alarm when it comes to their firm’s cybersecurity rigor”.

“While the mechanics of the breach itself have yet to be revealed, this was clearly a targeted attack. Law and accounting firms are particularly susceptible to ethical hacking and really, every firm should assume they’ll be breached. These firms house a treasure trove of sensitive data that, when compromised, can result in sometimes irrecoverable damage”, Sangster continued.

Ilia Kolochenko, CEO of web security company High-Tech Bridge said “hacking of their clients is quite costly, will likely be detected and investigated, and almost certainly will cause very serious counteractions,” said Kolochenko, in emailed comments. “It may be a good moment to think about imposing obligatory data security standards on law firms and practicing attorneys. Their data deserves at least the same level of protection as data of companies under PCI, DSS or HIPAA compliance. Otherwise, visiting attorneys will become a very risky practice”.

Verticalscope suffers second data breach; 2.7 million users affected

Verticalscope

Canada-based Web forum manager Verticalscope suffered a massive data breach for the second time in two years. The recent attack affected email addresses, usernames, and passwords of 2.7 million users. The compromise was first noticed by Hold security, a computer security firm that helps companies to enhance their security posture and stay secure.

In a statement, Verticalscope told KrebsOnSecurity, “the intrusion granted access to each individual website files. Out of an abundance of caution, we have removed the file manager, expired all passwords on the 6 websites in question, added the malicious file pattern and attack vector to our detection tools, and taken additional steps to lock down access.”

However, it did not disclose who conducted the attack and when did the data breach occur. Toyotanation.com, Jeepforum.com, and watchuseek.com are among six websites that have been impacted. Notably, Jeepforum.com is the second most popular website of Verticalscope.

Hold Security suspects that perpetrators gained access through a Web Shell backdoor, which can provide an unauthorized user remote access and control to a site.

Alex Holden, the security researcher and owner of Hold Security, alerted Krebs on November 2, 2017, that hackers were selling access to Verticalscope.com and other sites owned by it. He also claimed to have received screenshots of the stolen data from sellers.

During the investigation, Krebs wrote in his blog that after performing a simple search on compromised domains, he realized that there was a series of Pastebin posts, which were although deleted but highlighted that the hackers have tried to advertise on LuiDB (a suspicious new online service).

In June 2016, Verticalscope was hacked and the breach impacted 45 million user credentials from 1,100 websites and forums. The Internet media firm then had told users to change their passwords rather than notifying them about the breach.

Horangi Cybersecurity raises $3.1 million in Series A funding round

Funding

Singapore-based startup Horangi cybersecurity secured $3.1 million in successful Series A round of funding led by Monk’s Hill Ventures. Horangi will utilize the raised funds in proprietary technologies, scaling business operations, and accelerating expansion in key Asian markets, Digital News Asia reported.

Right Click Capital, 500 startups, Hub Ventures Fund, 6Degrees Ventures, and private investors participated in the financing round. Post investment, Monk’s Hill’s founding partners Peng T Ong and Kuo-Yi Lim have been appointed to Horangi’s board of directors.

“Cybersecurity is a growing concern for companies in this region. Online attacks are increasing in frequency and sophistication, while reliance on online services has also grown,” Lim said. “Horangi brings a level of expertise and much needed capability in its products to the market, particularly in Asia where this is lacking. The team’s extensive experiences put them in a strong position to help companies protect their online presence and data.”

Launched in early 2016 by Palantir alumni Lee Sult and Paul Hadjy, the firm has over 50 clients across sectors such as government, technology, financial services, and retail. The cybersecurity company builds security products that enable the rapid delivery of incident response and threat detection for our customers who lack the scale, expertise or time to do it themselves.

Horangi co-founder and CEO Paul Hadjy was quoted as saying, “as cyber threats become increasingly complex, businesses require proactive solutions to safeguard their digital environments. Our vision is to provide an affordable full-stack cybersecurity solution for our users globally, allowing them to quickly understand and deploy the right course of action.”

The specialties of the privately-held company includes Incident Response, Security Assessments, Digital Forensics, Policy and Governance, Training, and User-centered Design. Horangi opened its new office in Seoul in September this year. It has local branches in Taiwan, Hong Kong and Philippines.

This is Monk’s Hill Ventures third investment in Southeast Asia this year. It has offices in Singapore and Japan.