Home Blog Page 47

Your First 90 Days as CISO – 9 Steps to Success

CEO, cybersecurity, CISO, Future of the CISO

Chief Information Security Officers (CISOs) are an essential pillar of an organization’s defense, and they must account for a lot. Especially for new CISOs, this can be a daunting task. The first 90 days for a new CISO are crucial in setting up their security team, so there is little time to waste, and much to accomplish.

By George Tubin, Director of Product Strategy at Cynet

 SPONSORED CONTENT 

A new guide by XDR provider Cynet (download here) looks to give new and veteran CISOs a durable foundation to build a successful security organization. The challenges faced by new CISOs aren’t just logistical. They include securing their environment from both known and unknown threats, dealing with stakeholders with unique needs and demands, and interfacing with management to show the value of strong security.

Therefore, having clearly defined steps planned out can help CISOs seize the opportunity for change and to implement security capabilities that allow organizations to grow and prosper. Security leaders can also leverage the willingness of organizations to undergo digital transformations to deploy smarter and more adaptive defenses. This is critical, as a good security team can enhance an organization’s ability to scale and innovate. The question is where to start.

9 Steps for New CISOs

The eBook explains how new CISOs should tackle their first 90 days to ensure that each passing week builds on the last, and lets security leaders understand both their current reality, and what they need to improve. Before building a security stack and organization, new CISOs need to comprehend the status quo, what works, and what needs to be upgraded or replaced.

These are the nine steps to new CISO success, according to the guide:

  1. Understanding business risks – The first two weeks of a new security leader’s new job should be spent not doing but learning. New CISOs should familiarize themselves with their organization, how it operates, its security strategy, and how it interacts with the market. It should also be a time to meet with other executives and stakeholders to understand their needs.
  2. Comprehending organizational processes and developing a team – Next, it’s time to look at processes and teams, and how they interact. Before implementing new protocols, CISOs and security leaders should know the processes already in place and how they work or don’t work for the organization.
  3. Building a strategy – Then, it’s time to start building a new security strategy that meets the organization’s business strategy, goals, and objectives, as well as the staff’s career goals and objectives. This will include thinking about automation and how cyber-risks are detected and met, as well as how to test your defenses.
  4. Finalizing strategies and implementation – With a strategy built, it’s time to put rubber to road and get going. Before finalizing your strategy, it’s important to get critical feedback from other stakeholders before bringing a final plan to the board and the executive committee. With final approval, it’s time to start building tactics and plan how to implement the new strategy.
  5. Becoming agile – Once strategies are put into practice, security teams can focus on finding ways to become more responsive, more adaptable, and agile enough to meet any challenge. This includes finding the right project management tools and methods.
  6. Measuring and reporting – Now, it’s time to ensure that the plans that were implemented are properly working. Once things are in place, it’s time to begin regular measuring and reporting cycles to show both the security team and the executive committee that the strategy is working.
  7. Pen testing – This is a critical step and should be an important evaluation of a strategy’s effectiveness. Any good plan should always include rigorous testing to help teams find places where defenses are not working or vulnerabilities that might not have appeared on paper but do in practice.
  8. Building a ZTA plan – Now, it’s time to do away with outdated identity and access management (IAM) paradigms and upgrade to multi-factor authentication (MFA). This also includes upgrading SaaS application security posture, as well as network defenses that can prevent common attacks.
  9. Evaluate SaaS vendors – Finally, and with the goal of using SaaS applications wherever possible, a new CISO must carefully consider existing vendors to find a solution that can cover as many services as possible without requiring complex and potentially risky security stacks.

You can learn more about how CISOs can get started successfully here.


About the Author

George TubingGeorge Tubin is the Director of Product Strategy at Cynet and a recognized expert in cybercrime prevention. He was previously VP of Marketing at Socure and Senior Research Director at TowerGroup where he delivered thought leadership and insights to large enterprises on cybersecurity as well as identity and fraud management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Market Trends Report: Cloud Forensics in Today’s World

cloud forensics

Cloud computing is transforming digital and IT infrastructure at an astounding pace. The pandemic and changing business models have prompted many businesses to migrate their digital operations and storage to the cloud. Today, it is common practice for an organization to adopt a hybrid, multi-cloud approach.

