Home Blog Page 42

Australian Privacy Regulator Slams Clearview AI for Breaching Users’ Privacy

Clearview AI

Australia’s privacy watchdog, the Office of the Australian Information Commissioner (OAIC), stated that Clearview AI had violated privacy laws by harvesting users’ sensitive information without their consent and unfair methods.

Clearview AI is a facial recognition platform that provides software to companies, law enforcement, universities, and individuals.

A joint investigation by the OAIC and the U.K. Information Commissioner’s Office (ICO) revealed that Clearview AI’s facial recognition tool has scraped and saved biometric information of over three billion users. The OAIC stated that Clearview AI has failed to comply with the Australian Privacy Principle (APP) by not adhering to necessary security practices, procedures, and systems.

Clearview AI’s facial recognition tool allows users to upload a digital image of an individual’s face and run a search against the respondent’s database of more than three billion images. The tool displays likely matches and associated source information to the user to enable the identification of the individual. It also cross-references photos scraped from several social media platforms with a database of billions of user-profiles and images.

The OAIC ordered Clearview AI to:

  • Avoid repeating practices that breach users’ data privacy and security
  • Stop collecting scraped images, probe images, scraped image vectors, probe image vectors, and opt-out vectors from Australians
  • Destroy all scraped images, probe images, scraped image vectors, probe image vectors, and opt-out vectors it has collected from individuals in Australia within 90 days
  • Provide written confirmation to OAIC within 90 days regarding the actions taken

Causing Severe Identity Threats  

While Clearview AI claims that its facial recognition technology helps law enforcement agencies to identify suspects, persons of interest, and victims, the latest findings from OAIC reveal the growing criticism by privacy regulators over the controversial technology. Clearview services have been used/tested by law enforcement and police departments across the world.

Clearview AI provided free trials to the Australian Federal Police (AFP), Victoria Police, Queensland Police Service, and South Australia Police agencies from October 2019 to March 2020.

Reports suggest that Clearview AI did not take any steps to stop collecting scraped images of Australians, generating image vectors from those images, and disclosing any Australians in matched images to its registered users. Clearview’s website and form for requesting access to the facial recognition tool remain accessible to Australian IP addresses even after the trial period.

The exposure of Clearview’s intrusive practices will certainly cause security concerns across various government officials.

“Consent may not be implied if an individual’s intent is ambiguous or there is reasonable doubt about the individual’s intention. I consider that the act of uploading an image to a social media site does not unambiguously indicate agreement to collection of that image by an unknown third party for commercial purposes. In fact, this expectation is actively discouraged by many social media companies’ public-facing policies, which generally prohibit third parties from scraping their users’ data.

Consent also cannot be implied if individuals are not adequately informed about the implications of providing or withholding consent. This includes ensuring that an individual is properly and clearly informed about how their personal information will be handled, so they can decide whether to give consent,” the OAIC said.

Australia Imposes Stringent Rules on Social Media Platforms

The Australian government has proposed the Privacy Legislation Amendment (Enhancing Online Privacy and Other Measures) Bill 2021 to safeguard Australians against various data threats online. Attorney-General Michaelia Cash recently released the draft of the proposed Bill, which aims to create a compulsory online privacy code for social media companies, data brokers, and other organizations that operate by utilizing user data. The Bill will primarily require social media platforms to obtain parental consent for minors (users under the age of 16).

Continuous Development of Cloud-Native Apps Makes Organizations Vulnerable

cloud

Businesses have had to relook their strategies and navigate the new normal at a pace unimagined. If one thing has been the centerpiece of the world’s technical response to the pandemic, it is the cloud. While the focus on cloud spiked, so did the cyberattacks targeting cloud services.

As security threats progressively turn sophisticated and complex, cloud security and compliance continue to be the biggest pain points. An integrated approach and understanding security responsibility are key to building a robust cloud security strategy.

Minu Sirsalewala, Editorial Consultant, CISO MAG, interacted with Sanjay Manohar, Managing Director, McAfee Enterprise India, to discuss how securing the cloud in 2021 is becoming a business imperative for business continuity. Manohar also addressed the ambiguity around the shared responsibility model for cloud security, the DevSecOps approach, and the security and compliance requirements.

Manohar, as the Managing Director of McAfee Enterprise India, is responsible for driving accelerated adoption of McAfee’s cloud products, enhancing enterprise-centric product revenues, and improving customer satisfaction across the region.

With a career spanning over 26 years, Manohar’s expertise encompasses sales management and marketing domains across South-East Asia, China, and Asia-Pacific markets. He has in the past held leadership roles at technology giants such as Akamai, Oracle, and Dell at a time when cloud solutions had just begun reshaping the global IT industry. Manohar is a performance-oriented team leader and is committed to building and managing high-caliber teams, functioning in complex environments.

His core strengths include go-to-market strategy and execution, supplemented by his expertise in the areas of SaaS, enterprise software, and networking.

Manohar holds an MBA from the Bharathidasan Institute of Management, a Bachelor of Science degree from Bangalore University, and is an alumnus of the Rashtriya Military School.

Edited excerpts of the interview follow:

As more on-premise applications are moving to cloud, is cloud-native security enough to secure enterprises leveraging complex, hybrid, and multi-cloud environments?  How can cloud-native be made more secure?

