Home Blog Page 395

Microsoft discovered 71 new ransomware families in first half of 2017

microsoft ransomware cybersecurity CISOMAG, Microsoft Patch Tuesday October 2020

Microsoft recently came out with its Security Intelligence Report which highlighted a global increase in ransomware. The researchers discovered 71 new families of ransomware in the first half of 2017; the number of new ransomware families in the first half of 2016 was 64.

A number of ransomware families used new techniques while some have improved their techniques. The most commonly encountered ransomware family in the first quarter was Cerber, however, it gave way to Spora in the month of March. According to the report, Spora “Spora encrypts files with several popular extensions, including .doc, .docx, .jpg, .pdf, .xls, .xlsx, and .zip. It avoids encrypting files in the Games, Program Files (x86), Program Files, and Windows folders. Early versions of Spora targeted Russian speakers, although English language
versions have also been seen.”

The report also highlighted that Consumer and Enterprise Microsoft accounts are under more threat than ever. The company’s Identity Security and Protection team saw a 300 percent increase in user accounts attacked over the past year. The company said most of the breaches are the result of “weak, guessable passwords and poor password management, followed by targeted phishing attacks and breaches of third-party services.”

Security Intelligence Report also featured global ransomware outbreaks WannaCry and Petya that wreaked havoc earlier this year. “WannaCrypt and Petya defied the trend of more targeted and localized attacks and became the first global malware attacks in quite a while. They generated worldwide mainstream interest. Interestingly, this attention might have added more challenges for attackers.“

Critical security flaw in Apache Struts puts Fortune 100 companies at risk

Breach Apache Struts cybersecurity

A team of security researchers at LGTM recently discovered a security flaw in Apache Struts that allows hackers to easily breach an affected server to gain access to sensitive corporate data. The weakness enables the attackers to remotely run code on server running applications using REST plugin built with Apache Struts. Reportedly, all versions of Struts since 2008 are affected. As many Fortune 100 companies use Apache Struts for providing web applications in Java to power front and back-end applications, the vulnerability could put them at risk.

The team of researchers was led by Man Yue Mo, a security researcher at LGTM. According to Mo, only a web browser is enough for a hacker as Struts is used in airline booking and internet banking systems and many such publicly accessible web applications. Semmle provided the analytical software that was used to discover the security flaw.

Semmle’s product manager Bas van Schaik, said, “I can’t stress enough how incredibly easy this is to exploit. If you know what request to send, you can start any process on the web server running a vulnerable application.”

Mo also said that the security flaw is caused due to the process of deserializing the untrusted data by Struts. Apparently, the vulnerability can be exploited by attackers to run commands on firewall protected servers. The servers can also be used to bypass the corporate firewall and access the restricted network areas.

van Schaik further said that the weakness even allows a hacker to delete the data on the network. “An attacker can use the vulnerability to find the credentials, connect to the database server, and extract all data. A creative attacker will have a field day. And even worse: The organization under attack may not even notice until it is well too late,” he added.

According to him, there was no occurrence of any exploit of this vulnerability. However, he cautioned that the public announcement of the details could change the scenario.

Reportedly, an exploit has already been developed by the researchers but they did not release it to give some time to companies to patch their systems. Apache also released a source code fix a few weeks ago and a full patch this week.

Four million customer records exposed in Time Warner data breach

TImeWarner CISO MAG cybersecurity

BroadSoft, the software and service provider trusted with the safety of the customer records of Time Warner Cable, exposed millions of customer records online after its two cloud-based AWS S3 buckets were discovered open to the public. The error by Broadsoft affected almost four million customers; the breach is currently under investigations, according to sources.

The breach was discovered by the researchers at Kromtech Security Center, who later informed Broadsoft about it. According to Kromtech, the leaked information included transaction numbers, MAC numbers, user names, account numbers, types of service purchased as well as some internal development information like SQL database dumps and code with login credentials. The data was collected from November 10, 2010, to July 7, 2017.

Kromtech further wrote “They used Amazon’s cloud but misconfigured it by leaving it accessible. Amazon AWS buckets are protected by default but somehow were left publically available. It is most likely that they were forgotten by engineers and never closed the public configuration. This would allow anyone with an internet connection to access extremely sensitive documents.”

Commenting on the issue, Jeff Hill, the director of product manager of third-party risk management solutions provider Prevalent, said, “The Broadsoft episode underscores the relevance of the age-old aphorism ‘never attribute to malice that which can be reasonably explained by stupidity.’  Visibility into your vendors’ controls via a comprehensive third party risk management program provides insight into not just the controls and technologies that prevent or mitigate attacks by the bad guys, but also the procedures and policies that are meant to prevent untrained or careless employees acting innocently to inadvertently expose sensitive data in the vendors’ custody.”

