Home Blog Page 44

Australia Proposes Bill on Parental Consent for Minors on Social Media

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

The Australian government has proposed the Privacy Legislation Amendment (Enhancing Online Privacy and Other Measures) Bill 2021 to safeguard Australians against various data threats online. Attorney-General Michaelia Cash recently released the draft of the proposed Bill, which aims to create a compulsory online privacy code for social media companies, data brokers, and other organizations that operate by using user data. The bill will primarily require social media platforms to obtain parental consent for minors (users under the age of 16).

The draft of the proposed legislation is open to feedback until December 6, 2021, before presenting it in Parliament.

Stringent Rules on Social Media Platforms

The development of the new online privacy code is intended to address various data privacy and security challenges posed by social media services and other organizations that collect a high volume of users’ personal information. The new code requires social media and instant messaging platforms like Facebook, Reddit, and WhatsApp to take all the necessary measures to prevent any data misuse when handling users’ personal data.

The code will require social media services to:

  • Take all reasonable steps to verify the age of individuals who use the social media service.
  • Ensure that the collection, use, or disclosure of a child’s personal information is fair and reasonable in the circumstances, with the child’s best interests being the primary consideration when determining what is fair and reasonable.
  • Obtain parental or guardian express consent before collecting, using, or disclosing the personal information of a child under the age of 16, and take all reasonable steps to verify the consent. Suppose a social media service becomes aware that an individual was under the age of 16. In that case, the social media service must take all reasonable steps to obtain verifiable parental or guardian consent as soon as practicable.

The Bill will also introduce high penalties and enforcement powers to enable Australia’s privacy regulator, the Office of the Australian Information Commissioner, to resolve matters more effectively and efficiently. Companies that fail to follow the law will attract penalties of either 10% of the organization’s annual revenue or a fine of AUD 10 million ($7.5 million).

High Priority to Online Privacy

Attorney-General Michaelia Cash said the proposed Bill would ensure social media services treat Australians’ data more carefully and transparently online.

“We know that Australians are wary about what personal information they give over to large tech companies. We are ensuring their data and privacy will be protected and handled with care. Our draft legislation means that these companies will be punished heavily if they don’t meet that standard,” Cash said.

David Coleman, Assistant Minister to the Prime Minister for Mental Health and Suicide Prevention, said the new code would lead the world in protecting children from social media companies.

“In Australia, even before the COVID-19 pandemic, there was a consistent increase in signs of distress and mental ill-health among young people. While the reasons for this are varied and complex, we know that social media is part of the problem. Young people have told us this themselves. In a 2018 headspace survey of over 4,000 young people aged 12 to 25, social media was nominated as the main reason youth mental health is getting worse. And the recent leak of Facebook’s own internal research demonstrates the impact social media platforms can have on body image and the mental health of young people,” Coleman added.

Aim to Boost Cybersecurity

Australia has initiated multiple reforms and legislations on strengthening the data security and privacy of users online. The government recently passed the Surveillance Legislation Amendment (Identify and Disrupt) Bill 2020, allowing the Australian Federal Police (AFP) and the Australian Criminal Intelligence Commission (ACIC) to spy on potential cybercriminals online. Earlier, Australia also proposed the Ransomware Payments Bill 2021 that requires all organizations to inform the Australian Cyber Security Centre (ACSC) if/when they are considering paying ransom to cybercriminals in the event of a ransomware attack.

NIOPDC Hack Cripples Gas Stations in Iran

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

The National Iranian Oil Products Distribution Company (NIOPDC) was out of service for a day due to a cyberattack that affected the entire distribution network. The network, which has been supplying oil products for over 80 years, consists of more than 3,500 stations across the country.

Since critical infrastructure in the country was targeted, Iran is contemplating it to be a state-sponsored attack; however, the attacker has not been ascertained and the cause is unknown.

As a result of the security breach, citizens were held up at the gas stations for hours and were left without fuel.

Post the hack, a message reading ‘‘cyberattack 64411” was being displayed on the machines. The message relates to the July cyberattack on Iran’s train services. A similar pattern was seen where the railway message boards were modified and messages from the hackers were flashed.