There has been an increase in the adoption of cloud, driven by the pandemic, and enterprise cloud usage has increased massively. A large percentage of valuable corporate data is today on cloud. However, there has also been a substantial increase in cloud threats – according to recent McAfee Enterprise research, there were close to 366,000 incidents in India in Q4 2020, with 3.1 million attacks on cloud accounts worldwide!

To ensure effective cloud-native security, a top-down approach to IT security could be beneficial. As cloud-native applications gain prominence, companies have realized that merging the related security responsibilities with their central security teams is the way to go. This evolution is driving a shift from a project-team-led bottoms-up approach to a top-down approach for greater consistency across projects and environments. Apart from that, the automation of security practices via integration with DevOps could ensure that more cloud-native applications will be protected. The deployment of an integrated platform to protect cloud-native applications and infrastructure would make it more secure. Lastly, there is a considerable security maturity gap between cloud-native and non-cloud-native applications. As organizations gradually move to remote working and adopt IaaS and PaaS systems, an increase in investments — in both cloud-native security tools and employee training will go a long way in bolstering security and ensuring that cloud-native becomes safer to use.

Cloud misconfiguration exploits are the Achilles heel for cloud security. Public and open cloud storage buckets are unmonitored, add to it PET technologies (encryption, authentication) that are difficult to automate with unique protocols that each application requires. What cloud security solution is most effective?

By now, most organizations have realized that to ensure data security as they move to cloud, applications may have to be redesigned to become “cloud-native”. However, since cloud-native are continuously developed and deployed, and modern enterprises lack a way to measure cumulative risk, they are vulnerable to security breaches. Starting, March 2020, there has been a massive expansion in outsider assaults on cloud frameworks. The sort of assaults that agitators are following are recognizing the area of sensitive information, discovering how to take advantage of and taking advantage of weaknesses in programming to exfiltrate data.

What is the importance of security and compliance requirements such as data residency and administration access for adopting secured cloud technologies? Is it a driving force for the cloud security market?

Data residency and administration access are vital parts of cloud security for McAfee Enterprise. Depending on the industry an organization is in, it might have to comply with different regulatory frameworks. GDPR, PCI DSS, HIPAA, and HITECH are just a few compliance requirements that they must adhere to. While the ability to demonstrate compliance by meeting specific standards for business continuity and cybersecurity has become a necessity, it has also become a competitive advantage. Continuous compliance enables businesses to identify the risks and make sure they are never caught oblivious, while also being in position to detect, react, and recover from a disruption. Not just that, compliance also helps an organization keep away from the precarious monetary and reputational cost of resistance.

Read the full interview in the December issue of CISO MAG.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

Login Credentials of Shipping and Logistics Firms Being Traded on Dark Web

Shipping and Logistic companies

Cybercriminals have extended their cyberattack targets ranging from supply chains to critical infrastructures. While some threat actors try to penetrate vital network systems and compromise, other cybercriminal groups trade initial access credentials on the dark web. The latest analysis from Intel 471 revealed that the present trends of underground darknet markets have been changing exponentially. It was found that network access brokers (NAB) or initial access brokers (IABs) trade login credentials of international shipping and logistics companies on the dark web.

Shipping and Logistic Firms Targeted  

The increasing risks of cyberthreats become a severe crisis to logistics and shipping organizations worldwide, as they operate across air, ground, and maritime and are responsible for shifting critical goods. Hacker intrusions on these companies could have a massive impact on the global consumer economy as they transport billions of dollars worth of consumer goods.

Also Read: 3 Digital Assets That Are High in Demand on Dark Web Forums

Intel 471 identified a new threat actor and credentials broker in July 2021, claiming to have access to a network owned by a Japanese container transportation and shipping company. The attackers dumped the credentials belonging to over 50 companies on the dark web for sale. In August 2021, the researchers found Conti ransomware operators claiming access to corporate networks belonging to a U.S.-based transportation management and trucking software supplier and a U.S.-based commodity transportation services company.

Intel 471 stated that the threat actors had obtained credentials by exploiting vulnerabilities in remote access solutions such as Remote Desktop Protocol (RDP), VPNs, SonicWall, and Citrix. “Over the past few months, Intel 471 has observed network access brokers selling credentials or other forms of access to shipping and logistics companies on the cybercrime underground. The actors responsible for selling these credentials range from newcomers to the most prolific network access brokers,” Intel 471 said.

Lasting Impact

Stealing login credentials and trading them on the dark web has become a common attack vector for various cybercriminal groups and affiliates. Several threat actors misuse these credentials to exploit the critical network systems, encrypt them, and demand ransom. The threat to critical infrastructure affects the consumer economy of a country. It is also one of the reasons why ransomware impacted organizations are compelled to pay ransom to restore their services at the earliest.

From fuel services, health care services, and food processing supply chains, threat actors exploit every sector to their advantage. Colonial PipelineJBS, and Kaseya attacks exemplify how ransomware is getting bigger by the day.

Russia-linked Conti Ransomware Gang Pillages Jewelry Brand Graff

Ransomware Attacks, Graff ransomware attack

Conti gang, in yet another attack, has targeted a well-known U.K.-based luxury jewelry brand Graff. As per reports, the hackers have pillaged the personal details of the well-heeled clients of the firm and sold a part of the bounty on the dark web.

