Home Blog Page 404

Germany strengthens defense against cyber attacks

Over 126 Mn People are Victims of Cybercrime Across U.S. and U.K.

Joining the bandwagon of the cyber-secured countries in the world, Germany has launched a cyber-command unit which will boast an equal status of that of the army, air force, and navy. With this, Germany has become the first NATO member nation to have a self-contained operational department for cybersecurity.

Christened as the Bundeshwehr’s Cyber and Information Space (CIR), the command unit will shield weapons system and information technology from growing cyber threats. This follows the attacks clocking 284,000 times within the first nine weeks of 2017. Chancellor Angela Merkel was also quoted saying, “Protecting infrastructure from potential cyber-attacks was a top priority and the federal government had to work together with localities on that.”

Lieutenant General Ludwig Leinhos, CIR’s new commander while talking to weekly news magazine Focus said, “CIR will operate and protect the military’s own IT infrastructure and computer-assisted weapons systems, and tackle online threats.” Adding that Germany will be one of the leading countries in terms of cybersecurity.

As per reports, the CIR will commence with 260 IT specialists and will reach the size of 13,500 military and civilian personnel by July, this year.

It would also develop offensive capabilities, because “in order to be able to defend yourself, you have to know the options for attack”, Leinhos, told Focus. However, any full-fledged cyber-attack will require approval from the German Parliament, like any other military mission.

“We are in a constant race between the development of attack options and defensive capabilities. To be able to defend yourself, one has to know which options for attack,” Leinhos told Focus.

Defense Against WannaCry Part of Microsoft’s Patch Tuesday

Microsoft-WannaCry

In action designed to curtail the WannaCry malware, Microsoft has embedded into its most recent Patch Tuesday — its regular security patch release — code to address the tough cyber crime software.

Also known as WannaCrypt and WanaCrypt0r 2.0, the ransomware has spread quickly since its May 2017 release. It is active in over 100 countries and as many as 75,000 computers. Once infected, computers are “locked” by data being encrypted, with a ransom message demanding $300 to subsequently decrypt the data. The cyber attack did particular damage in the United Kingdom, getting into the National Health Service system and forcing some hospitals to temporarily restrict services.

In an unusual move, the release includes a patch for the older Windows XP operating system, which Microsoft stopped supporting in April of 2014. A press release highlights the potency of WannaCry by stating that Microsoft recognizes “the elevated risk for destructive cyber attacks at this time.”

The general manager of the Cyber Defense Operations Center at Microsoft, Adrienne Hall, referenced providing additional security updates with the Update Tuesday release due to the current elevated risk posed by cyber attacks that are backed by government organizations, known as nation-state actors, or other copycat organizations.

Via either Microsoft’s Download Center or Windows Update, the update will protect computers running Windows XP, Windows Vista, and any other recent — unsupported or supported — versions of Windows. The unusual step to support older versions of Windows was based on “an assessment of the current threat landscape by our security engineers” according to a Microsoft press release.

It is strongly advised that the patches be used as soon as possible. Computers running Windows 10 or Windows 8.1 with automatic updates enabled have already had the patch incorporated into their system.

U.S. Attorney General Denies Collusion with Russia

General-Denies-Collusion-with-Russia

The attorney general of the United States, the chief law enforcement agent for the country, vigorously denied in sworn testimony to the Senate Intelligence Committee any collusion with Russian officials that would have undermined the 2016 national election. He termed any such allegation against him an “appalling and detestable lie.”

In a somewhat odd twist, Session said it appears that many in the U.S. intelligence community have now decided that Russia did in fact launch operations to influence the outcome of the election. But he stated that most of his knowledge of this consensus has come from media reports and not direct contact with officials in the U.S. government.

This comes only days after former FBI Director James Comey, testifying to the same committee, stated directly that there had been “massive” Russian actions: “There should be no fuzz on this whatsoever. The Russians interfered in our election during the 2016 cycle … They did it with overwhelming technical efforts.”

Because of Sessions’ role in the campaign of now President Donald Trump, which occurred at a time when he had at least two meetings with Russian officials, he has recused himself from the current investigations into Russian activities. He stated categorically in his testimony that he had not had any talks with Russians “… concerning any type of interference with any campaign or election in the United States.”