US Senator Shaheen proposes federal ban on Kaspersky products

Kaspersky Lab

The predicament for Russian cybersecurity firm Kaspersky to continue operations in the United States has hit another major road block. After the amendment in the bill by the United States Senate which sought a ban on all Kaspersky Labs products from Department of Defense budget, Senator Jeanne Shaheen is now pressing for a federal government-wide ban of all Kaspersky Lab products in U.S.

According to a statement released from Shaheen, the company have been involving in malicious activities, with founder of Kaspersky, Eugene Kaspersky, instructing his staff to work on a secret Project “per a big request on the Lubyanka side,” a reference to the F.S.B.’s Moscow offices. “The Kremlin hacked our presidential election, is waging a cyberwar against our NATO allies and is probing opportunities to use similar tactics against democracies worldwide. Why then are federal agencies, local and state governments and millions of Americans unwittingly inviting this threat into their cyber networks and secure spaces?” She pointed. “That threat is posed by antivirus and security software products created by Kaspersky Lab, a Moscow-based company with extensive ties to Russian intelligence. To close this alarming national security vulnerability, I am advancing bipartisan legislation to prohibit the federal government from using Kaspersky Lab software.

“When a user installs Kaspersky Lab software, the company gets an all-access pass to every corner of a user’s computer network, including all applications, files and emails. And because Kaspersky’s servers are in Russia, sensitive United States data is constantly cycled through a hostile country. Under Russian laws and according to Kaspersky Lab’s certification by the F.S.B., the company is required to assist the spy agency in its operations, and the F.S.B. can assign agency officers to work at the company. Russian law requires telecommunications service providers such as Kaspersky Lab to install communications interception equipment that allows the F.S.B. to monitor all of a company’s data transmissions.”

Shaheen cited that intelligence officials during a public hearing had stated that they weren’t comfortable with using Kaspersky Lab software in computers at the intelligence agencies. Adding, “Americans were outraged by Russia’s interference in our presidential election, but a wider threat is Russia’s doctrine of hybrid warfare, which includes cybersabotage of critical American infrastructure from nuclear plants to electrical grids. Kaspersky Lab, with an active presence in millions of computer systems in the United States, is capable of playing a powerful role in such an assault. It’s time to put a stop to this threat to our national security.”

Shaheen was instrumental in introducing the amendment to the Senate defense policy legislation which banned Defense Department from using Kaspersky Lab software. Following which Eugene wanted to testify before the U.S. Department of Defense with the source code of the company. “I do understand why we look strange. Because for Russia it’s very unusual, a Russian IT that’s very successful everywhere around the world. But it’s true.”

China bans fundraising activities through digital currency

Chinese Government Shuts 173 Cryptocurrency Exchanges

Following a series of major security breaches of digital currency exchanges during their Initial Coin Offerings, China has banned the use of virtual currencies such as Bitcoins for investments in fundraising activities.

A joint communication by the People’s Bank of China, China Securities Regulatory Commission, China Banking Regulatory Commission, and China Insurance Regulatory Commission said, “As of the date of this announcement, all types of [digital] currency issuance financing activities shall cease immediately,” The statement also said that cryptocurrencies “do not have legal status equivalent to money,”. Organizations and individuals who completed their financing would have to make arrangements to return funds used to buy tokens.

The announcement had a big impact on the market value of various cryptocurrency vendors as various reports suggest a drop in the valuation of the digital currencies. A blog post from cybersecurity firm ESET said, “Whether the move by China can be viewed as a way to remove any possible hacking threats, or if it’s simply a way for them to slow the growth of these cryptocurrency exchanges so they can put stricter regulations in place, remains to be seen,”

There have been some major cyber breaches related to these cryptocurrencies in the recent past that have affected virtual currency exchanges, their users, and their investors. One such incident occurred during the month of August, where hackers stole around $500,000 in Ethereum from cryptocurrency trading platform provider Enigma. The incident left many professionals skeptical about the cybersecurity concerns related to cybersecurity.

US Army ties up with IBM for Cloud Services

IBM CISO MAG Cybersecurity

IBM recently announced that the U.S. Army’s Logistics Support Activity (LOGSA) awarded IBM a contract to continue providing cloud services, software development and cognitive computing, constituting the technical infrastructure for one of the U.S. federal government’s biggest logistics systems.

The 33-month, $135 million contract represents a successful re-compete of work that LOGSA signed with IBM in September 2012. Under that managed services agreement, the Army pays only for cloud services that it actually consumes. The efficiencies created by this arrangement have enabled the Army to avoid about $15 million per year in operational costs.

In addition to continuing to provide managed services as part of this new contract, IBM also will help the Army focus on:

  • improving cybersecurity by applying the risk management framework (RMF) security controls to LOGSA’s IT enterprise. RMF is the unified information security framework for the entire U.S. federal government; it replaces legacy IT security standards;
  • incorporating cognitive computing that enhances readiness by anticipating needs, and
  • speeding application modernization.

