Home Blog Page 39

HTML Smuggling – A Novel Malware Deploying Technique

HTML Smuggling

Like creating various malware variants, cybercriminals often find new techniques to deploy malware and evade security scans. As per a report from Microsoft 365 Defender Threat Intelligence Team, adversaries are increasingly relying on HTML smuggling techniques in email phishing and malware campaigns to obtain access and infect a network or system with an array of malware variants. These include banking malware, ransomware, and remote access trojans (RATs).

The report stated that attackers also distributed Mekotio banking Trojan, malware backdoors like AsyncRAT and NjRAT, and the infamous TrickBot malware to gain the initial control of the compromised systems and deploy ransomware payloads.

What is HTML Smuggling?

HTML smuggling is a malicious technique used by hackers to hide malware payloads in an encoded script in a specially crafted HTML attachment or web page. The malicious script decodes and deploys the payload on the targeted device when the victim opens/clicks the HTML attachment/link. The HTML smuggling technique leverages legitimate HTML5 and JavaScript features to hide malicious payloads and evade security detections.

The HTML smuggling method is highly evasive. It could bypass standard perimeter security controls like web proxies and email gateways, which only check for suspicious attachments like EXE, ZIP, or DOCX.

NOBELIUM Group Used HTML Smuggling

Microsoft researchers stated this technique was observed in a spear-phishing campaign by the infamous NOBELIUM – a Russian state-sponsored group allegedly behind the SolarWinds hacks, the SUNBURST backdoor, GoldMax malware, and the TEARDROP malware campaigns. The researchers stated the malicious email campaign leveraged an HTML file attachment, which, when opened by the victim, uses HTML smuggling to download the primary payload on the targeted device.

Eventually, other cybercriminal groups appeared to have followed NOBELIUM’s suit and adopted the technique for their own campaigns. “The surge in the use of HTML smuggling in email campaigns is another example of how attackers keep refining specific components of their attacks by integrating highly evasive techniques. HTML smuggling uses legitimate features of HTML5 and JavaScript, which are both supported by all modern browsers, to generate malicious files behind the firewall. Specifically, HTML smuggling leverages the HTML5 “download” attribute for anchor tags, as well as the creation and use of a JavaScript Blob to put together the payload downloaded into an affected device,” Microsoft said. 

How to Detect HTML Smuggling?

Microsoft recommended security admins to use behavior rules to identify the common characteristics of HTML smuggling, which include:

  • An attached ZIP file contains JavaScript
  • An attachment is password-protected
  • An HTML file contains a suspicious script code
  • An HTML file decodes a Base64 code or obfuscates a JavaScript

For endpoints, security admins can prevent HTML smuggling activities by:

  • Blocking JavaScript or VBScript from launching downloaded executable content
  • Blocking execution of potentially obfuscated scripts
  • Blocking executable files from running unless they meet a prevalence, age, or trusted list criterion

Mitigation

Organizations and users can prevent JavaScript codes from executing automatically by changing file associations for .js and .jse files to reduce the impact of threats that utilize HTML smuggling. Users and employees need to be aware of various malware infections and preventive measures to help mitigate malware-based threats.

3 Steps Businesses Can Take to Protect Themselves From Software Supply Chain Attacks

supply chain attacks

In August, the White House hosted a meeting with some of the most powerful CEOs in the world; from Apple to JPMorgan. The topic for discussion? The rampant scourge of software supply chain attacks, which has surged by a staggering 650% in 2021.

By Nick Caley, VP of UK and Ireland, ForgeRock

There is no doubt that protecting technology supply chains is now a hot-button issue for companies and governments alike. With one well-placed piece of malicious code, and apparently trusted piece of software can turn into the cyber equivalent of a WMD, allowing hackers to hijack distribution systems and turn a supplier’s customers into digital trojan horses.

With all this attention on the issue, you could be forgiven for thinking this was a new problem. It’s not. Experts have been warning about the threat of these attacks for years.

However, the threat has certainly evolved thanks in part to the acceleration in digital transformation triggered by the pandemic. In 2021, demand for open source “supply” increased by 73%, with developers downloading more than 2.2 trillion open-source packages 2021.

As uptake has grown, so has the threat to businesses. For example, hackers have begun using a technique that goes further upstream toward the origins of the open-source code, essentially meaning that they can infiltrate from top to bottom.