From a security perspective, cloud technology poses many challenges for cybersecurity leaders. One such issue is cloud forensics; scaling the traditional digital forensics process in a multi-jurisdictional and distributed cloud environment has become a challenging task.

The complex nature of the cloud poses multiple challenges to traditional forensics. It has become imperative for security leaders to understand the state of the cloud from the perspective of existing challenges and trends to develop solutions for the further development of information security against current and future threats.

The cloud offers various architectures, service models, processes, and continuously changing paradigms. So, it is challenging for investigators to gain access to data and resources required for forensics – the “artifacts,” as they call it. That includes registry keys, files, timestamps, and event logs. This is digital evidence that can be used in a court of law for criminal litigation.

market tresnds report on cloud forensicsThis Market Research Report titled “Cloud Forensics in Today’s World” is based on a survey conducted by EC-Council’s Cyber Research team. It is backed by the insightful perspectives of industry experts towards various trends and challenges particularly, with digital forensics in a cloud environment.

Key Findings:

  • Both multi-tenancy-related privacy issues and distributed data location were considered equally challenging by one-fourth of the respondents.
  • More than half of the respondents believe the hybrid cloud deployment model presents the most challenges towards cloud forensics.
  • Nearly 40% of the respondents say that a lack of channels for international communication contributes significantly to the legal challenges faced by cloud forensics.
  • There is a growing demand that the SLA should mention when and what data to collect, its purpose and legal liabilities.
  • FaaS (Forensics as a Service) is the most anticipated trend towards improving the cloud forensics domain.
market tresnds report on cloud forensicsTo view the complete analysis and reportage, hit the download button now!

 

Check out our other Market Trends Reports here.

 

 

How to Become a Successful Digital Forensic Investigator?

digital forensic investigator

Digital forensic investigators play an essential role in solving computer-based crimes. A sub-division of forensic science, digital forensics is alternatively known as computer forensics.

With the widespread use of web applications for banking, transactions, and other services, the pandemic-induced remote work has resulted in a massive jump in digital-based crimes. Cybercrime has increased 600% since the pandemic, according to Embroker statistics. As a result, there is a significant need for digital forensics investigators to look into these crimes and assist with data recovery operations.

So, if you are a cybersecurity enthusiast with critical and analytical skills, tracing computer-based crimes may be apt for you.

This article discusses the necessary skills, educational requirements etc., that can help you build a rewarding career in the digital forensics domain. But before we go into the details, let’s learn briefly about this field and the responsibilities of a digital forensic investigator.

Who is a Digital Forensic Investigator?

A digital forensics investigator is a trained professional/expert with impeccable knowledge of forensics principles, data acquisition, and legal procedures hired by law enforcement agencies and private firms. They are required to have an exceptional practical understanding of various concepts pertaining to digital devices (hardware related, software related, encryption, decryption etc.) for conducting a digital investigation. Identifying, collecting, storing, and documenting computer data using digital forensics tools to produce the necessary evidence that may be utilized in a court of law, is known as digital forensics investigation.

During the investigation, the digital forensic expert must understand, reconstruct, and analyze the crime scene, consider which digital device can be regarded as evidence, and extract the required data from the digital evidence. They are responsible for collecting evidence from the crime scene and preserving the pieces of evidence, lest they are tampered with.

The role of the digital forensic investigator differs depending on the nature of the case, i.e., recovering data (erased or lost data), incidents such as hacking and online frauds/swindles, or tracking sources (perpetrator) of a cyberattack. So, they need to learn the various digital forensics steps and phases to execute their tasks in a logical and systematic manner.

Advancing your career as a digital forensic investigator, one must gain specific skills, which we shall highlight in the next section.

Digital Forensics Skills and Requirements

In order to perform the tasks of a digital forensic investigator or analyst, one must be proficient in certain areas besides acquiring specific skills or certifications. The following are the basic set of skills and requirements one must acquire to become a successful digital forensics expert:

Education Requirements

A background in computer science or an equivalent is crucial to begin your career in this field. A bachelor’s in criminal justice can also be a viable option for one to pursue combined with computer forensics training later. Additionally, you can also earn your certifications online from a credible agency or institution. Employers’ requirements vary depending on the kind of profile they are hiring for. Getting a bachelor’s or master’s degree in cybersecurity specializing in digital forensics can also advance your career.