Customers who are entitled to get subsidized fuel at 5 cents or 20 cents a liter under the government scheme were greeted with the hacker’s message “cyberattack 64411”.

Predator or The Hunted

Iran and cyberattacks are inseparable; the country is mostly at the forefront for being behind cyberattacks, particularly targeting Israel and the U.S.

See also: Iranian Hackers Impersonate U.K. Academia in “SpoofedScholars” Phishing Campaign

Iranian hackers are generally considered less advanced in technical exploitation like zero-day vulnerabilities compared to their well-resourced counterparts in Israel, Russia, or China, who are considered experts in social engineering attacks.

High number of ransomware and cyber espionage cases have been attributed to the Iranian hacker community.

Security experts at Proofpoint had discovered an active social engineering campaign by Iran-based threat actors, who impersonated scholars from the University of London’s School of Oriental and African Studies (SOAS) to target senior think tank personnel, journalists, and professors.

Beware! Gummy Browsers Attack Captures Browser Fingerprints

Redline malware, Gummy Browsers attack

Cybersecurity experts discover new kinds of cyberattacks more often as threat actors continue to evolve their hacking techniques. Security researchers from A&M University and the University of Florida recently uncovered a new fingerprint capturing and browser spoofing attack that compromises users’ privacy and security. Dubbed as Gummy Browsers, the attack harvests the browser fingerprinting information without the victims’ knowledge.

What is a Gummy Browsers Attack?

According to the research, the Gummy Browsers attack primarily focuses on obtaining users’ fingerprint details by tricking them into visiting a hacker-operated website. The attackers then spoof the fingerprint to use it on other targeted platforms. The Gummy Browsers attack technique enables a threat actor to disrupt any web application with browser fingerprinting.

Once the attacker obtains the victims’ fingerprints, it can be leveraged to:

  • Bypass 2FA and MFA authentications
  • Spoof users’ online fingerprints to steal identity and conduct frauds
  • Steal personal data by breaking into user devices

Fingerprint Spoofing Methods

The researchers revealed three methods that could be used to spoof the users’ fingerprints online. These include:

  1. Script Injection– In this method, attackers spoof victims’ fingerprints by injecting scripts extracted by the JavaScript API calls.
  2. Browser Setting and Debugging Tool– Attackers manipuate the browser settings and the debugging tool that enable one to alter various attributes of the client device and the browser.
  3. Script Modification– Changing the browser properties by modifying the scripts embedded on the website before it sends it to the webserver.

Risks of Stolen Fingerprints

With the increase in fingerprint and biometric authentication procedures, stolen digital fingerprints have become one of the primary targets of cybercriminals. Threat actors even trade stolen credentials along with fingerprints on various darknet forums, allowing cybercriminals and affiliates to perform scams and frauds.

“Our results showed that Gummy Browsers can successfully impersonate the victim’s browser transparently almost all the time without affecting the tracking of legitimate users. Since acquiring and spoofing the browser characteristics is oblivious to both the user and the remote web server, Gummy Browsers can be launched easily while remaining hard to detect. The impact of Gummy Browsers can be devastating and lasting on the online security and privacy of the users, especially given that browser fingerprinting is starting to get widely adopted in the real world. In light of this attack, our work raises the question of whether browser fingerprinting is safe to deploy on a large scale,” the researchers said.

Five Best Practices to Ensure Responsible Use of Privileged Access

network security, BlackMatter ransomware, privilege

It is now well accepted that identity is the new perimeter in this multi-cloud world and is representing the largest security vulnerability for any enterprise. The Verizon Data Breach Investigation Report 2021 establishes that 61% of data breaches involved credential data and instances of misrepresentation increased by 15 times compared to last year. As enterprises are increasingly adopting IoT, AI, and robotics, and other emerging technologies the cyberthreat landscape is becoming increasingly complex. The recent spate of cyberattacks is a prominent reminder to establish processes and procedures on the management of privileges and address the problem of granting unlimited access to applications, services, or individuals.