Major attacks like SolarWinds and Kaseya have certainly focused minds and moved the issue up the agenda for many business leaders and policymakers.

But governments aren’t acting quickly enough. The US and UK have either only begun or are midway through processes to formulate concrete guidance for companies to deal with the evolving threat. With only 12% of U.K. businesses having reviewed the cybersecurity risks posed by third-party software suppliers in the last year, the need for clear direction has never been more urgent.

It’s time for businesses to take the matter into their own hands. Here are the three steps to building a real cyber defense against supply chain threats.

Implement a Framework That Engrains Security as an Organisation-wide Value

In the aftermath of the SolarWinds attack which affected multiple federal US agencies, including the National Nuclear Security Administration, the Biden administration enacted its cybersecurity executive order.

One of the key recommendations from this order was a process for new minimum security standards for any company that wants to sell software to federal agencies. The process is expected to conclude by May 2022 and is anchored by the National Institute of Standards and Technology (NIST), a globally recognized standard-setting body under the U.S. Department of Commerce.

While this process won’t conclude until next year, NIST has published a widely-recognized framework that compiles industry standards and best practices for secure software development.

The new process will be additive to these guidelines but, in the interim, this framework is what companies should use as the basis for their own responses. Essentially, it helps engrain best practices and procedures to secure software development covering people, processes, and projects to identify vulnerabilities, understand risks, and quickly integrate lessons learned.

It is crucial that businesses build trust both internally and externally, with suppliers, customers, and partners. Adopting a common security framework will lay the foundations for strong cybersecurity defense.

Slim Down Your Network of Third-party Software Suppliers

According to Gartner, 60% of organizations are now working with more than 1,000 third parties and 71% of organizations reported working with more organizations than they did before. This number is expected to grow even more in the coming years, underscoring how vast and sprawling software supply chains have become.

To manage this growth businesses need to monitor their third-party network by establishing internal triggers that signal when there is a change in an external relationship. As third-party relationships change, leaders must ensure that firstly the risks are mitigated and secondly the relationships are re-evaluated.

By filtering the pool of external suppliers a company works with, it can streamline the points of contact throughout the digital supply chain, and minimize potential points of ingress for cyberattackers.

Additionally, focusing on a smaller network of suppliers whose processes they trust and understand, will allow a company to review supply chain security more regularly and easily as opposed to, say, just the onboarding and recertification phases.

Often when it comes to software supply chain security, less is more.

Ensure Your Access Tools are Fit for Purpose 

Lastly, it’s important to remember that your software systems are only as secure as the access tools you use. Understanding who or what needs access, and under what conditions, is critical to securing internal systems and preventing software supply chain attacks from occurring. The rise of a remote workforce has increased demand for access to new cloud applications, services, and IoT, it is, therefore, crucial that businesses have an identity governance solution that is fit for purpose.

Adding automation to make sure your identity and access management systems are always kept up to date with other changes throughout the business can make a huge difference. Digital supply chains inevitably grow and change as partners and suppliers enter and exit the supply chain. If you are relying on manually managing access requests to reflect these changes, then you are leaving your business exposed to risk through human error. IT and security teams are already stretched, creating conditions where potentially risky entitlements and access requests can slip through the cracks.

This can compound as well and lead to ‘entitlement creep’ across the supply chain as access and roles accumulate within a system, expanding the potential footprint for attackers. Instead, businesses need to harness the ability of AI-powered identity governance solutions. By automating access approvals, AI enables IT and security teams to identify access risks and provide actionable insights to help accelerate the removal of overprivileged accounts while allowing teams to focus on high-risk situations.

Combatting an Exponential Threat 

Protecting businesses from crippling software supply chain attacks is now a priority for the whole of the economy. These attacks are so dangerous because they can cause damage far beyond a traditional breach: a compromised supply chain risks exposing thousands of other companies and public sector organizations.

There no longer needs to be a compromise made between user productivity, experience, and robust levels of security. By streamlining their supply chains, implementing secure-by-design software development, and adopting a modern, AI-powered identity governance solution, businesses can take a risk-informed approach and protect themselves while also protecting society at large.