Common Skills

There are certain skills you need to hone to gain mastery in this field. Some common skill sets are discussed below.

  1. Networking Skills: Sound knowledge in networking and connectivity concepts can help you in identifying a network intrusion.
  2. Technical Skills: A thorough understanding of the fundamental technical aspects such as networking fundamentals, technical concepts, digital devices, how a system works, knowledge of different OS etc., can help you to acquire advanced certifications
  3. Analytical Skills: Analyzing the digital evidence and data, cybercrime patterns and attacks etc. requires you to demonstrate critical and analytical skills to think like black hat hackers.
  4. Communication Skills: As a digital forensic analyst, you need to convey technical information in a simple manner, so working on your communication skills should be on your list.

Comprehension of Cybersecurity Techniques

Broaden your knowledge about the latest breaches, vulnerabilities, risks, malware etc., in addition to being well-versed with the terms and concepts of cybersecurity.

Aspire to Learn

Technology is constantly evolving, and one needs to have the desire to learn and stay updated with modern technologies and evolving scope of attacks.

Work Experience

After obtaining skills and required certifications, gaining relevant experience in the required domain as a computer forensics analyst or an equivalent can help you accelerate your career and land you high-paying jobs as well.

How Can You Advance Your Digital Forensics Career with C|HFI

In addition to the skills mentioned above, one must know the various tools, techniques, and other methods used to conduct an investigation. Moreover, organizations prefer people who are well-versed in the digital forensics process and hold advanced from. Thus, increasing the possibilities of getting a job and qualifies them to be digital forensics experts with comparatively higher pay than other IT professionals. In addition, an accredited certification also enables one to apply in government as well as corporations. According to PayScale, the average pay of a certified digital forensic investigator is $64,900 per year.

Digital forensics is also expanding rapidly to include other branches such as Network Forensics, Database Forensics and so on which further increases the scope of employment in diverse fields.

There are various certified digital forensics courses one can pursue. However, earning a credible certification that aligns with the industry-specific roles can broaden your career prospects. EC-Council’s Certified Computer Hacking Forensic Investigator (C|HFI) program is ANSI accredited which offers vendor-neutral training to organizations. C|HFI’s in-depth curriculum, carefully curated based on the numerous methods and digital forensics tools necessary and employed in an investigation, allows you to build a solid foundation. Further, this course validates your skills to be the finest digital forensics investigator.

20+ Job Roles | 4,000+ Job Openings | Avg. Salary of $96,000

Start your C|HFI Certification and Explore New Career Opportunities in the World of Digital Forensics.


FAQs

  1. What are the requirements to become a Cyber Forensic Investigator?

You must possess good technical and analytical skills and have in-depth knowledge about the various operating systems and networking concepts. The primary educational qualifications are a bachelor’s degree in computer science, cyber forensics, or computer applications and a certification course like CHFI, which validates your skillset and gives an overall view of the complete work process of an investigator.

  1. What are the various job opportunities available in computer forensics?

There are numerous job opportunities in the field of computer forensics. One such job role is the cyber forensics investigator, responsible for the thorough investigation of cybercrime. Other roles available are security analyst, network analyst, security consultant, computer forensic technician etc.


References:

  1. https://en.wikipedia.org/wiki/Digital_forensics
  2. https://www.guru99.com/digital-forensics.html
  3. https://en.wikipedia.org/wiki/Digital_forensic_process
  4. https://www.geeksforgeeks.org/chain-of-custody-digital-forensics/.
  5. https://www.forensicnotes.com/how-to-become-a-digital-forensics-professional/
  6. https://cybersecurityguide.org/careers/computer-forensics/
  7. https://online.champlain.edu/blog/top-skills-required-for-computer-forensics-careers
  8. https://www.forbes.com/sites/laurencebradford/2017/04/29/6-skills-required-for-a-career-in-digital-forensics/?sh=461908017fa6
  9. https://www.newindianexpress.com/business/2020/dec/08/cybercrimes-cost-global-economy-over-usd-945-billion-2233285.html

Australia Unveils Ransomware Action Plan to Combat Cyberattacks

Cryptocurrency scams in Australia

With rising state-sponsored ransomware operators and attacks becoming widespread, the Australian government has announced a Ransomware Action Plan to tackle the rising cyberthreats. The government is also collaborating with international and business partners to protect Australians against global ransomware threats.