Russia-based Conti group, responsible for over 400 ransomware attacks recently, is again making headlines with its recent virtual heist at Graff Jewellers firm. Personal details of billionaire tycoons, world leaders, politicians, and Hollywood A-listers, who are clients of the firm, have been stolen and partly published on the dark web to seek ransomware. The A-listers include Donald Trump, Oprah Winfrey, Tom Hanks, David Beckham, Formula One heiress Tamara Ecclestone, former footballer Frank Lampard, Singer Tony Bennett, and Sir Philip Green.

The leaked data includes client lists, receipts, credit notes, and invoices, which could be exploited for personal or financial gain. The hackers claim to have leaked 69,000 documents with critical information on the dark web. They are also demanding millions of pounds in ransom in exchange for the unsold stolen data.

Cache 22

It isn’t an easy choice between relenting to the demand of attackers or taking a stand against a criminal group.

Dan Halpin_CybertraceDan Halpin, Managing Director of Cybertrace, opines, “Non-payment of the ransom is a necessary global strategy for defeating ransomware gangs. Graff Jewelers will lose regardless of their decision, whether that be through ransom payment, loss of business records, or reputational damage. And then, of course, their clients may become collateral damage.”

It’s understandable that Graff Jewellers would choose to protect their clients and pay the ransom. However, this is counteractive to global efforts and will encourage ransomware gangs.

Halpin further added, “Graff Jewellers need to accept that there is no alternative but to work with authorities to collect all forensic data required to investigate and take down the gang. We have seen this strategy work with the recent takedown of the notorious ransomware gang REvil. The only situation the ransomware gangs fear and despise at the same time is non-payment and being investigated globally.”

Delving into the issue of giving in to the ransom demands, SteveSteve Turner_Forrester Turner, Analyst, Security & Risk, Forrester, opined, “Organizations should put themselves in the best position possible by reducing the risk of exposure should something within their organization get compromised and where a breach doesn’t force their hand in terms of having to pay a ransom. Whether or not to pay a ransom is still a very grey area due to the state of security across all organizations big and small, but at some point, we will get to a position where that decision leans more towards no.”

Luxury brands, hospitality, and varied customer rich services depend on their high-end client base, and any vulnerability can lead to complete downtime or closing of business at times. These firms may not be high net worth but have clients who are billionaires with sensitive data. Their IT security budgets are not at par with other industry sectors where data and network security are prioritized. Critical infrastructure, public services, health care, and telecom are among the few sectors that are most frequently targeted. But post-pandemic, there has been a visible trend where attacks are moving to SMBs and end-user services like restaurant chains, boutique shops, and small retailers.

Turner says, “Ransomware operators attack targets that have a higher likelihood to pay such as critical infrastructures such as Colonial Pipeline or folks that have a litany of extremely personal information such as healthcare and public media agencies. The threat to all these organizations, especially ones without significant information security resources, remains incredibly high. The lack of security hygiene has been thrust into the limelight, whether it be organizations not patching their systems to folks getting their credentials stolen via a phishing attack, but it’s really easy to throw stones and place blame when these organizations, big and small that haven’t been given guidance, assistance, and support (financial, regulatory, etc) they needed to implement the basics.”

Global Efforts

The menace of ransomware has been so imminent that there are constructive initiatives put into action globally. In September 2021, CISA and the FBI issued an alert on increased Conti ransomware in over 400 attacks on U.S. and international organizations. The agencies issued a joint advisory listing the technical details of the attacks and suggestions to safeguard the organizations’ systems against the Conti attack.

Resilience and Recovery

Organizations globally are working on their security posture by creating awareness around data privacy and access. It has been asserted on numerous occasions that resiliency and recovery should be prioritized over everything else.

Turner said, “Every organization should be backing up their critical data and storing them offline, enforcing least privilege access across the board paired with multifactor authentication, and implementing comprehensive security monitoring that includes both detection and response. Longer term, moving to the model of zero trust helps provide a significant defense in depth strategy without breaking the bank. These recommendations give companies a significantly better chance of fending off or recovering from ransomware or any other devastating attacks. Even implementing one of these recommendations can make a difference between a company shutting down for a few weeks to recover versus a day or two to get back an operational state.”

The 2021 Cyber Threat Report from SonicWall revealed that over 304.7 million ransomware attacks were reported across the globe in H1 2021. Various reasons lead to the surge in ransomware attacks; however, victims’ willingness to pay up for their compromised data has been the primary reason. According to a recent survey from IDC, nearly 44% of the organizations admitted that they are willing to pay ransom to restore their files and operations in the event of a ransomware attack. The survey also revealed that Australia (60%) and Singapore (49%) are the top-most ransom paying countries.

How to Know if Your Smartphone is Hacked?

Hacked Smartphones

Nowadays, it’s hard to find a person without a smartphone. With the ease of technology, the proliferation of smartphone culture has also brought in various kinds of security threats. A lot of sensitive information is being stored on these smartphones as people use them for online banking, shopping, emails, and other communications. From phishing lures to deploying mobile spyware, threat actors leverage different social engineering tactics to compromise/spy users’ mobile devices.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

The smarter our phones, the more we become vulnerable to cybersecurity risks.