About the Author

Nick Caley, VP, ForgeRockNick Caley is Vice President of UK and Ireland at ForgeRock is responsible for advising global clients in industry and government on security strategy and digital transformation focused on hybrid data architectures and data-driven business models.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Top 5 Skills Every SOC Analyst Needs to Have

SOC analyst

As the landscape of cyberthreats expands, it is imperative for enterprises to focus on employing security operations center analysts, also known as SOC analysts, to prevent and mitigate cyberattacks. Companies need to envision and revamp or build new SOC teams before cyberattacks occur to avoid financial and reputational damage.

The Need for SOC Analysts Today

The quickly expanding technological landscape, combined with the complex attack approaches used by cybercriminals, is the primary reason for the burgeoning demand in this field. Enterprises are increasingly vulnerable to risks due to the remote work framework, Bring Your Own Device allowances, outdated policies, and a slew of additional concerns. To address these issues, corporations need to ensure enhanced network and system visibility and 24/7 monitoring to mitigate threats, thereby creating the need for security operations center analysts.

Defending intellectual assets in an organization is just one role a SOC analyst plays. The security operations center is a centralized unit made up of three elements — people, processes, and technology, which help monitor an organization’s IT and security infrastructure. SOC is one large team of security managers, SOC analysts, cybersecurity engineers, and more, who are responsible for managing and mitigating various threats.

Becoming a certified SOC analyst is a rewarding cybersecurity career. Organizations employ SOC analysts who can assume the role of front-line defenders, monitor their security posture, and alert relevant parties of any possible or emerging cyberthreats. This article discusses five skills that are necessary to begin a career in this field.

Before we explore that subject, however, it’s important to first understand the typical duties of a SOC analyst.

What Does a Security Analyst Do?

Security operations center analysts are skilled professionals with in-depth knowledge about SOC processes, tools, and technologies to help identify and mitigate cyber risks and ensure data security and privacy. Setting up a SOC team is not an initiative that happens after the cyberattack. A SOC team looks after the overall security posture of an organization, and SOC analysts are the first responders to cyber breaches. Let’s look at their core responsibilities:

  • SOC analysts work to identify, assess, and mitigate the complete security aspects within the SOC.
  • Highly skilled security analysts are responsible for conducting forensics investigations in organizations, while Level 1 professionals do triage work. The job of Level 2 SOC analysts is to monitor, report, and classify suspicious activities on networks and assign priority levels to them. A certified SOC analyst investigates security alerts and data breaches and identifies vulnerabilities that may lead to network incidents if left unchecked.
  • Organizations benefit from the round-the-clock monitoring of their IT infrastructure that a SOC team provides. The team brings centralized visibility to all aspects of security.
  • They maintain detailed reports of incidents and security policies.
  • Security analysts use their analytical and critical thinking skills to examine security flaws and design robust recommendations for network security and strategies.
  • The SOC team performs frequent assessments and audits to stay ahead of cybercriminals.
  • SOC analysts stay up to date with the latest technologies and developments and adopt self-teaching practices to ensure they are up to date with changes in the industry.

security operations analyst must also ensure that data flowing through the silos of an organization doesn’t get intercepted. Using a combination of different testing methodologies, updating cybersecurity strategies and systems, and recommending the best course of action for businesses in data breaches are some of the major responsibilities of a security operations analyst.

Now, let’s look at what makes a SOC analyst a top-notch professional to employ as a front-line defense.

Five Key Skills of a SOC Analyst

There are five key skills every SOC analyst must master to succeed in the cybersecurity industry:

1. Programming Skills

While it’s a given that cybersecurity professionals must demonstrate proficiency in technical skills to adapt to the evolving threat landscape, they also need to know programming languages. SOC analysts often work with cybersecurity engineers and security experts to devise threat mitigation strategies. Coding and programming skills are crucial. Sound knowledge of JavaScript, C++, and Python, to name a few, give a boost to those looking to pursue careers as SOC analysts.

2. Strong Fundamental Skills

While it may seem obvious, a SOC analyst must have a strong understanding of network protocols, systems, and IT infrastructure, along with knowledge of attack vectors and methodologies. Global employers highly value those with sound technical and rapid threat mitigation skills. Technology solutions are constantly evolving, which means SOC analysts should be able to learn on the fly and adapt quickly to changing threat scenarios. Most of them demonstrate excellent critical thinking skills and apply methodologies that go beyond mere textbook knowledge for dealing with threats.