“We are continuing to observe cybercriminals successfully use ransomware to disrupt services and steal from Australians. Whether it is conducting attacks on critical infrastructure, taking from small businesses, or targeting the most vulnerable members of our community, cybercriminals use ransomware to do Australians real and long-lasting harm,” said Karen Andrews, MP Minister for Home Affairs.

Ransomware Action Plan

The Ransomware Action Plan is built on three objectives – Prepare and Prevent; Respond and Recover; Disrupt and Deter.

The authorities stated the ransomware action plan would ensure that Australia remains a challenging target for cybercriminals. Under the ransomware action plan, the Australian government will:

  • Launch additional operational activity to target criminals seeking to disrupt and profit from Australian businesses and individuals
  • Establishment of the multi-agency taskforce Operation Orcus as Australia’s strongest response to the surging ransomware threat, led by the Australian Federal Police
  • Awareness raising and clear advice for critical infrastructure, large businesses and small to medium enterprises on ransomware payments
  • Joint operations with international counterparts to strengthen shared capabilities to detect, investigate, disrupt, and prosecute malicious cyber actors when engaging in ransomware
  • Introducing a specific mandatory ransomware incident reporting to the Australian Government
  • Introducing a stand-alone offense for all forms of cyber extortion

Cybersecurity Initiatives by Australia 

The Australian government has initiated multiple cybersecurity measures to combat rising cyber and ransomware attacks. The government invested $1.67 billion in cybersecurity funding over ten years via its Cybersecurity Strategy 2020 to build new cybersecurity and law enforcement capabilities.

International Pact to Thwart Cyberattacks

Australia recently partnered with the U.K. and the U.S. to form a trilateral security partnership known as AUKUS. The security pact is committed to maintaining diplomatic, security, and defense cooperation in the Indo-Pacific region. The three nations announced their plans to boost cybersecurity, artificial intelligence, quantum computing, and other critical technologies.

OpenSea NFT Marketplace Bug Allows Hackers to Steal Crypto Wallets

Eterbase cryptocurrency Exchange hacked, OpenSea

Over the past few weeks, several cases of lost crypto wallets have been reported and tweeted on social media platforms. Users have been complaining about zero balance in their crypto wallets; a result of accepting a gift on the OpenSea marketplace.

Taking the lead from these tweets, Check Point researchers investigated the OpenSea platform to discover the vulnerability. The investigation revealed a critical security vulnerability, which, if exploited, allows hackers to hijack user accounts and steal crypto wallets by enticing them through malicious free non-fungible tokens (NFTs).

OpenSea is a peer-to-peer digital marketplace for crypto collectibles and NFTs. It is a platform to buy and sell exclusive digital assets. OpenSea recorded $3.4 billion in transaction volume in August 2021 and has grown to be one of the largest marketplaces for NFT of the crypto world.

Keep vigilant

Exploitation Explained

The security vulnerability on the OpenSea platform allows the hacker to create a malicious NFT and send it as a gift to the target victim.

On viewing the malicious NFT, a pop-up is activated from the storage domain, asking for a connection to the target’s cryptocurrency wallet. Not suspecting the pop-up, the victim clicks to connect their wallet to claim the gift (NFT), allowing the hacker access to the user wallet.

An additional pop-up describing the transaction is triggered, which is also sent from OpenSea’s storage domain. Once the user clicks it without noticing the message, the hacker can steal the entire cryptocurrency wallet. The victims fall prey easily as any action — even liking an art in the system — on the platform requires a wallet sign-in. These messages evade suspicion as these are frequent system notices, which users are accustomed to while operating on these platforms.

Check Point researchers informed OpenSea of their findings, and both the groups have collaborated to address the issue. OpenSea came up with a solution, though it claims to have not identified any case where the attackers have cheated their customers.