5 Signs Your Phone Is Hacked

While there are no standard measures to determine whether a smartphone is compromised or not, you can find out by observing the functions of your device. Here are five signs that will help you know if your smartphone is behaving erratically or controlled by others:

1. Unusual Messages and Pop-ups

If you are receiving inappropriate messages or unwanted ad pop-ups on your smartphone, it may indicate the presence of mobile malware or spyware. Threat actors often target/trick users with various phishing lures via flashing ads or malicious links, which, when clicked, redirect the users to a hacker-controlled webpage or take full control of the device by deploying additional payloads.

2. Presence of Unusual Apps

There could be multiple reasons for a sudden increase in internet usage. But if mobile data is higher than usual without your consent, your device is likely compromised. Hackers and fraudsters consume your mobile’s data to run their apps in stealth mode in the background.

3. High Usage of the Internet

Identify unusual installs or suspicious apps on your smartphone that you did not download. It could be the act of cybercriminals as they download fake/malicious apps embedded with spyware to monitor users’ activity and steal sensitive information.  If you find any messages you didn’t send or calls you didn’t make, it’s likely a hacker’s act.

Also Read: How to Spot Malicious or Fake Apps

4. Increased Battery Drainage

While a smartphone’s battery life decreases with time, a phone infected with malware or spyware shows a significant battery drain than usual. This is due to the presence of hacker-controlled malware/spyware apps on your device. These malicious apps leverage mobile resources like data and battery to run in the background, monitor the device, and transfer the data to the cybercriminal servers.

5. Slow Performance

Smartphones come with a variety of specifications and capabilities, which also decline over time. But if you feel the performance of your smartphone suddenly has degraded, then it’s time to act. Compromised mobile devices often freeze out, crash applications, and experience continued running of apps even after closing them.

How to Restore Your Hacked Smartphone

  • Download a robust mobile security app or anti-malware software on your device to scan and eliminate malware/spyware from it.
  • Change the login credentials of all accounts immediately.
  • Uninstall all suspicious apps from the device.
  • Inform your contacts to not click/respond to any suspicious messages or links received from you as they could be malicious.
  • If you’re still facing the same issues with your device, restore your smartphone to its factory settings.

How to Protect Your Smartphone from Hackers 

  • Turn off your mobile hotspot and Bluetooth when in public.
  • Avoid using public Wi-Fi and charging points.
  • Don’t leave your device unattended. Always lock it with a password.
  • Frequently review the apps you’ve downloaded on your smartphone. Immediately delete if you find any suspicious apps.
  • Continue using updated anti-malware apps and software.
  • Use VPNs to secure your browsing and keep it private.
  • Always download apps and attachments from trusted sources only (Play Store and App Store).
  • While traveling, avoid using public USB charging points or use a USB condom if you must.

Wrap-Up

Smartphones are an undeniable part of our lives. The increased usage of smart devices has become the primary reason for cybercriminals to compromise devices and steal information. Threat actors will always find new ways to break into smartphones. Mindful use of smartphones, awareness of potential mobile threats, and practicing cyber hygiene can only help users against the rising mobile threat landscape.

Rudra SrinivasAbout the Author

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

More from Rudra

 

How Blockchain and AI will Promote Industrial Growth: An Overview

blockchain

Artificial Intelligence models will soon be combined with Blockchain frameworks to enable automated decision making and a greater scope for creating intelligent financial products. Blockchain provides secure storage of digital monetary assets, while AI allows seamless sharing of data and insights from these networks. The cyber threat landscape is constantly evolving, which means that enterprises are adopting these merger technology trends.

By Karim El Chenawi, CISO, John Doe Invest

Today, we’ll look at how Artificial Intelligence and Blockchain will dominate the technology industry, their various use-cases, and how companies can succeed in staying protected from multiple threats by taking advantage of these trends. Enterprises over public blockchains favor private blockchain networks, and AI models can classify, analyze, and gain insights from financial data. Together, blockchain AI will form a collaborative learning model that assures the trustworthiness of data being shared, ensures its integrity, and makes it convenient for users to extract and share insights, thus ensuring that transactions and the information associated with them are thoroughly validated. Microsoft researchers are working towards making considerable advancements in the Blockchain AI domain to make their innovations more accessible to everyday devices, apps, and IoT networks.

Future of Artificial Intelligence

Investments in Artificial Intelligence technologies are expected to rise by $97.9 billion by 2023, and since the COVID-19 pandemic, the valuation of the AI industry has grown. AI will become increasingly prevalent as organizations will work towards automating day-to-day processes from the supply chain to core business functions. AI will also play a significant role in adopting Cloud technologies by enterprises in 2021, and AIOps providers will help business leaders improve their decision-making processes.

Artificial Intelligence is one of the fastest-growing domains that deal with intelligent machine learning models to automate repetitive tasks and mimic human cognitive thought patterns when analyzing and processing them. With RPA and Deep Learning, organizations will use AI to solve global challenges and foster a data-driven culture that emphasizes producing sustainable deliverable models.

Blockchain Industry Outlook

Blockchain is a decentralized technology used for storing and transacting digital assets by both individuals and organizations. BaaS (Blockchain as a Service) is an emerging technology trend used by start-ups and enterprises to develop cloud-based digital products/services. Federated blockchains are rising in popularity, and the industry outlook shows that “stable coins” will reach an all-time high as a driving force for the top cryptocurrencies in 2020. According to the Blockchain as a Service Market, the market size for BaaS is estimated to reach a valuation of USD 15,455 million by 2023 and grow at a CAGR of 90.1% throughout the forecast period.