Most skills cannot be learned with diligent study and require hands-on experience in the field. To identify, detect, and mitigate threats, SOC analysts should know how networks and their various elements work, including how adversaries find flaws and proceed toward exploiting them.

3. Communication and Collaboration

SOC analysts work closely with their team and other security professionals, and the ability to share information with all team members concisely and effectively is essential. Soft skills such as empathy, emotional intelligence, motivation, and the drive to accomplish challenging tasks despite the circumstances are valuable traits in SOC analysts. They should know how to effectively manage IOC alerts and incident defense tools and resolve key security breaches while keeping everyone updated.

4. Ethical Hacking Skills

SOC analysts must demonstrate ethical hacking and pen testing skills to detect, identify, and mitigate threats. Pen testing is an essential skill to be able to test the vulnerability of systems, web applications, and networks, report the anomalies, and respond appropriately.

5. Incident Handling and Documentation

Incident handling and response measures are often unpredictable, and SOC analysts must also be able to devise adequate data backup and maintain recovery plans. Reporting incidents to key stakeholders in the organization and addressing security challenges on priority are typical of their duties.

SOC analysts are responsible for documenting incidents, data breaches, and any malicious activities conducted in networks. They must help managers optimize security budgets and assist companies in determining which cybersecurity standards to implement for future protection. Understanding the role of pen tests in networks, web applications, and API vulnerabilities, as well as collecting, analyzing, and reporting security data are all requirements for effective incident documentation.

Apart from these, SOC analysts must also be able to effectively handle pressure. The ability to work under pressure during incidents and meet timelines for regular security audits is essential. The best SOC analysts are constantly honing their skills to gain an edge over others and create timely solutions while working in challenging environments.

They also monitor and analyze social engineering attempts. Incidents can sometimes happen due to internal threats and a lack of operational security awareness. This is where SOC analysts must stop lapses in judgment, whether human errors are accidental, intentional, or unexpected. They must also constantly review employee records, update systems, and ensure the latest patches are applied to keep network security up to date.

How to Become a Security Operations Center Analyst in 2021

security operations analyst can wear multiple hats in an organization, and the day-to-day job roles might vary. Many professionals require a bachelor’s degree in cybersecurity to break into the industry and land their first job. There is a wide variety of certifications a professional can complete to advance their career and earn higher pay as they acquire extensive professional experience. According to Salary.com, the average pay of a SOC analyst in the United States is $90,538 per year. However, it is important to know that the average pay range can vary based on numerous criteria, including educational background, work experience, and so on.

For those who are interested in stepping into a career as a security operations center analyst, here are some essential requirements:

  • Education Requirements

The first step is to identify the roadmap to your career goals. Understand the niche field you want to specialize in, what certifications are needed, and how to get there. Even entry-level security analysts require specialized training, and most experts have a bachelor’s degree or a background in military service. Entry-level certifications show proficiency with in-demand skills, and many employers prefer to hire analysts that have demonstrated a certain level of expertise in acquiring them. If you wish to join a SOC team, the first step is to get a Certified SOC Analyst (CSA) certification.

  • Networking

Networking is a powerful tool that can help you advance your career. SOC analysts may network by talking with other cybersecurity professionals in the industry or attending conferences, whether online or in person. Lasting connections can also be made through certification programs and degree programs. A strong career path could start with a Bachelor of Science in Information Management Systems and SOC analyst certifications earned periodically to reskill, upskill, and gain more industry knowledge.

  • Certifications

Like any other role in cybersecurity, the day-to-day tasks of a SOC analyst can differ. On some days, the analyst may be busy performing vulnerability assessments on systems, monitoring networks, and reporting malicious events to the staff. A SOC 2 certification is helpful in getting a job in this field, and many recognized internships help analysts obtain the required work experience to get started. One such credential program is CSA training that equips participants with the necessary technical skills to make dynamic contributions to SOC teams.

Join EC-Council’s Certified SOC Analyst (CSA)

Every SOC analyst requires specific skills to succeed in their jobs, and a SOC 2 certification can go a long way toward starting or enhancing a career in the field. SOC Tier 1 and Tier 2 professionals ensure that security operations teams have the security monitoring tools and strategies they need to safeguard the security architecture of enterprises. With high salaries and promising opportunities, SOC analysts are in demand in 2021.