By Kumar MSSRRM, Associate Vice President and Delivery Head, Cybersecurity, Infosys

With the diminishing control over physical and network controls, accelerated adoption of remote working, and the rise in dispersed workforce, any identity can become a privileged identity. This renders traditional cybersecurity practices as inadequate. Organizations must strategize on building robust cybersecurity capabilities and access management systems. They must carry out employee awareness programs to address the threat landscape.

Few commonly observed scenarios wherein privileged access are devolved to identities include:

  • Enterprise workforce requiring elevated permissions on a workstation (laptop) to execute business processes or access critical data
  • Third-party vendors requiring access to corporate resources to perform their tasks
  • Application developers or DevOps engineers requiring access to source code
  • Applications or RPA bots requiring access to enterprise resources to perform the workflow tasks

Enterprises face additional risks in the above-mentioned cases, necessitating the adoption of security controls and a culture for responsible and managed use of privileged access. The following principles may be considered to prevent the exploitation of privileged access.

  1. Understand the privileged access footprint: Enterprises should be aware of where privileged accounts exist within their landscape (on-premises and beyond, cloud infrastructure, SaaS applications, hardcoded in legacy/bots). Not knowing this can lead to allowing users to bypass controls and gain elevated access without authorization. Policies should be defined for initial identification and ongoing automated discovery of privileged accounts across the enterprise landscape.
  2. Define policy for rotation of passwords: Enterprises should define password protection and password rotation policy for privileged accounts. As a best practice, it is recommended that all privileged account passwords are updated automatically, and periodically as per the compliance regulations and on a need basis for reasons such as a change in owner or detection of a threat. Further, it must be ensured that the default passwords setup on privileged accounts are changed and the risk of exposure with default passwords is minimized.
  3. Management of credentials for shared and service accounts: Shared accounts typically lack defined ownership and accountability in an enterprise. Privileged access management (PAM) solution is essential to manage such accounts with appropriate auditing of the access and usage of such shared accounts. Service accounts are created with the approach to facilitate the smooth execution of applications and service jobs. Unlawful access to such accounts can allow unauthorized users to move laterally across the network by getting access through a single password. Thus, due care should be taken to make service accounts non-interactive and manage credentials through the PAM solution for controlled usage.
  4. Privileged access governance: Appropriate access governance ensures that privileged access is properly managed and controlled through defined policies, rules, and processes. Enterprises shall invest in extending the access governance solutions to the lifecycle management of privileged accounts including periodic governance of permissions on them.
  5. Zero standing privileges: Finally, in the journey of zero-trust, enterprises must embrace the principles of zero standing privileges, grant of temporary access, and apply the least privilege model for all access credentials. The adoption of context-based decision-making for privileged access will ensure that the enterprise landscape (on-premise, cloud, SaaS, and others) is incrementally protected against the threats of privilege misuse.

In conclusion, the adoption of controls for responsible use of privileged access helps secure the digital transformation journey for enterprises. By incrementally reducing risks and vulnerabilities related to credential theft, lateral and vertical movement, and abuse through privilege escalation, one can safeguard the enterprise data.


About the Author

Kumar MSSRRM Kumar MSSRRM is an Associate Vice President and Delivery Head for Cybersecurity at Infosys. Kumar has over 23 years of experience as an Information Technology professional with demonstrated expertise across various technologies and industries. He has been instrumental in nurturing niche units to high-performing units, leading transformational initiatives, and driving innovation. He is an authority in project and program management practices. He participates very actively in designing collaborative programs with national and international academia. He is a regular speaker at universities and conferences such as the Information Security Forum.

Kumar holds an MTech in machine design and a management degree from the Indian School of Business.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not necessarily reflect the views of CISO MAG.

Microsoft Finds New Activity from Russian Hacker Group Nobelium

Nobelium

Microsoft has identified the latest activity from Nobelium, the Russian nation-state actor behind the SolarWinds attack in 2020. Nobelium is trying to replicate the same approach and has reportedly targeted hundreds of U.S. organizations in its latest wave of attacks.

“We have discovered this campaign during its early stages, and we are sharing these developments to help cloud service resellers, technology providers, and their customers take timely steps to help ensure Nobelium is not more successful,” Microsoft said in an official release.