How Blockchain Works

Blockchain features multiple blocks and uses three key elements:

  • Data contained within the blocks
  • Nonce, a 32-bit whole number
  • Hash, 256-bit number

Every time data is input into blocks; a nonce is generated. The nonce is tied to a Hash which is used for locating these blocks. The mining process is what’s referred to as accessing blocks in a chain and withdrawing the cryptocurrency. Over 4 billion nonce-hash combinations make it impossible for hackers to guess the unique nonce and find the relevant block. Every block in a blockchain references the previous block, which means miners have to go through all the blocks to find the ‘golden nonce.’ Changes in blocks must be accepted by all nodes in the network before the currency is mined successfully and withdrawn.

Benefits of Combining AI and Blockchain Technologies

Industry leaders in healthcare, finance, government, etc., such as Synapse AI, Ocean Protocol, Enigma, and Numerai, are exploring combining AI and Blockchain to disrupt the technological landscape. Many businesses are already experiencing the benefits of enhanced scalability, traceability, increased efficiency, lower running costs, and smoother operations by simply blending these two tech trends.

Greater Transparency and Increased Security

Blockchain is a type of distributed ledger that offers users more transparency on their digital transactions. Changing a single record would mean making changes to subsequent documents, and this is what makes Blockchain technology so powerful. Only a shared copy of the ledger is distributed to participants in the network. When Artificial Intelligence is combined with blockchain, it results in the creation of “smart contracts.”Smart contracts contain code that executes automatically to simplify business transactions and ensure that pre-defined criteria for agreements are met before crypto trades take place. They are used for making intelligent digital financial arrangements such as insurance policies, legal contracts, crowdfunding agreements and are considered a reliable medium for the exchange of Ethereum. Essentially, by leveraging AI and blockchain, smart contracts take out the middle-men for forming agreements between parties and make trades a lot more seamless.

Smart contracts write down the terms and conditions of agreements between buyers and sellers directly into the code. SingularityNET is a platform that provides hardware and software services through AGI tokens in exchange for adding AI services by users.

Improved Financial Audits

Companies like Walmart enter vast volumes of transaction data into AI systems for review and processing. Blockchain helps in analyzing this information on a datapoint-to-datapoint basis which yields a high level of accuracy. When records are processed in the correct sequence, there is greater confidence in their integrity, reliability, and users don’t have to worry about the possibility of tampering. Blockchains are used in the financial decision-making process by companies and help in the investigation of various transactions, thus preventing duplication, identity thefts, and fraud. 

Efficient Mining

Blockchains consume vast amounts of computing power for managing blocks on “stupid” computers and use hashing algorithms to mine data. When AI is used in conjunction with Bitcoin blockchains, it prevents the need for using ‘brute force,’ approaches for figuring out the combination of characters until one fits in and authenticates the transaction. AI adds intelligent processing for code-breaking blocks and can instantaneously encrypt or decrypt blocks by being fed the proper training datasets. 

Reduced Costs 

Businesses focus on reducing costs while sustaining operations in different industry verticals. Blockchain eliminates the need for intermediaries for drafting contractual agreements while AI automates and speeds up data processing. Together these two technological trends reduce the need for paper-based document storage, and since everyone has shared access to records, it makes it easier to view and manage them. There are no discrepancies in these records, and all the information shared across gets fact-checked and validated.

How Blockchain and AI Augment Each other

Blockchain is a technology used for protecting financial data from cyber thefts, and AI helps services make intelligent decisions when it comes to processing requests and ensuring data security. Many industries use a blockchain because of its secure infrastructure and how well it intertwines with machine learning algorithms to process huge volumes of transactions.

AI and machine learning algorithms converging with blockchain would mean businesses are enjoying more excellent encryption, better performance, and precise decision-making. Here is a list of key applications offered by AI and blockchain.

Increased Computing Power

AI helps in boosting computing resources and power when converging with Blockchain frameworks. Blockchain provides the necessary infrastructure, but organizations require enormous computing power to manage data flow in real-time and access records.

Improved Credibility

Businesses that are hopping onto the convergence of Blockchain and AI are enjoying improved credibility amongst consumers. Brands investing vast amounts into these merger technologies find that they are experiencing greater returns on investments.

Reduced Hacking

Blockchain technology offers tremendous benefits for user privacy, and by converging with AI, it helps prevent illicit digital activities. AI algorithms benefit from getting trained using large datasets and use blockchain to encrypt and optimize business frameworks, thus making transactions or exchanges very secure.

What the Future Holds

As we head towards the future, Blockchain and AI will play a vital role in automating crucial processes across all major industries. Understanding and evaluating the needs of businesses and harnessing enough raw computing power for conducting intelligent automation will be the focus of modern technological evolution. Just as computing power is needed for faster automation, so is a technology like Artificial Intelligence for quicker and more accurate analysis, including deriving insights from large data sets. Organizations are spending upwards of $4.4 billion in 2020 on the blockchain, and global investments are expected to cross $19 billion by 2024. A majority of business respondents report they plan to invest a minimum of $1 million into these distributed ledgers.