Obtaining EC-Council’s Certified SOC Analyst (CSA) certificate is the first thing you need to join a SOC team. It is an extensive training and credentialing program that offers a comprehensive approach to learning.

CSA offers in-depth course content focusing on SOC operations’ core fundamentals, log management, correlation techniques, SIEM deployment, incident response, and advanced incident detection methodologies. The program is ideal for Tier I and Tier II SOC analysts, cybersecurity analysts, and anyone who wants to become a SOC analyst. The certification creates new and dynamic opportunities for cybersecurity professionals to help them gain the necessary skills and techniques to perform entry-level and intermediate-level operations.


According to the U.S. Bureau of Labor Statistics, more than 100,000 information security analyst jobs remain unfilled.

Ready to become a SOC analyst? Get job-ready today.


FAQs

1. What are the responsibilities of a SOC analyst?

SOC analysts constantly monitor, detect, and escalate threats. They also assess security and business risks. SOC analysts use various tools to detect and mitigate threats.

2. What are the basic skills required by a SOC analyst?

The basic skills required by a SOC analyst are as follows:

  1. Programming ability
  2. Knowledge of network security
  3. Knowledge of security fundamentals
  4. Incident handling and documentation
  5. Ethical hacking

3. What tools do SOC analysts use?

Some of the tools used by SOC analysts are as follows:

  • Security information and event management tools
  • Governance, risk, and compliance systems
  • Intrusion detection systems
  • Intrusion prevention systems
  • Cyber threat databases
  • Perimeter 81 FWaaS, Fortinet FortiGate (7000 series), Forcepoint NGFW, and so on

References:

  1. https://www.allhandsontech.com/security/4-essential-skills-for-a-security-analyst/
  2. https://www.cyberdegrees.org/jobs/security-analyst/
  3. https://www.eccouncil.org/programs/certified-soc-analyst-csa/
  4. https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm

Stolen Access Key Exposes Customer Data Stored in the Aruba Central Environment

Secret Terrorist Watchlist Leak, Aruba

HPE-owned Aruba has disclosed that an access key to the data repositories for their Aruba Central network monitoring platform was compromised, allowing an unauthorized external threat actor to access the subset of information.

Internal security monitoring tools installed in the Aruba Central environment discovered a suspicious activity and alerted the Security Operations team. On further investigation, the team inferred that the access was unauthorized and affirmed the breach on November 2, 2021.

Aruba detailed the breach, stating that it exposed the data repository; one dataset (“network analytics”) contained network telemetry data for most Aruba Central customers about Wi-Fi client devices connected to customer Wi-Fi networks. A second dataset (“contact tracing”) contained location-oriented data about Wi-Fi client devices, including which devices were in proximity to other Wi-Fi client devices.

“The Customer Personal Data in the exposed data repositories consists of device Media Access Control (MAC) address, IP address, device operating system type and hostname, and, for Wi-Fi networks where authentication is used, the username. The data repositories also contained records of date, time, and the physical Wi-Fi access point where a device was connected, which could allow the general vicinity of a user’s location to be determined. The environment did not include any sensitive or special categories of personal data (as defined by GDPR),” Aruba said.

On deeper analysis of the usage records of the exposed repositories with authorized activity, Aruba engineers discovered a small data pool to be affected.

“This lets us state definitively that the unauthorized actor did not view, download, or transfer out of the repositories any significant amount of data,” states Aruba.

Action – Key Revoked

When the incident was discovered, HPE had already decommissioned and rotated the access key in question on October 27, 2021, as part of a regular security exercise. As a result, the threat actor had no further access using the key after that date. HPE then ran a search of all Aruba Central logs to establish any additional unauthorized usage of the keys.

“The Security Operations team activated its data breach incident response plan, notifying various Security, Legal, and Privacy functions inside HPE,” said Aruba.

Hike in IPv4 Prices Pose Severe Cybersecurity Threat

IPv4 Address Price, International Internet Day

Following the growing demand for internet commodities like IP assets, the prices of IPv4 addresses have reached new heights in recent times. Cybersecurity experts warn that this scenario could boost the risk of security threats as opportunistic cybercriminals might target unused or unsecured IP addresses to compromise them and trade on underground markets. Organizations that own or manage IPv4 address blocks should be vigilant and look out for any hijacking attempts on their IPv4 addresses by hackers.