As part of this new contract, IBM also will help the Army predict vehicle maintenance failures from more than 5 billion data points of on-board sensors that will be stored within this environment. In addition, the Army is adopting Watson IoT services and a new Watson IoT Equipment Advisor solution that analyzes unstructured, structured and sensor data directly from military assets.

The solution, part of the IBM Watson IoT for Manufacturing and Industrial Products product suite, includes IBM Predictive Maintenance and Quality System, an integrated solution that monitors, analyzes, and reports on information gathered from devices and equipment and recommends maintenance procedures. It also includes Watson Explorer, a cognitive exploration and content analysis platform that enables users to securely capture and analyze both structured and unstructured data. With the platform, the Army will look to extract enhanced insights from its vehicle data and recommend optimal repair methods and procedures. By combining tactical vehicle sensor and maintenance data, the Army better understands the health of its vehicles and can take proactive repair measures.

IBM recently completed a proof of concept that demonstrated the effectiveness of Watson cognitive computing for 10 percent of the Army’s Stryker vehicle fleet. Under this new contract, LOGSA will increase its ability to provide that predictive and prescriptive maintenance information to the Army.

LOGSA provides on-time integrated logistics support of worldwide Army operations, impacting every soldier, every day. As the Army’s authoritative source for logistics data, LOGSA provides logistics intelligence, life cycle support, technical advice, and assistance to the current and future force; integrates logistics information (force structure, readiness, and other logistics data) for worldwide equipment readiness and distribution analysis; and provides asset visibility for timely and proactive decision-making.

In addition to private cloud deployments, IBM manages five dedicated federal cloud data centers, including a cloud environment accredited up to impact level 5 (IL-5). These were built to meet Federal Risk and Authorization Management Program (FedRAMP) and Federal Information Security Management Act (FISMA) requirements for government workloads.

77% of educational institutions are not prepared for IT risks: Survey

Institutes cyber security

Netwrix Corporation, provider of a visibility platform for data security and risk mitigation in hybrid environments, recently announced the release of its 2017 IT Risks in Education infographics. The findings presented in the infographics are based on feedback provided by IT specialists working for educational institutions around the globe as part of the recent IT Risks Survey conducted by Netwrix.

The 2017 IT Risks in Education infographics provide a deep look into IT security practices, pains, successful experiences and plans in the education vertical. The IT risks are divided into three areas: security, compliance and operations.

The survey’s key findings for the education vertical are:

  • More than three quarters (79%) of educational institutions do not use any software for information security governance or risk management.
  • 72% of educational institutions do not have any dedicated employees responsible for the cybersecurity function.
  • 77% of educational institutions perceive employees to be the biggest threat to system availability and security.
  • 49% of educational institutions have faced security incidents caused by human errors, and 37% have had security incidents due to malware.
  • Only 23% of educations institutions consider themselves to be well prepared to beat IT risks.
  • Educational institutions named lack of budget (74%), lack of time (54%) and insufficient participation of senior management (44%) as the main obstacles to taking a more efficient approach towards cyber risk management.
  • Protecting against data breach and fraud tops the current agenda of 49% of educational institutions.

“Typically, IT departments in the educational sector are understaffed and underbudgeted. Nevertheless, they have to support hundreds of users and meet tightening requirements for data protection. To successfully secure sensitive data and maximize system uptime, educational institutions need to gain visibility into user activity across the entire IT infrastructure. Knowing who does what in which system, who has which permissions, who accesses what files and so on will cost-efficiently facilitate security, compliance and operational tasks, as well as simplify dealing with IT incidents,” said Michael Fimin, CEO and co-founder of Netwrix.

Entefy raises Series A at $150 million valuation

Startup Funding

Entefy Inc. announced that the company has secured its Series A with $8 million of capital at a $150 million valuation. This has brought the company’s total venture funding to date to $17.7 million. The new capital will support the company’s product launch as well as additional hiring.

“Closing our Series A is a significant milestone for the company, adding to Entefy’s already strong momentum in innovation, product development, and hiring. We’ve created an advanced artificial intelligence platform that brings communication, search, and security to a new level,” said Entefy CEO and Co-Founder Alston Ghafourifar. “Internally, we’ve been using the core technology and expect private beta deployments. It’s an exciting time for our team and the AI industry as a whole.”

2017 has already been an active year for Entefy with its advances in core AI, communication, search, and cyber security technology. In May, Entefy announced it had been issued a patent covering state-of-the-art context awareness in digital messages. In March, the company announced the issuance of another patent covering encrypted search, strengthening its data security and search capabilities. These patent issuances follow on the heels of the January announcement that Entefy had filed a group of 13 new patents in artificial intelligence, security, and cyber privacy, bringing total patents filed to 31.