Cryptocurrency mining of Bitcoin and Ethereum dominates the Blockchain segment, and many believe that more cryptocurrencies will be mined in the future. Blockchain has the potential to digitize traditional monetary transactions and ultimately make businesses go paperless and virtuous. AI and Blockchain add trust to these transactions and enhance security. Hence companies are increasingly investing capital funds in blockchain AI technology to fuel market growth. The global AI industry is forecasted to grow to $703 million by 2024 at an annual CAGR of 25.3%.

Conclusion

To summarize, the convergence of Blockchain and AI will improve concerns related to user privacy, management, security, and reliability of information shared across IoT systems. Blockchain AI will dramatically address the limitations faced by businesses when streamlining their digital operations and support increased scalability. The more data fed into AI algorithms, the better they become at their work, and the anonymity of Blockchain transactions is what makes combining these two trends so powerful. In the future, companies will be working towards updating legacy systems using these merger technologies and make extensive upgrades to how they store, manage, and share data across centralized servers through Blockchain AI integrations.


About the Author

Karim El ChenawiKarim El Chenawi is an information security specialist with more than 14 years of experience in the online gaming and e-commerce industry. He has profound knowledge of security governance and hands-on experience with corresponding technical details. He is both a specialist and a generalist having had technical as well as strategical roles such as security consultant and Chief Information Security Officer, and he has broad experience of working in a highly regulated environment.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers Use SEO Poisoning to Spread Ransomware

SEO poisoning

Cybersecurity experts from Menlo Labs identified two ransomware campaigns that distributed REvil and SolarMarker backdoors on the targeted networks by using SEO poisoning. The two campaigns, tracked as Gootloader and SolarMarker, are deploying ransomware backdoors employing SEO poisoning techniques.

What is SEO Poisoning?

SEO poisoning, also known as search poisoning, is an old attacking strategy in which threat actors create malicious websites and use different SEO techniques to make them appear on top in search results. In SEO poisoning,  attackers use keyword stuffing, PDF documents, hidden text, and cloaking to manipulate the search rankings and redirect the victims to unwanted applications, phishing sites, malware links, and adware.

Gootloader and SolarMarker Infection Chain

Researchers stated that they have observed over 2,000 unique search terms that led to malicious websites, which automatically deploy malware on the victims’ devices. Threat actors inject malicious websites with trending keywords that users search for. The most used search terms/keywords include:

  • Blue-jacket-of-the-quarter-write-up-examples
  • Industrial-hygiene-walk-through-survey-checklist
  • 5-levels-of-PD-eval
  • Sports Mental Toughness Questionnaire

In addition to these two campaigns, the researchers have identified a rise in attacks designed to bypass the traditional security measures by exploiting the bugs in web browsers and browser capabilities. The compromised browsers are then used to spread malware and ransomware, and steal credentials from the targets.

How the Attack Works

Threat actors usually hide the malware into the websites that redirect the users to the fraudulent websites that host malware backdoors. When a user clicks on the SEO poisoned link, it redirects to the malicious PDF docs and HTTP redirections, after which a malicious payload is downloaded onto the endpoint. Menlo Labs has observed three different payload sizes being downloaded in this campaign. The smallest payload was about 70MB, while the largest was about 123MB.

“All the compromised sites hosting the malicious PDFs were observed to be WordPress sites. Most of the sites were benign sites that were compromised to host the malicious content. During our analysis, we found some well-known educational and .gov websites serving malicious PDFs. As part of our commitment to ensuring a safe Internet, we notified all the affected parties, and these malicious PDFs were taken down,” the researchers said.

Exploiting WordPress Plugins  

In the two campaigns, the attackers did not create malicious websites, instead compromised original WordPress sites with good Google search rankings. The sites were compromised by exploiting an undisclosed vulnerability in the Formidable Forms WordPress plugin of the 5.0.07 version. However, the flaw is now fixed in version 5.0.10 and later.

Conclusion

Most employees spend maximum time on web-browsers, searching for information or using applications. New browser risks like SEO poisoning and other SEO-based manipulations pose a severe security threat to organizations globally. Blocking Windows executable file downloads from unknown sources is highly recommended.

TA575 Hackers Found Using Squid Game Baits to Drop Dridex Malware

Squid Game, Dridex malware

Threat actor TA575 is piggybacking on a popular Netflix web series, Squid Game, as bait to propagate the Dridex malware.

The threat group is sending out thousands of malicious emails to potential victims, enticing them through promises to be a part of the next season, early preview, and access to the show. The subject line read:

  • Squid Game is back, watch new season before anyone else.
  • Invite for Customer to access the new season.
  • Squid game new season commercials casting preview
  • Squid game scheduled season commercials talent cast schedule

The Game Revealed

Proofpoint, a cybersecurity company, first spotted thousands of emails aimed at industries based in the U.S.  The emails used convincing subject lines such as Squid Game is back, watch new season before anyone else, and talent cast schedule amongst many to bait the victim. As a next step, the victim is asked to fill out either an attached document to get early access to the show’s new season or a talent form to become part of the background casting. The attachments are Excel documents with macros which, if enabled, will download the Dridex banking trojan affiliate id “22203” from Discord URLs.

 

The Dridex Trojan

Dridex is a banking trojan commonly distributed through emails containing malicious Excel documents. Researchers have associated Dridex operations with other malware toolkits such as Ursnif, Emotet, TrickBot, and DoppelPaymer ransomware. The motive here is data theft and the installation of follow-on malware such as ransomware.