What is an IPv4 Address?

The IPv4 or IP (version 4) address is the fourth version of the internet protocol (IP), which has a set of rules governing the format of data communications sent over the internet and other networks. IPv4 addresses are 32-bit integers that can be expressed in hexadecimal notation (Example: 192.0.2.146 is an IPv4 address)

IPv4 and Associated Cyber Risks

According to a report from IPXO, the price of an IPv4 address increased to $32 in Q1 2021 as the supply of IP resources failed to meet demand. It’s suspected that the increase in cyberattacks is a probable consequence of this price surge, as reselling hijacked IP addresses would be a profit in underground markets. The gap between the supply and demand of IP resources makes transactions expensive and exhaustive, leading companies to engage in IPv4 black market transactions.

Also Read: 3 Digital Assets That Are High in Demand on Dark Web Forums

Vincentas Grinius, CEO of IPXO, stated that increased prices and limited accessibility contribute to the rise of cybercrimes. “Cybercriminals can exploit these vulnerabilities in two ways: firstly, they target the IPv4 addresses of companies who do not feel pressured by IPv4 depletion, unaware of what is being done to their vast reserves of IP resources. Secondly, they offer desperate companies, willing to side-step legalities, the opportunity to obtain needed IPv4 addresses quickly but at prices equal and, in some cases, higher than in legal markets.”

The report also claims that over 800 million unused IPv4 addresses at present, which could become a prime target for attackers to re-sell them under the record-high market price.

Some of the threats that affect IPv4 include:

1. Sniffing Attacks – A sniffing attack involves the illegal extraction of unencrypted data by capturing network traffic through packet sniffers.

2. Application Layer Attacks – An application layer attack targets computers by deliberately causing a fault in a computer’s operating system or applications. These include DDoS attacks, SQL injections, cross-site scripting, etc.

3. Flooding – Flooding results when a device is targeted with large amounts of network traffic, which could lead the network to become unavailable or out of service.

4. Rogue Devices – Rogue devices are unauthorized end-user computers or wireless access points that prey on sensitive information such as credit card numbers, passwords, and more.

5. Man-in-the-Middle Attacks In a man-in-the-middle attack, the attacker places himself in an ongoing communication or data transfer between an application/service and its user to spy or impersonate someone.

“Cybercriminals mainly capitalize on existing market problems, which the rapid price growth of IPv4 has demonstrated. By tapping into the vulnerabilities created by unequal resources, hijackers have created a lucrative black market. A possible solution to these issues is the creation of more sustainable internet governance. As IP leasing presents both a cost-efficient and accessible option for businesses, cybercriminals may be pushed out of the market by superior competition,” Grinius added.

Security Is Everybody’s Business

A joint study from Stanford University Professor Jeff Hancock and security firm Tessian revealed that nine in 10 (88%) data breach incidents are caused by employees’ mistakes. The study “Psychology of Human Error” highlighted that employees are unwilling to admit their mistakes if organizations judge them severely.  So, it can be concluded that humans are the weakest link in the supply chain and are frequently targeted through phishing attacks, malware, and social engineering. But why are security awareness levels so low in organizations and what do they need to do?

In an exclusive video interview, Brian Pereira, Editor-in-Chief, CISO MAG, discusses the organizational challenges for security awareness with Dr. Frank Ofori, Cybersecurity Specialist and a former U.S. Army veteran.

Dr. Ofori says everyone in the organization is responsible for security awareness and must practice cyber hygiene at work and home for personal computing. It is not just a top-down approach. It could also be bottom-up. He also offers some tips and advice for creating an incident response plan.

Dr. Ofori is a retired U.S. Army veteran with over 13 years of experience in both IT and Cyber Security. He is a Cyber Security Specialist with the U.S. Department of State and an Adjunct Professor at Stratford University with concentration in both Offensive and Defensive Cyber Security.

He specializes in corporate and enterprise security, development of cyber defense programs, and business operations protection for both US Federal and commercial clients.

He has been certified an industry professional by the International Information Security Certification Consortium (ISC2), Information System Audit and Control Association (ISACA), and the EC-Council as Certified Chief Information Security Officer (C|CISO).