The testimony of both Sessions and Comey come in the aftermath of a leaked National Security Agency document detailing how Russian hackers had penetrated far more deeply into the U.S. election system than previously believed.

Along with the already known hacking of the Democratic National Committee, evidence was found of direct attacks on election systems, with attempts to get into voter data files. There are rising fears that the localized voting systems of the United States, which use a wide variety of not always sophisticated software, are very vulnerable to cyber attacks.

Average U.S. Cyber Security Salaries Disclosed

U.S. introduce security bills

At a recent RiskSec Toronto 2017 presentation, Foote Partners reported that senior cyber security specialists in the first quarter of 2017 averaged a salary of $118,887 in the United States. Non-senior specialists earned $100,279 in the same time period, according to David Foote, who holds the IT salary/skills and market intelligence portfolio at Foote Partners. The research focused on 65 cities across the country.

Additional first quarter 2017 findings included: senior information security (infosec) analysts averaged $115, 212, with non-senior averaging $92,179; senior security administrators averaged $88,526, with non-senior administrators averaging $75,847; and security architects averaged $123,009.

This report showing strong wages in the U.S. cyber security labor market echoes studies reporting the same wage pressures across the global economy. The recently released Global Information Security Workforce Study by (ISC)2 outlined the continuing labor shortage in the field, with expected vacancies in information and network security positions over the next five years reaching 1.8 million. It is a seller’s market for cyber security professionals.

The labor market demand in the United States for cyber security professionals is very robust, according to Foote, and is driving wage levels upwards. He summed the situation up by saying it was “… the greatest time since probably the early days of the Internet to be working in this field.”

Cyber Security Threat to National Power Grids Reported

Cyber-Security-Threat-to-National-Power-Grids, Recorded Future

Fears concerning the ability of hackers to launch cyber attacks against national electrical grids have been renewed by a recent report. Partnering in the analysis was the security software firm ESET, based in Slovakia, and Dragos, a U.S. company specializing in data collection that aids in the defense of critical infrastructure.

Malware dubbed “Crash Override” or “Industroyer” was the supposed trigger in an attack on the Ukrainian national electrical grid in December 2016. The cyber crime was a sophisticated one, with industrial computers being ordered to shut down transmission on the electrical grid. The vulnerability of power grids has long been a concern of antiterrorism and cyber warfare experts, and this attack only intensified such fears.

Officials in the Ukraine are blaming Russian hackers, with official sanction from the government, for the attack. This is similar to current accusations in the United States that Russian state-sponsored hackers were involved in disrupting the 2016 election. Officials of the Russian government deny any involvement.

Robert M. Lee, the founder of Dragos, said the malware used in the Ukrainian attack was sophisticated enough to cause power outages of a few days in portions of the national grid, but not yet strong enough to bring down the entirety of the power grid all at once. He went on to report that defensive measures have been developed and shared with the Ukrainian authorities and power companies.

To detect this malware, power utilities will have to create network security procedures specific to it, according to Lee, who has experience as U.S. Air Force warfare operations officer. He added that the malware was able to attack power systems across Europe and that with “…small modifications, it could be leveraged against the United States.”

The technical analysis by ESET was released publicly and stated that Crash Override was “very probably” the source of the Ukrainian power outage, with its December 17 activation time stamp coinciding with the incident.

Crash Override is similar to a 2010 malware code dubbed Stuxnet, which is widely believed to have been used against the Iranian nuclear program in an attack coordinated by Israel and the United States.

Stronger Cyber Security Laws Proposed in Malaysia

U.S. introduce security bills

A proposed cyber security bill in the Malaysian parliament seeks to regulate not only current cyber crimes, but also lay the groundwork to deal with coming threats. According to Communications and Multimedia Minister Salleh Said Keruak, who is a member of the National Security Council (NSC), the bill will focus on cyber security issues posed by extremist groups that use the Internet to recruit members and organize political activity.

The NSC’s National Cyber Security Agency (NSCA) will be in charge of shepherding the bill through Parliament, which will be in session from July 24 to August 10. The NSCA was created in 2016 and uses a variety of existing laws — including the Communication and Multimedia Act of 1998, the Defamation Act of 1957, and the Sedition Act of 1948 — to fight cyber threats.