Per Red Canary 2021 Threat Detection Report, Dridex is ranked at #7 based on the number of customer organizations affected at 5.8%.

The banking trojan shares both code similarities and overlapping infrastructure with Gameover Zeus. The operators of Dridex are referred to by various names, including TA505 and INDRIK SPIDER.  “Dridex has consistently focused on getting into user mailboxes and ushering users into unwittingly executing malicious code on their endpoints,” the report states.

“While Dridex is a threat in and of itself, in 2020 we also observed multiple environments where Dridex led to the ransomware family DoppelPaymer—and we’ve observed the same pattern in early 2021. Similar to other “ransomware precursor” families in our top 10 such as TrickBot, Emotet, and Qbot, the threat of follow-on ransomware emphasizes the need for quick identification and remediation of Dridex in any environment,” the report adds.

The report suggests filtering emails at the mail gateway to mitigate the risk and prevent the spread of the malicious actor.

TA575’s Activity

The BlackBerry Research & Intelligence team has been tracking and monitoring Cobalt Strike team servers associated with the threat actor TA575, a financially motivated cybercrime group, and prolific Dridex affiliate. They are well-known for conducting mass spam campaigns that use malicious document lures to deliver malware such as Dridex, Qakbot, and WastedLocker.

Since February 2021, TA575 has deployed over 50 Cobalt Strike team servers. Per the intelligence team, the actor had been undetected as they use unique values in their configurations and fly under the radar. Cobalt Blue is becoming more popular with TA575, both for deployment of payloads and subsequent lateral movement in networks.

Conclusion

It is no surprise that Squid Game is being used as a rider to deliver the trojan. The popularity of the series with all generations makes it a convincing bait, which will easily trap unsuspecting users. It is an attractive lure because it is the most-watched show with the highest viewership for 2021. A Forbes report states that Squid Game is the #1 show in Netflix Originals history, in terms of household views, 142 million by last count. With a staggering viewership in millions and growing; the potential target pool available to the threat group to attack and interact is much larger than any available vulnerable group. The probability of an interaction with malicious content is more definitive than ever. Banking on the invitation, to participate in the upcoming season, TA575 is taking its chance with both Red and Blue. (The basic premise of the game to participate).

DDoS Attacks Hit U.K. VoIP Providers

DDoS attack on VoIP Providers , DDoS Attacks , DDoS Attack on Yandex

The primary motivation of cybercriminals always differs. Sometimes it’s financial, otherwise it is to disrupt the services and create unnecessary chaos. Threat actors steal sensitive data to trade on the dark web or demand ransom. But to cause interruptions to the services of a targeted organization, cybercriminals mostly rely on Distributed Denial of Services (DDoS) attacks. DDoS techniques are leveraged to target global organizations by taking down their websites and impacting other services more often.

A massive and co-ordinated DDoS attack recently hit multiple voice over internet protocol (VoIP) services in the U.K. Comms Council UK announced that several of its members had been impacted in a DDoS campaign suspected of running an extortion scheme against VoIP providers across the region.

VoIP providers offer internet-based call services to a range of users and organizations, including agencies in the public sector, the police, and law enforcement departments. In a DDoS attack, cybercriminals make a targeted network or service unavailable to its users by flooding it with unwanted incoming traffic from different sources.

“Several Comms Council UK members and international IP-based communications service providers have been subjected to Distributed Denial of Service (DDoS) attacks over the past four weeks, which appear to be part of a coordinated extortion-focused international campaign by professional cybercriminals,” said Eli Katz, Chair of Comms Council UK.

The Impact

Comms Council UK could not specify how many firms were affected in the incident, describing the attack as unprecedented. It is suspected that threat actors exploited weaknesses in VoIP providers to cause maximum damage to the services. With employees working from home, the latest attack on VoIP services could cause severe interruptions to internet-based communication services like Teams and Zoom.

“We’re liaising closely with the UK Government, National Cyber Security Centre, Ofcom & international agencies to share information and details about the nature of the attacks in the expectation of halting this criminal activity as quickly as possible. As our members supply telecoms services to critical infrastructure organizations, including the Police, NHS, and other public services, attacks on our members are attacks on the foundations of U.K. infrastructure. We are confident that, with a joined-up Government-led initiative, this damaging criminal activity can be halted,” Katz added.

VoIP Providers Battle DDoS Attacks

This is a second successful and massive DDoS attack in a few days. Recently, attackers hit a Canada-based VoIP provider VoIP.ms in a week-long DDoS attack. The company provides internet telephony services to users and organizations across the U.S. and Canada.

Rise of DDoS Attacks

The rate of DDoS attacks on global organizations has increased as cybercriminal groups leverage various DDoS techniques to cause severe damage to organizations’ critical systems. A recent analysis from Atlas VPN revealed that cybercriminals launched nearly 5.4 million DDoS attacks in the first half of 2021, an 11% increase compared to the first half of 2020. Out of these, attackers leveraged compromised computer systems and botnet networks in 2.8 million of the attacks.