Dr. Ofori started his career as a technical networking specialist; he then specialized, trained, and qualified in a number of disciplines including but not limited to ethical hacking, international management systems, risk management, business continuity, international governance frameworks, financial service regulations, cyber laws, and project management.

Dr. Ofori is noted for his ability to integrate competing objectives (like a “cloud-first” policy, data transparency, clarity of multiple-party responsibilities, Privacy, and security) in customized and practical compromises that are acceptable to all parties involved. He acknowledges that information security is multi-disciplinary, multi-departmental, and often multi-organizational. He is also noted for his ability to synthesize and document cybersecurity policies in contracts, security architectures, system security requirements, risk assessments, project plans, policy statements, and other clear action-oriented documents.

Also see:

Expert Opinion: Cybersecurity Awareness Month


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

More stories from Brian

Sideloading: A New Malware Delivery Method via Spam Email

Cyber Espionage Campaign Naikon APT

Cybercriminals often rely on different malware campaigns to exploit new vulnerabilities and break into critical network systems. The latest security research from the Mimecast threat center uncovered a new malware campaign via Sideloading technique. The threat actor behind this campaign is known for delivering Trickbot and BazarLoader malware payloads on the compromised system that leads to ransomware attacks.

What is Sideloading?

Sideloading is the process of adding an application that is not vetted by the developer of the mobile’s operating system. Threat actors leverage Sideloading technique to spread malware via fake or malicious apps across end-users.  Sideloading method enables access to mobile applications that are unavailable in official app stores.

Exploiting Microsoft Feature

The researchers stated that the attackers behind the campaign had exploited a feature in Microsoft’s App Installer. The App Installer is a software component of Windows 10 used for the installation and maintenance of applications. It allows the users to sideload Windows 10 apps from a web page while bypassing the Windows store.

“Unfortunately, a threat actor known for spreading Trickbot and BazarLoader, which deliver spam often resulting in ransomware attacks, has exploited this feature. This is yet another example of the importance of updated email antispam software to help prevent ransomware attacks,” the researchers said.

The researchers found that scammers sent legitimate-looking emails with malicious attachments to unwitting users, tricking them to click or download. The attackers created a sense of urgency by keeping the email subject as a customer complaint. Instead of downloading, the users are tricked into thinking they need an app to view the email attachment. But when users click install, they end up downloading an app bundle used by Windows 10 containing malware.

The researchers claim that this campaign has been seen more than 16,000 times across varying countries, including the U.S., the U.K., Germany, Australia, and South Africa.

Conclusion

This campaign represents the importance of implementing robust email security software by organizations to prevent malware threats. Companies can initiate an effective email antispam security and train their employees on phishing threats, eventually strengthening the overall security posture.

Nucleus:13 – Critical Vulnerabilities Found Affecting the Nucleus TCP/IP Stack

healthcare cybersecurity, Nucleus:13

Researchers at Forescout Research Labs, with support from Medigate Labs, discovered vulnerabilities affecting Nucleus TCP/IP stack, a software that powers devices across the health care system.  The lab has discovered a set of 13 new vulnerabilities, which could lead to remote code execution, denial of service, and information leak. The vulnerabilities have been named as NUCLEUS:13.

About Nucleus

Nucleus, a real-time operating system (RTOS), is used in safety-critical devices, such as anesthesia machines, patient monitors, etc. The system powers devices that are extensively used in the health care, automotive, industrial, and aerospace industries. Siemens (which acquired Nucleus in 2017) has released patches for all the vulnerabilities.

The vulnerability was discovered under an initiative by the Forescout Research lab, named Project Memoria. The industry peers and academia came together to analyze the security of multiple TCP/IP stacks. Some of the vulnerability studies published under the project are AMNESIA:33, NUMBER:JACK, NAME:WRECK, and INFRA:HALT. The project ran over a period of 18 months and exposed a total of 97 vulnerabilities, affecting 14 TCP/IP stacks.

The vulnerability if exploited, could cause critical health care systems like monitoring machines, imaging machines and life support systems to crash.

Criminal Minds

The health care sector has been a constant target of cyberattacks, especially in the pandemic when the vulnerabilities were more evident and easily exploited.