Old Tactics, New Targets

Microsoft observed that Nobelium used its old attack techniques to target organizations integral to the global IT supply chains, including resellers and other technology service providers that customize, deploy, and manage cloud services and other technologies. As per reports, Nobelium operators are trying to obtain direct access that resellers may have to their customers’ IT systems. Active since May 2021, the group has targeted more than 140 resellers and technology service providers in the U.S., and around 14 resellers and service providers were compromised.

The recent attacks did not exploit any vulnerability in software, instead used password spray and phishing techniques to steal login credentials and obtain privileged access.

“We’ve also been coordinating with others in the security community to improve our knowledge of, and protections against, Nobelium’s activity, and we’ve been working closely with government agencies in the U.S. and Europe. While we are clear-eyed that nation-states, including Russia, will not stop attacks like these overnight, we believe steps like the cybersecurity executive order in the U.S., and the greater coordination and information sharing we’ve seen between industry and government in the past two years, have put us all in a much better position to defend against them,” Microsoft added.

Perspective

Despite several cybersecurity initiatives, Russian hackers continue to target the critical infrastructures in the U.S. The latest activity indicates that Russian state-sponsored actors are trying to access the critical supply chain technology and establish a long-term cyberespionage campaign. However, several cybersecurity experts opine that these kinds of attacks can be prevented if cloud service providers practice robust cybersecurity measures.

Commenting on the latest cybercampaign, Amit Yoran, Chairman and CEO of Tenable, said, “Those who thought SolarWinds was a once-in-a-lifetime attack didn’t see the writing on the wall. The cybercriminals behind the infamous breach are unsurprisingly at it again. This time, they’re targeting Microsoft cloud services resellers through an unsophisticated yet wide-scale attack. The attacks were preventable had companies implemented basic cyber hygiene measures such as enforcing multi-factor authentication, implementing strong password policies, and enabling robust access management.

“Once again, we’re not seeing super sophisticated, never-before-seen techniques behind a major cyberattack. It’s the basics that are still tripping organizations up. What is a relatively new development over the last 12 months is a strategic and continued focus on the software supply chain. This speaks directly to the gaping supply chain security issues that SolarWinds brought to attention — break just one chain link, and you can bring down the entire fence.”

What is an SQL Injection Attack and How to Prevent it?

SQL Injection Attack

With the prevalence of data breaches, the consequences of not securing your databases and network systems could be severe. So, you either boost cybersecurity capabilities or sustain cyber intrusions. Threat actors often target unsecured databases to pilfer sensitive information, and one of their most common attack vectors is SQL injection attack.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

What is an SQL Injection Attack?

Structured Query Language (SQL) is a domain-specific programming language used in managing information stored in a database management system. Security admins send queries to databases via SQL commands to access, retrieve, save, or delete data from the server. Websites and web applications have SQL features used to execute commands. Threat actors often target vulnerable or poorly secured databases to compromise and execute their malicious commands.

How an SQL Injection Attack Works

In an SQL injection attack, an attacker injects a website or a web application with malicious codes to retrieve sensitive information hosted in the database without the admin’s knowledge. The attacker then tricks the server into thinking that the command is legitimate and initiates the data retrieval process. They further leverage vulnerabilities in user-input fields such as login pages, comment sections, product, and support request forms. The attacker can also obtain persistent backdoor access to an organization’s database systems for a long-term compromise.

Risks of SQL Injection Attacks

SQL injection attacks are considered one of the top web application attacks to obtain sensitive information from databases. A successful SQL injection attack can cause severe security repercussions, including unauthorized access to information that is otherwise not accessible, data breaches, altering or deleting critical corporate data.

Many high-profile data breaches in recent times have been executed via SQL injection attacks. Freepik recently suffered a major security breach that affected over 8.3 million users. In a security alert, the company stated that hackers unauthorizedly obtained emails and hashed passwords of its Freepik and Flaticon website users. The data leak occurred after an SQL injection vulnerability was exploited to gain access to one of its databases that held users’ data.