Advisory

OpenSea released an advisory to protect its users against the threat, stating the following:

  • While signing wallet actions is required to take certain actions on OpenSea, you should always be careful when receiving requests to sign a transaction with your wallet online. Before you approve a request for your signature, you should carefully review what is being requested and consider whether the request is abnormal or suspicious. If you have any doubts, you should reject the request.
  • Check if the signature request correlates with an expected action.
  • Users should note that OpenSea does not request wallet signatures for viewing or clicking third-party photos or links. Such activity is highly suspicious, and users should not sign transactions that are unrelated to the specific actions on OpenSea.

The crypto market is largely an unorganized sector without stringent policies and regulations in place. This makes it an attractive target for cyberattacks. As these marketplaces were created to enhance the financial sector, countries are viewing them more as a bane than a boon.

China had issued a blanket ban on all crypto transactions and mining to further its crackdown and root out all illegal cryptocurrency activity from its country. Many countries are taking preventive measures to curb the security challenges arising from the DeFi markets.

Also Read:

U.S. DoJ Launches Civil Cyber-Fraud and Cryptocurrency Initiatives

White House Brings 30 Nations Together for Counter-Ransomware Event

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

As announced earlier, the Biden administration has initiated the virtual Counter-Ransomware Initiative meetings joined by ministers and senior officials from over 30 countries to address the growing ransomware landscape. The two-day Counter-Ransomware Initiative meetings will discuss the efforts to improve national resilience, addressing the misuse of virtual currency, laundering ransom payments, disrupting the ransomware ecosystem, and prosecuting the cybercriminals.

The Biden Administration organized the Counter-Ransomware efforts in four parameters:

  1. Disrupt Ransomware Infrastructure and Actors
  2. Bolster Resilience to Withstand Ransomware Attacks
  3. Address the Abuse of Virtual Currency to Launder Ransom Payments
  4. Leverage International Cooperation to Disrupt the Ransomware

 Participating Countries

According to an official statement from the White House, the meetings host several senior ministers and representatives from Australia, Brazil, Bulgaria, Canada, Czech Republic, Dominican Republic, Estonia, the EU, France, Germany, India, Ireland, Israel, Italy, Japan, Kenya, Lithuania, Mexico, the Netherlands, New Zealand, Nigeria, Poland, the Republic of Korea, Romania, Singapore, South Africa, Sweden, Switzerland, Ukraine, the UAE, and the U.K.

In particular, four countries have volunteered to organize specific discussions on:

  • India for resilience,
  • Australia for disruption
  • The U.K. for virtual currency
  • Germany for diplomacy

Russia and China Not Invited

Despite multiple cooperation in several areas, the U.S. government has not invited Russia to the Counter-Ransomware meetings.

“We did not invite the Russians to participate for a host of reasons, including various constraints. However, as I noted, we are having active discussions with the Russians. But in this forum, they were not invited to participate, but that doesn’t preclude future opportunities for them to participate as we do further sessions like these. We do look to the Russian government to address ransomware criminal activity coming from actors within Russia. I can report that we’ve had, in the Experts Group, frank and professional exchanges in which we’ve communicated those expectations,” said a Senior Administration Official from the White House.

Primary Goal – To Curb Ransomware

The Counter-Ransomware Initiative comes in response to a series of ransomware attacks on Colonial PipelineJBS Foods, and Kaseya, which have affected several critical infrastructures in the country. White House stated that several international ransomware operators have targeted organizations of all sizes in the U.S. It has revealed that the global economic losses from ransomware reached over $400 million globally in 2020 and topped $81 million in the first quarter of 2021.

The Biden Administration also called on multiple tech companies in the private sector to modernize their cybersecurity capabilities to protect against ransomware threats.

Episode #15: Malware Through the Green Channel

Malware, Gartner, Prateek Bhajanka, Senior Principal Analyst, Gartner, Inc.

Ransomware has become synonymous with cyberattacks in the last two years and is single-handedly driving conversations and investments in the cybersecurity domain. Organizations that weren’t taking cybersecurity seriously, now have their boards talking about ransomware threats and asking about mitigation strategies. Unfortunately, there is no single control known as anti-ransomware control and the approach needs controls at multiple layers in the organization, spanning across people, processes, and technology.