Roman ZhidkovRoman Zhidkov, CTO, DDI development, in an exclusive article for CISO MAG, opined, “Health data security is an even more important issue to focus on than financial data security. Because often it is much harder, frustrating, costly, and time-consuming to correct and restore health data. Medical records, when breached, cannot be changed or cleaned at the touch of a button – the damage is irreversible. For health care organizations, a health data breach can be financially and reputationally destructive and lead to shut down.”

A study conducted by Armis revealed that 85 % of IT professional respondents did see an increase in cyber risk over the past 12 months, and 58% of IT pros in health care stated that their organization had been hit with ransomware. Increased digitization and remote health monitoring have resulted in a significant surge in connected devices — expanding the attack surface.

See also: Cyberthreats: The Stealthily Spreading Cancer in the Health Care Sector

 

DDoS Attack on VoIP Provider Telnyx Impacts Global Telephony Services

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

Cybercriminals often leverage Distributed Denial of Services (DDoS) techniques to disrupt critical services of global organizations. Days after a massive DDoS attack on multiple voice over internet protocol (VoIP) services in the U.K., Telnyx reported that it had suffered a DDoS attack that impacted its global telephony services. Telnyx is a voice over Internet Protocol (VoIP) company that provides telephony services online across the U.S., APAC, Australia, and EMEA regions. In DDoS attacks, threat actors make a targeted network or service unavailable to its users by flooding it with unwanted incoming traffic from different sources.

Two DDoS Attacks in a Day

Telnyx confirmed that it sustained the increasing intensity of DDoS attacks twice in a day. “It is anticipated that the DDoS attacks will continue, but there is no way for us to predict it. Telnyx has not been in communication with the bad actors. There has not yet been a ransom request,” Telnyx said in a statement.

What is Telnyx doing to mitigate the incident?

Given the severity of the attack, Telnyx is moving its operations to Cloudflare Magic Transit to mitigate additional risks. The company warned that users might experience failed calls, API and portal latency/time outs, and/or delayed or failed messages until proper resolutions are made.

“We are working through the night to transition as much of our network as possible to this service. We are continuing to migrate all regions of our global network behind CloudFlare’s DDoS protection. For migration updates, please visit http://status.telnyx.com. Services are operational, and teams are monitoring for signs of further disruption. We continue to fortify our DDoS protection, working directly with CloudFlare to implement protection across our network. Configuration is complete & we are testing traffic. Teams are monitoring for signs of further disruption,” Telnyx said in a Twitter post.

Rise of DDoS Attacks

Several global organizations have reported that their services were impacted due to DDoS attacks. Most of the DDoS campaigns are suspected of running an extortion scheme against the victim organizations. A recent report from Kaspersky revealed that the Q3 of 2021 has recorded more DDoS attacks than the previous year. The total number of DDoS attacks was up 24% compared to Q3 2020. Kaspersky observed over 8,825 DDoS attacks on August 18, with over 5,000 on August 21 and 22. However, the average and maximum durations of DDoS attacks in Q3 of 2021 decreased to 284 and 339 hours, respectively.

Expert Opinion

DDoS attacks could create huge damage to victims’ operations, making it difficult for a single defender to stop the flood of incoming traffic.

Nathan Wenzler Explaining the impact and severity of DDoS attacks, Nathan Wenzler, Chief Cybersecurity Strategist at Tenable, said,  “By their very nature, DDoS attacks create a huge flood of network traffic, scaling up and dynamically changing the source of the flood. This makes it incredibly difficult for a single defender to stop the bad incoming traffic. It’s for these reasons that organizations must be able to meet these kinds of threats with defenses that can equally scale and be flexible in response to these attacks.

“Organizations can leverage perimeter-level defenses, which can be maintained by an internal team and operated automatically to detect DDoS traffic and block the incoming traffic dynamically, preventing impact to core critical systems. Additionally, organizations can leverage the services of large-scale Content Delivery Network (CDN) providers who incorporate anti-DDoS technologies into their platforms. These providers typically maintain massive, global network infrastructures which can scale up in response to absorb an incoming DDoS attack. Ultimately, any strategy that can meet the DDoS attack with the same level of automated scaling capabilities while providing an equally dynamic response will be what’s needed to thwart these massive network flood attacks,” Wenzler added.