Though the contents of the bill have not been made public, Deputy Prime Minister Ahmad Zahid Hamidi has publicly stated that it would focus on giving authorities the ability to hamper recruitment drives and interfere with the online fundraising of extremist groups, as well as design preventive measures regarding money laundering and online gambling.

Dr. P. Sundramoorthy, a criminologist at University of Science, Malaysia, said he hoped the bill would be broad in its approach to cyber crime, including creating the analytical and technical abilities to enforce the bill’s provisions. He cited studies indicating that only one in seven cyber crimes are actually reported, which makes it difficult to accurately model which types of cyber crimes are on the rise.

But it is clear that cyber crimes are on the rise. Senior Vice-Chairman Tan Sri Lee Lam Thye of the Malaysia Crime Prevention Foundation cites statistics showing 2,428 cyber crimes reported from January to April of 2017, while online fraud cases in 2016 had risen by 20 percent over 2015 levels. Lee also noted that the government should step up its cooperation with regional and world agencies that are committed to enhancing cyber security.

The bill has the full support of Chief Executive Officer Amirudin Abdul Wahab of CyberSecurity Malaysia, who promises full technical support to governmental agencies that are engaged in protecting the nation from cyber attacks and warfare.

Cyber Security Cooperation Pledge Between Singapore and Australia

cybersecurity-singapore-australia

At the recent Singapore-Australia Leaders’ Summit, the two nations signed a Memorandum of Understanding (MOU) pledging greater cooperation on cyber security issues. The agreement pledges greater information exchange between the nations, including a regular exchange of information regarding cyber attacks and safety, the sharing of best practices in order to reinforce innovative programs in information security, and shared training programs.

Joint cyber security exercises will be held to build network security defenses and deepen the working relationship between the two countries’ tech sectors. A pledge to “promote voluntary norms of responsible state behavior in cyberspace” was also made as part of the agreement, with the first public event in the program being scheduled for late 2017 at the Association of Southeast Asian Nations cyber risk reduction workshop.

The important role cyber security plays in supporting innovation, economic growth, and social development was stressed by Cyber Security Agency of Singapore (CSA) chief David Koh, who was co-signatory of the document with Ambassador for Cyber Affairs Tobias Feakin.

A number of entities in Singapore, including Nanyang Polytechnic and the Singapore Institute of Technology, have signed cooperative agreements with the CSA, as well as the governments of India, France, The Netherlands, The United Kingdom, and the United States. These agreements cover research and development of information security capabilities, cyber security training programs, and internships in the field.

The CEO of Nanyang Polytechnic, Jeanne Liew, spoke of the new definition of national security in the digital age, stressing that it was no longer a term limited to the physical realm.

She also noted the need to keep curriculum updated at all times in order to train students to step directly into the cyber security workforce. Since the methodology of cyber attacks is constantly evolving, the skillsets and understanding of those in the information security profession and those about to enter it need to be constantly improved.

Obsidian Security becomes new entrant in cyber security landscape

Obsidian-Security

Raising an initial $9.5 million via the Silicon Valley venture capital company Greylock Partners, Obsidian Security is about to join the cyber security landscape as a startup. The company is targeting the cloud and data center sectors with cyber safety protections based on artificial intelligence and hybrid-cloud technology.

Its founders include Cylance’s former Chief Technology Officer Glenn Chisholm, who is stepping in as CEO. He has also held the position of chief information security officer at Telstra, a large Australian telecom company.

The chief technology officer for Obsidian will be Ben Johnson, who was chief security strategist and co-founder at Carbon Black, which was bought by Bit9 in 2014, operated as Bit9 + Carbon Black, and has been known as Carbon Black since 2016.

Matt Wolff is the last member of the founding trio, also coming from Cylance, where he worked as the chief data scientist. He will hold the title chief scientist at Obsidian. Wolff also worked as a computer scientist at the U.S. National Security Agency, as did Johnson.