How to Prevent SQL Injection Attacks

Usually, SQL injection attackers rely on manipulating user inputs to execute malicious commands. Some of the preventative measures include:

  • Enabling a robust input validation to monitor input
  • Sanitizing potential malicious codes
  • Validating user inputs
  • Enabling a web application firewall (WAF) to detect any suspicious codes
  • Limiting access to critical systems
  • Updating the systems for timely patch management

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Expert’s Take: Why Organizations Fail to Prepare for Cyberattacks

Prepare for Cyberattacks, incident response plan

Failure is not an option. This was NASA’s motto for the Apollo space and moon missions in the last century. It could well be the motto for organizations today, in the context of cyber readiness. We have an experts opinion on what organizations need to do to prepare for cyberattacks.

In an interview with Brian Pereira, Editor-in-Chief of CISO MAG, Le Nguyen Truong Giang, Global Security Operations Lead and Security Transform Consultant, outlines the various reasons why organizations let their guard down and fail to prepare for a cyberattack. He also offers recommendations on what to include in the incident response plan.

Edited excerpts of the interview follow:

Can you comment on the general state of cybersecurity awareness and state of readiness for a cyberthreat?

In the past, there were many statements like cybersecurity is a shared responsibility or cybersecurity in the workplace is everyone’s business. But most stakeholders didn’t know much about cybersecurity; they did not do enough to protect the business’ information assets. However, the increased volume of cyberattacks is a significant warning that every business is at risk of a cyberattack; they could be victims of a cyber attack or breach. As the result, there are collaborative efforts between government and industry to raise awareness about the importance of cybersecurity and to ensure that all stakeholders have the resources they need to be safer and more secure online. According to many data breach investigation reports, most cyberattacks were traced back to human errors. Obviously, CEOs, business directors, and managers want to keep their data safe or protect their business’ information assets against cyberthreats, so they have to educate their colleagues and create a workplace culture surrounding cybersecurity awareness.

In my opinion, most organizations have already acknowledged business risks related to cyberattacks; but they lack the ability somehow to identify, prevent, detect and respond to cyberthreats. They are facing many difficulties, not only due to limited budgets for technology investment, lack of well-defined processes for building and optimizing, and also skilled security personnel.

What are some of the common causes for a failure to prepare for cyberattacks? Should this be blamed squarely on the leadership?

There are some common causes for a failure to prepare for cyberattacks. Organizations fail to set a top-down strategy to manage cyber and privacy risks. They fail to apply a governance framework to implement and monitor their controls. Senior leaders fail to engage or support cybersecurity programs; they fail to identify areas to prioritize technology investments; they fail to recruit a cybersecurity leader who has a deeper understanding of the complexity of cybersecurity.

The person they recruit must be capable of leading a team and managing cybersecurity programs that align with cyber risks and business requirements.

Business leaders also fail to create a culture surrounding cybersecurity awareness that benefits the entire organization. Further, undefined or not so well-defined processes could be a recipe for failure as well.

Of course, we should not blame it squarely on the leadership because cybersecurity is a shared responsibility; cybersecurity in the workplace is everyone’s business. However, leadership plays a crucial role in creating a robust plan for countering a cyberattack.

What are the steps to prepare a robust incident response plan or IRP?

Even though each business follows a different incident response plan, all IRPs possess the same fundamental components as they go through the same six-phase process. Each of these phases deals with a few specific areas of requirement, which must be fulfilled to create an effective incident response plan for your organization. These phases or steps are preparation, identification, containment, eradication, recovery, and lesson learned.

For instance, IBM Security prescribes six steps to build a robust incident response function:

  • Step 1 – Understand your threats, both external and internal
  • Step 2 – Build a standard, documented, repeatable IR plan
  • Step 3 – Proactively test and improve IR processes
  • Step 4 – Leverage threat intelligence
  • Step 5 – Streamline incident investigation and response
  • Step 6 – Orchestrate across people, process, and technology

Source: IBM Security

To ensure the success of the plan, firstly, we must have support from C-suite executives or key stakeholders who can empower the incident response team to act quickly and confidently during a crisis. Secondly, we must define roles, responsibilities, and processes for incident responding. Lastly, we must have technologies and partnerships to enable autonomous and quick action.