“Our team has been heads down building the first universal communicator,” said Entefy Co-Founder Brienne Ghafourifar. “With our Series A formalized, we look forward to unveiling more about why our team and investors are so excited.”

Entefy was founded by the sibling duo Alston Ghafourifar and Brienne Ghafourifar with vision to democratize digital communication—freeing users from walled garden platforms and protecting them from data insecurity and cyber privacy violations.

Fact-checker site Verrit hacked hours after Clinton’s endorsement

Hillary

The current president of the United States, Donald Trump, has never shied away from stirring up controversies. While social and mainstream media is abuzz with stories mocking/criticizing his regime, the Republican media conglomerates have painted a picture from a rose tinted glass. Several critics have also called it “a parallel universe that operates as a mirror image of its mainstream counterpart with its own ‘alternative facts,’ audience, and interpretation of truth.” To take a dig at Trump’s administration and extend support to the former First Lady and 2016 Presidential runner up, Hillary Clinton, a fact-checking website Verrit was launched.

Verrit was dubbed as the media for “the 65.8 million” people who voted for Hillary Clinton in 2016. Created by former Clinton staffer Peter Daou, Verrit is his attempt to create an online hub for Clinton backers so that they can find easy-to-share facts, stats and other “information you can take out to social media when you’re having debates on key issues people are discussing,” Daou said in an interview. Reports also suggest that the “media platform has also funded a number of organizations that are campaigning against Donald Trump”.

“I’m excited to sign up for @Verrit, a media platform for the 65.8 million! Will you join me and sign up too?” Clinton tweeted on Sunday. But soon after Clinton endorsed the website, Verrit fell victim of a Distributed Denial of Service (DDoS) cyber attack, forcing the website offline.

For starters, DDoS is one of the common digital attacks where a website is overwhelmed by traffic from several sources forcing the servers to crash. “Hilary Clinton endorsed @Verrit, our new media platform, an hour ago and we’ve already been subjected to a denial-of-service attack,” Daou said via Twitter on Sunday evening.

Describing the attack Peter Daou wrote, “I had the WILDEST night in the fetid swamps of Hillary hate. These people are PETRIFIED of her. I’ll explain… On a relatively quiet #LaborDay weekend night, Hillary Clinton endorsed @Verrit, the media platform I cofounded. Within seconds, traffic to the site surged and we began getting thousands of signups. Then all hell broke loose. @Verrit was hit with a sophisticated and persistent denial-of-service attack. Our tech team worked for three hours to restore the site. Once the Hillary-bashers got wind of @Verrit, we were inundated with a wave of hate as extreme as ANYTHING we saw during the campaign. There are now threads on message boards plotting about taking @Verrit down. A Wikipedia page was set up with fabricated information.” But despite the attack, Daou claimed that the site had attracted 11,000 new followers after Clinton had extended her support.

Virginia adopts NICE Cybersecurity Workforce Framework

Virginia

To meet the skills gap, Commonwealth of Virginia on August 31, became the first state to formally adopt National Initiative for Cybersecurity Education (NICE) Workforce Framework and incorporate it into existing cybersecurity education and hiring efforts.

The NICE Framework provides a common language to speak about cyber roles and jobs, and helps define personal requirements in cybersecurity. It is comprised of three components namely categories, specialty areas, and work roles and its key audience consists of employers, workers, training and certification providers, education providers, and technology providers.

The federal framework acts as a catalyst for firms and industry sectors with shared needs for a cyber-workforce. Employers can use the framework to provide guidance for Virginia’s workforce education and training partners.

The NICE framework has been adopted by Virginia’s K-12 career technical education programs and community college system, that allows the state to align secondary and post-secondary education and training to support the growing demand for the cluster of cyber security occupations.

To endorse the guideline, Virginia Governor Terry McAuliffe said, “Adding this framework to our current efforts led by the Secretaries of Technology, Education, Commerce and Trade, and Administration will strengthen the commonwealth’s ability to address the high demand for skilled cyber security professionals and enhance our position as a global leader in cyber security”, while adding “Virginia has one of the highest concentrations of cyber professionals in the country, but we need to continue to evolve our workforce education and training efforts to support Virginia’s businesses as they work to meet the challenges of data security and integrity and thwart compromising cyberattacks”.

Virginia Secretary of Technology Karen Jackson told Statescoop, “Everything we do in the cyber world, through the CIO, CISO — Nelson [Moe] and Mike [Watson] — all of it somehow ties back and has a nexus to that [2014] framework”.

In an email to Statescoop, NICE Director Rodney Petersen said, “the organization does not track which states have adopted the NICE Framework or to what extent — only that there are anecdotes of states having referenced it”.

Development of the NICE Framework was done in coordination with the National Institute of Standards and Technology (NIST), a national focused resource that categorizes and describes cybersecurity work.