Details about the company’s plans are being held tight to the vest, though one of the Greylock partners who helped raise the startup funding, Asheem Chandna, has said that the company is leaning in the direction of “helping large enterprises better manage and protect user accounts both on-premise and in the cloud.” Chandna, Sarah Guo of Greylock, Chisholm, and Johnson will serve on Obsidian’s board of directors.

The company’s plans to broadly apply AI and machine learning in large networks play to the strengths of Chisholm and Wolff, who led similar efforts at Cylance.

Headquarters for the new company will be in Newport Beach, California, not far from Cylance’s facility in Irvine. Recruitment efforts for staff are underway. According to Chisholm, the goal is to build “a world-class engineering and data science team, focused on user security for hybrid environments. We’re hiring.”

BT launches new services in partnership with ForeScout

BT-ForeScout

The cyber security firm BT has released a new service focused on the mobile device sector. BT Managed Endpoint Security provides tools to ease the management of mobile devices and provide greater security.

This new product line is an outgrowth of BT’s 2015 £12.5 billion purchase of EE, the United Kingdom’s largest mobile phone provider. According to Security Portfolio Vice President David Stark, BT’s global reach and focus on the mobile and IoT sectors make it a “partner of choice for organizations all over the world.”

BT provides packages of cyber security services to corporate customers. These comprise of network tools, unified communications, and direct connections to public cloud providers. A “cloud of clouds” is the concept of their developing strategy.

The company’s strategic partners include firms such as Trend Micro, Symantec, and most recently ForeScout, which is involved in BT Managed Endpoint Security. Technology provided by ForeScout is the foundation for greater real-time visibility and control of mobile devices in the new product line. Administrators will have the capability of classifying, assessing, and monitoring devices, with workflow automation and faster response times also part of the improved security management tools.

According to Stark, the technological expertise from ForeScout will extend BT’s ability to protect organizations against cyber crimes by improving visibility and control of mobile networks. The capability of monitoring almost any device connected to a network will add additional layers of cyber security to companies’ operations, whether at the headquarters or across satellite locations.
The president of the BT Security division, Mark Hughes, has noted that BT’s internal security protocols have been beefed up since the 2016 TalkTalk cyber attack and that BT has been recruiting heavily in order to add more cyber security staff.

Contractor with high-level clearance leaks to press

Contractor-with-high-level-clearance-leaks-to-press

In a case echoing the massive information security breach by U.S. National Security Agency (NSA) contractor Edward Snowden in 2013, another contractor has been brought up on charges of sharing classified material with the press. Though a much smaller incident, the arrest and prosecution of Reality Leigh Winner is another example of weak cyber security protocols plaguing private contractors working for the U.S. government, while also being part of the ongoing Russian cyber warfare story.

Winner is accused of passing to the online publication The Intercept a top-secret NSA document concerning Russian cyber attacks on an American voting software company. The attack featured spear-phishing emails that sought to have employees at the company click on a link that would then give access to the company’s data files to hackers. The email was sent to over 100 local election officials in the days leading up to the November 8, 2016, election in the United States.

The leak brings to light the in-house conclusions of U.S. intelligence agencies that their Russian counterparts were actively seeking to infiltrate the American electoral system with a series of cyber attacks. There is as yet no evidence of successful manipulation of vote tallies, but the operations are clearly of an aggressive nature and a continuing effort to find weaknesses in the network security of governmental agencies.

The document was supposedly not to be declassified until May 5, 2042. Winner is accused of printing it on or about May 5, 2017, and was arrested just two days later. The arrest is one of the first visible actions by the U.S. Justice Department in following up President Donald Trump’s pledge to crack down on individuals who leak information to the press.

Winner had been working at Pluribus International Corporation, probably at their facility at Georgia’s Fort Gordon Army base near Augusta. It appears she was employed at the Georgia Cryptologic Center, nicknamed “Sweet Tea,” which is a 604,000-square-foot facility that gathers electronic intelligence from Europe, North Africa, and the Middle East. It became fully operational in 2012 and it is reported that 4,000 analysts and translators work there. Winner, age 25, is a linguist with a background in the U.S. Air Force and is fluent in several Middle Eastern languages.

It is not unusual for relatively young individuals to have such high-level security clearances, since thousands are trained during their college years to aid in processing and analyzing information that comes in dozens of languages.