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved foundational certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Lone Wolf Campaign Targets India and Afghanistan with Commodity RATs

Lone Wolf, SideCopy APT

Cyberattacks and malware campaigns against India and its neighboring countries have increased exponentially. Recently, security experts Cisco Talos uncovered a new malware campaign targeting organizations in India and Afghanistan by exploiting a 20-year-old vulnerability in Microsoft Office. Tracked as Lone Wolf, the campaign reportedly deployed a series of commodity remote access trojans (RATs) to obtain full control over the compromised endpoints.

Lone Wolf Attack Phases 

The researchers observed Lone Wolf targeting entities in India and Afghanistan by leveraging malicious RTF documents that deploy a variety of commodity malware to victims. Lone Wolf campaign attacks occur in two phases:

  • A reconnaissance phase that involves a custom file enumerator and infector to the victims
  • An attack phase that deploys a variety of commodity RATs, such as DcRAT and QuasarRAT, on the targeted devices

 How Lone Wolf Attacks

The Lone Wolf operators were found using political and government-themed malicious domains to target the victims. They deployed dcRAT and QuasarRAT Trojans on targeted Windows via malicious documents by exploiting CVE-2017-11882 — a memory corruption vulnerability in Microsoft Office. They also created a Lahore-based fake IT firm called Bunse Technologies as a front to carry out their malicious activities.

The campaign also used malicious RTF documents, PowerShell scripts, and C# downloader binaries to distribute malware, while displaying decoy images to victims to appear legitimate.

“This campaign is a classic example of an individual threat actor employing political, humanitarian, and diplomatic themes in a campaign to deliver commodity malware to victims. Commodity RAT families are increasingly being used by both crimeware and APT groups to infect their targets. These RATs are packed with multiple functionalities to achieve complete control over the victim’s endpoint — from preliminary reconnaissance capabilities to arbitrary command execution and data exfiltration. These families also act as excellent launch pads for deploying additional malware against their victims. Furthermore, these out-of-the-box features enable the attackers to make minimal configuration changes to the RATs, taking away the need for a full-fledged development cycle of custom malware by an actor,” the researchers said.

Increased Use of Commodity RATs

There has been a surge in the use of commodity RATs in recent times. Microsoft recently discovered a campaign targeting airline, cargo, and travel industries, which delivers RAT payloads via spear phishing emails.

 

Microsoft is Attackers’ Favorite for Brand Phishing Attacks

Brand Phishing Attacks

Technology giant Microsoft continues to be the favorite brand of cybercriminals for phishing attacks. According to Check Point’s Brand Phishing Report for Q3 2021, Microsoft has topped “the most commonly imitated brands” list in phishing campaigns. The report highlights the popular brands that threat actors mostly imitated to trick users into giving up their login credentials and other sensitive information in July, August, and September of 2021.

Despite the lower phishing rate, Microsoft continued as the brand most frequently targeted by adversaries – with 29% of all brand phishing attempts, down from 45% in Q2 2021. Amazon has ranked second, with 13% of all phishing attempts as hackers took advantage of online shopping and targeted vulnerable, distributed workforces during the pandemic.

The Top Phishing Brands in Q3 2021

  1. Microsoft (29%)
  2. Amazon (13%)
  3. DHL (9%)
  4. Bestbuy (8%)
  5. Google (6%)
  6. WhatsApp (3%)
  7. Netflix (2.6%)
  8. LinkedIn (2.5%)
  9. Paypal (2.3%)
  10. Facebook (2.2%)

Phishing Email – A Common Lure 

Check Point researchers stated they had witnessed multiple malicious phishing emails specially crafted to steal a Google account access credentials. Hackers sent phishing emails from [email protected] with the subject “Help strengthen the security of your Google Account.” The attackers placed fraudulent and malicious links in the email body, which, when clicked, redirected the user to a fake Google login page to steal victims’ credentials.

Similarly, threat actors targeted LinkedIn members by sending phishing emails via [email protected] with the subject “You have a new Linkedln business invitation from.”