What Experts Say…

Nathan Wenzler Commenting on the rise and severity of DDoS attacks, Nathan Wenzler, Chief Cybersecurity Strategist at Tenable, said, “By their very nature, DDoS attacks create a huge flood of network traffic, scaling up and dynamically changing the source of the flood. This makes it incredibly difficult for a single defender to stop the bad incoming traffic. It’s for these reasons that organizations must be able to meet these kinds of threats with defenses that can equally scale and be flexible in response to these attacks.

He added, “Organizations can leverage perimeter-level defenses, which can be maintained by an internal team and operated automatically to detect DDoS traffic and block the incoming traffic dynamically, preventing impact to core critical systems. Additionally, organizations can leverage the services of large-scale Content Delivery Network (CDN) providers who incorporate anti-DDoS technologies into their platforms. These providers typically maintain massive, global network infrastructures which can scale up in response to absorb an incoming DDoS attack. Ultimately, any strategy that can meet the DDoS attack with the same level of automated scaling capabilities while providing an equally dynamic response will be what’s needed to thwart these massive network flood attacks.”

Why Data Science is Key to Delivering Continuous Authentication

secure and private compute summit, data, data science

Back when security threats were relatively unsophisticated, understanding threats was easier.  Attackers often gained access by generating or guessing passwords. Passwords were drilled into both IT professionals and users as the front line of defense, and users had password creation and usage rules beat into them.  Unfortunately, users often had passwords that were easy to crack, or they were difficult to crack but hard to remember, and written down instead.

By Saryu Nayyar, CEO, Gurucl

Passwords were what we had, and almost universally used, but they leave a lot to be desired. Fortunately, attacks years ago were pretty basic. Over the last several years, that has changed as attacks have become more subtle and pervasive. Passwords are increasingly being overwhelmed by attack techniques that didn’t exist when passwords gained broad acceptance.

Data Science Can Replace Passwords for Authentication

Data science and analytics are changing that equation, though.  Rather than a single binary login, data science offers the opportunity to monitor activity on an ongoing basis, as it occurs.  What does this buy the enterprise looking for a better cybersecurity strategy?

It seems odd that an analytical approach can make a real difference in enterprise cybersecurity, but it’s a very real trend.  Here’s how it works.  The data, which is produced and stored in system, network, and application log files, represents the steady-state of the environment; in other words, normal people do normal things to do their jobs.  With the most sophisticated data science tools, algorithms can even learn how to recognize and distinguish between common activities and other activities that may have an indication of an attack.

The log files of events are examined by algorithms in real-time, and evaluated as normal activity or potentially suspicious.  If an activity is identified as potentially suspicious, it can be investigated further, either by other software or by security professionals.

How is an activity potentially suspicious?  Data science uses classical statistical techniques to determine this.  It classifies activities and evaluates them based on what they do and how frequently they occur.  If some of the activities are unlikely to occur based on statistical results, that might be indicative of an outlier that is an attack.

Data science can also use machine learning models.  These models might fit data in the form of adjustable algorithms, in effect learning what is normal or not by watching the data over time.  The model-based approach tends to be much more effective, in that it customizes its algorithms for that particular enterprise.

Leading to Continuous Authentication

Using data science and analytics opens up the opportunity to employ continuous authentication rather than being dependent on user actions.  Continuous authentication is a difficult concept for many security professionals to get their minds around.  There isn’t necessarily a single login that provides users with all of their privileges.  Instead, every event is checked against the algorithms and evaluated both singly and as a group to determine if it is a normal activity.

Can data science eliminate the need for a one-time authentication such as passwords?  Much of the security industry is already moving in that direction, understanding the difficulties and limitations of passwords.  How does continuous authentication work?

To effectively use data science as a more reliable method of authentication, it’s critical to be able to examine and make decisions on individuals and groups of events in real-time.  It’s not possible to wait until the end of the day to identify a potential attack.

So what data science does is continuously examine all logged activities, with more sophisticated models doing a bit more than that.  Model-based analysis refines this approach to focus on narrowing down the false positives to identify true attacks.  If the sequence of activities is something that a user would normally do, then he or she is allowed to do it.  If it is unusual or clearly an attack, an automated system or IT will intervene.

Continuous Authentication and Changing Mindsets

The mindsets and expectations of both security professionals and users will have to change dramatically in order for data science to be successful in cybersecurity.  Security professionals have to become used to users not physically logging into their systems, the network, or individual application.  Instead, they have to trust that the analytics can more accurately authenticate on an ongoing basis, rather than relying on a password.

And users have to accept that the lack of a traditional login function doesn’t mean that they are free to do anything they want.  They are being observed constantly, and it doesn’t make sense to try to access areas for which they don’t have authorization.

But mindsets will adjust rapidly, and data science just has too many advantages over passwords to ignore.  Count on a rapid sea of change to data science and analytics to offer enterprises better cybersecurity with less effort.


About the Author

Saryu Nayyar CEO GuruculSaryu Nayyar is an internationally recognized cybersecurity expert, author, speaker, and member of the Forbes Technology Council. She has more than 15 years of experience in information security, identity & access management, IT risk & compliance, and security risk management sectors. She has held leadership roles in security products and services strategy at Ernst & Young, Oracle, Simeio, Sun Microsystems, Vaau (acquired by Sun), and Disney. She is passionate about building disruptive technologies and has several patents pending for behavior analytics, anomaly detection, and dynamic risk scoring inventions.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not necessarily reflect the views of CISO MAG.