How are CISOs in India preparing against ransomware attacks? What are the gaps in preparedness that CISOs need to be cautious about?

According to Prateek Bhajanka, Senior Principal Analyst, Gartner, Inc., the preparedness level among the Indian CISOs is on the lower side as compared to their counterparts in matured markets. Backup and data restoration controls are being put at the center of an anti-ransomware strategy, which is less effective in light of “Human Operated Ransomware” attacks.

Indian organizations are emphasizing more on Prevention controls as opposed to reducing the attack surfaces and investing in detection controls. As the ransomware threat actors are leveraging legitimate applications/software, compromised/stolen credentials, and existing vulnerabilities to launch attacks are making it difficult to prevent such attacks.

Organizations should look at focusing on Detection and Response controls to identify malicious behavior exhibited by threat actors, while they are disabling security capabilities/doing lateral movement/data exfiltration to detect such incidents and respond on time.

Organizations should look at implementing frameworks such as the Continuous Adaptive Risk and Trust Assessment model (CARTA) to have a multi-layered approach to combating the threat of ransomware. Multi-layer ransomware attacks need multi-prong anti- ransomware approach.

Irrespective of the existing controls, an organization should always be prepared for an incident. Organizations often don’t have an Incident Response policy (IR) or procedure in place; even if in place, it is revised in the light of evolving threat landscape. In the root cause analysis of the recent high-profile ransomware attacks, it has been brought to notice that organizations had an IR policy or procure in place, but it was generic in nature and not specific to Ransomware attacks.

Bhajanka says organizations should implement an “if you can’t prevent it, prepare for it” approach and look at creating and simulating a Ransomware incident response procedure or playbook.

Prateek Bhajanka is a Senior Principal Analyst for the IT Leaders (ITL) constituency, focusing on Security and Risk Management for Gartner Research. His areas of research include Endpoint protection platforms/Endpoint detection and response (EPP/EDR), malware and ransomware prevention, etc. His key tasks encompass creating high-quality, actionable and consumable written research and give clients insights and advice on various security problems they face. Bhajanka also helps organizations save money on new contracts and renewals on endpoint protection platforms and endpoint detection and response.

Listen to all the CISO MAG Podcasts here.

Thales to Provide Cybersecurity Solutions to Indian Defense Sector

Thales

Indian organizations have become a primary target of various cyberattacks. Several state-sponsored malware campaigns are making rounds to compromise critical infrastructures across multiple sectors in the country. As the government of India focuses on acquiring advanced technologies to defend against rising cyberthreats, French defense firm Thales Group recently announced its plan to provide cybersecurity solutions to the Indian armed forces.

The company is expanding its reach in areas of cybersecurity and other digital solutions in the Indian defense sector, which is focusing on acquiring advanced technologies such as quantum computing, AI, swarm drones, and robotics to defend against evolving security threats.

Commenting on the latest cybersecurity initiative, Patrice Caine, the Chairman and CEO of Thales Group, said, “We are also looking at bringing some key pieces of equipment and systems to contribute to raise our level of involvement in sharing defense technologies with India’s defense sector in the field of sonar, radars and other platforms. We are totally committed to helping India expand its defense production under the ‘Make in India Initiative’ by producing equipment either on our own or with our partners. India has a good talent pool to develop cyber-security solutions, AI applications and big data analytics.”

Rising Cybercrimes in India

Organizations and users based in India have encountered many phishing and ransomware attacks over the year. A recent analysis, Crime in India-2020,” from the National Crime Records Bureau (NCRB) of India, revealed that a total of 50,035 cybercriminal cases were registered in 2020, an increase of 11.8% compared to 2019 (44,735 cases). The NCRB is responsible for collecting and analyzing the cybercriminal data reported in the country. In addition, 73% of organizations in India are likely to suffer a data breach in the next 12 months, a similar survey from Trend Micro predicted. It’s found that lost IP, critical infrastructure damage and cost of outside experts are the significant consequences faced by Indian organizations after a data breach.