Social Platforms Become Primary Targets 

The report also revealed that social media platforms were among the top three sectors to be imitated in phishing campaigns, with WhatsApp, LinkedIn, and Facebook appearing in the top ten list of most imitated brands. Recently, threat attackers leveraged a malicious version of WhatsApp tracked as FMWhatsapp to distribute Triada mobile Trojan. The fake WhatsApp version displays malware-infused ads, it accesses users’ SMSs, and downloads other Trojans.

How Hackers Perform Brand Phishing

In brand phishing attacks, attackers imitate the official website of a famous brand by creating a similar domain name or URL of the original site. The links to the fraudulent website are then sent to targeted individuals via email or SMS. Once a user clicks the link, it redirects to the fake website, which often contains a form intended to steal users’ credentials, payment details, or other sensitive information.

Point of View

While phishing emails trick users to open/click an attachment/link, brand phishing emails give additional trust to victims, as they imitate popular brands. Attackers mostly choose famous brands as they have a large customer base, and the chance of users responding to phishing emails is relatively high. Popular enterprises like Microsoft, Facebook, and Amazon are always a primary target for cybercriminals. A report from Barracuda divulged how attackers are increasingly getting shrewd in their approach to evade security perimeters and the most recent trends in spear phishing. Nearly 43% of phishing attacks impersonated Microsoft brands, followed by WeTransfer (18%), DHL (8%), and Google (8%).

Mitigation

We recommend users be extra vigilant while providing personal data and login details to business applications or websites. Think twice before downloading any email attachments or clicking links in emails that claim to be from popular companies like WhatsApp, Amazon, Microsoft, or DHL, as they are the most likely to be impersonated or malicious.

DSCI Whitepaper on Encryption Includes Viewpoints from Various Stakeholders

Network Encryption, DSCI Whitepaper on Encryption

Data Security Council of India (DSCI) has launched a whitepaper on encryption titled “Encryption and the Digital Economy: Balancing Security, Privacy and National Security”. The paper offers a holistic viewpoint on the more extensive encryption debate by engaging with stakeholders within academia, government, law enforcement, as well as the industry. The DSCI Whitepaper on Encryption endeavors to widen the horizon around encryption deliberations and bring up the technical, moral, and law enforcement complexities, encryption creates as we attempt to secure personal data and digital services through end-to-end encryption (E2EE).

DSCI is a premier industry body on data protection in India, set up by NASSCOM, committed to making cyberspace safe, secure, and trusted by establishing best practices, standards, and initiatives in cybersecurity and privacy. DSCI brings together governments and their agencies, industry sectors including IT-BPM, BFSI, Telecom, industry associations, data protection authorities and think tanks for public advocacy, thought leadership, capacity building, and outreach initiatives.

DSCI Whitepaper on EncryptionThe DSCI Whitepaper on Encryption extends a deep dive into various perspectives from law enforcement to technology companies, governments, and users. It also provides a detailed overview of the regulatory landscape in India and around the globe on the benefits and challenges of encryption and encryption challenging interventions. The paper offers a comprehensive breakdown of various facets, ranging from encryption’s historical and legal context to the technical and constitutional considerations of breaking E2EE and traceability. It also advises the user to look at encryption as a complex tool with a broad and varied impact that has both primary effects and consequences and secondary implications in criminal justice and law enforcement.

Delivering her remarks at the launch of the DSCI whitepaper on encryption, Rama Vedashree, CEO, DSCI, said, “Encryption has become a ubiquitous part of digital products and platforms and is the necessary protection that underpins digital transactions. Our paper looks at encryption not simply as a security tool but rather places it in the larger narrative around individual privacy, national security, human rights, and the digital economy. It’s important to approach this in a holistic manner and engage all stakeholders in progressive policy-making.”

Prof. Subhashis Banerjee, Professor, IIT-D, said, “End-to-end encryption and traceability are contentious issues for which informed nation-wide debate is essential. I congratulate DSCI for its whitepaper on encryption which can provide valuable inputs for such debates. We also require comprehensive threat models for both privacy and national security requirements without which a complete understanding of the problem at hand will remain elusive.”

Download the Report