Apple Releases iOS 15.0.2 Security Update to Fix IOMFB Bug 

Apple, Apple security update

Apple has released a security update iOS 15.0.2 and iPad OS 15.0.2 to fix a zero-day vulnerability that is actively exploited in attacks targeting iPhones and iPads. 

The vulnerability, tracked as CVE-2021-30883, allows an application to execute commands on vulnerable devices with kernel privileges. This vulnerability is a critical, memory corruption bug in the IOMobileFrameBuffer.  

As kernel privileges allow the application to execute arbitrary code on the device, threat actors could potentially use it to steal data or install further malware. 

IOMobileFramebuffer is a kernel extension for managing the screen framebuffer. It is controlled by the user-land framework IOMobileFramework. 

Per the release, the update is for the following list of devices:  

  • iPhone 6s and later 
  • iPad Pro (all models) 
  • iPad Air 2 and later 
  • iPad 5th generation and later 
  • iPad mini 4 and later 
  • iPod touch (7th generation) 

CVE-2021-30883 Details 

The vulnerability affects an unknown code block of the component IOMobileFrameBuffer. An unknown input or code can be manipulated, which leads to a memory corruption vulnerability. This is going to have an impact on confidentiality, integrity, and availability. The vulnerability database documenting community VulDB has pegged the pricing for this exploit at around USD $10k-$25k and expects to see the exploit prices for this product increasing soon. 

According to the Apple release, upgrading to version 15.0.2 eliminates this vulnerability. 

Stream of Vulnerabilities  

Apple has been regularly releasing security updates for attacks against iPhones, iPads, and macOS devices to safeguard its customers from further exploitation. With the constant increase in incidents of data breaches and zero-day exploits, customers are encouraged to review security releases and apply the updates/patches at the earliest.

Also read: Apple Releases Security Updates for Two Zero-Day Vulnerabilities

Google Unveils Cybersecurity Action Team to Boost Cybersecurity

Google Cybersecurity Action Team Google, EU warns Google

Search engine giant Google announced the formation of a  Cybersecurity Action Team to support the security and digital transformation of governments, critical infrastructure, private enterprises, and small businesses. The Google Cybersecurity Action Team intends to guide customers through the cycle of security transformation and enhance their cyber-resilience preparedness against potential security threats.

The team, which initially begins within Google Cloud, will bring full-spectrum security and customer engineering solutions to help organizations address business and security challenges. It also provides new security solutions to organizations of all sizes as per future requirements.

The Google Cybersecurity Action Team offers:

  • Strategic advisory services for customers security strategies
  • Trust and compliance services
  • Security customer and solutions engineering
  • Threat intelligence and incident response services

“Cybersecurity is at the top of every C-level and board agenda, given the increasing prominence of software supply chain exploits, ransomware, and other attacks. To address these unprecedented security challenges facing organizations in every industry today, we are announcing the creation of the Google Cybersecurity Action Team. The Google Cybersecurity Action Team is part of our ongoing commitment to be the best partner for our enterprise and government customers along their security transformation journey,” said Thomas Kurian, CEO of Google Cloud.

Need for Threat Protection

Ransomware attacks have become rampant in the U.S. lately with the series of supply chain attacks on Colonial Pipeline and SolarWinds. Google dedicated $10 billion over the next five years to strengthen cybersecurity – by expanding zero trust programs, securing software supply chain frameworks, enhancing open-source security, and reinforcing the digital security skills of the U.S. workforce.

The company recently unveiled its plan to auto-enroll 150 million Google users in a two-step verification (2SV) process. It requires two million YouTube creators to turn it on by the end of 2021. Google announced the new security precautions to make users’ sign-in process more secure, acknowledging Cybersecurity Awareness Month.

“It’s great to see a large company like Google Cloud orient itself to support the cybersecurity of all organizations large and small through its Cybersecurity Action Team. The Cybersecurity and Infrastructure Security Agency (CISA) recently established the Joint Cyber Defense Collaborative (JCDC). This initiative will unite government and private sector entities to enhance efforts to prevent and respond to malicious cyber activity against the nation’s critical infrastructure. As part of the JCDC and other initiatives, we look forward to partnering with them and other tech companies in this vital effort,” said CISA Director Jen Easterly.