Home Blog Page 48

“Incident Response professionals are working in a high-paced and stressful environment”

sriram tarikere, incident response

At the beginning of 2021, when the cybersecurity community was reeling from the aftereffects of the SolarWinds supply chain attack, a new ransomware strain made a disruptive entry. Babuk Locker compromised some of the global corporate networks, encrypted users’ sensitive information, and demanded a lofty ransom of $60,000 to $85,000 in Bitcoins. And since then, ransomware threats have grown in volume and sophistication. It continues to be touted as the “most prominent” threat, crippling the security architecture of critical sectors and SMBs alike. While some companies volunteered to pay the ransom, others focused on building strong incident response and disaster recovery plans.

Pooja Tikekar, Sub Editor at CISO MAG, chatted with Sriram Tarikere, Senior Director with Alvarez & Marsal’s Global Cyber Risk Services in New York, to discuss the need for having well-prepared incident response teams in responding to threats. He also shares ways to respond to a cyber incident in a timely manner, common cloud migration misconceptions, and security predictions for 2022.

Tarikere has over 15 years of experience in executing cybersecurity and privacy risk assessments, ranging from very detailed ISO 27001/NIST, HIPAA, PCIDSS and Risk Quantification assessments, to technical cloud and blockchain secure design and architecture reviews, application and network security assessments, red teaming, threat hunting and social engineering exercises. He has led and coordinated incident response and forensic investigation efforts for some of the largest and high-profile breaches in the recent past. He also advises clients on some of the most complex cybersecurity initiatives and acts as a trusted security adviser to organizations, C-Suite and board members.

Tarikere earned a master’s degree in computer sciences/cybersecurity from New York University. He holds the Chief Information Security Officer (CISO) certificate. He is a CISSP, PCI-QSA, GWAPT, GCIH and ISO 27001 Lead Auditor.

Edited excerpts of the interview follow:

As information security and incident response professional with over a decade of experience, what are some of the pressing issues you encountered during your career, and more recently?

While the cybersecurity threat landscape is continuously evolving, threat actors are employing more and more sophisticated tactics to attack organizations, and organizations are continuing to bring cybersecurity to the forefront; below are some critical challenges that organizations continue to encounter to date.

  • Industry Collaboration: Real-time threat and vulnerability information-sharing and widespread collaboration within the industry.
  • Cyberattacks due to Emerging Technology: Inability for cybersecurity to keep up with the pace of innovation and rapid change in the technology landscape.
  • People Problem: Humans are the weakest link in the chain, given their lack of technological understanding.
  • Senior Executive Buy-in and Engagement: Cybersecurity has always been an afterthought. Although we see a shift in the perspective, we are far from where we need to be.
  • Supply Chain Risk: Supply chain risk has, is, and continues to present a significant challenge for organizations.
  • Cyber Skill Shortage: It’s not just buying tools; it’s investing in people, in their knowledge and ability, that they are prepared to detect, contain, and respond to cyberattacks. Hiring and retaining cybersecurity professionals remains a top challenge for organizations in 2021.

At the end of 2020, the SolarWinds attack blew the internet. In response, businesses and federal agencies prioritized their cybersecurity budgets and embraced proactive security practices. However, the threat landscape grew manifold in 2021, and supply chains and critical infrastructure continued to incur breaches and ransomware attacks. What, according to you, is the root cause for all this?

Gartner predicts that by 2023, in addition to costing businesses over $50 billion, cyberattackers would have weaponized the Operational Technology systems to the point that they may harm or take a human life.[1] Historically, critical infrastructure has been designed to have their Industrial Control Systems (ICS) isolated and physically separated from the internet and other corporate networks. Furthermore, it was thought that the risk of cyberattacks on critical infrastructures was low because of the highly customized nature of these systems that required a specialized skill set to understand the architecture of the control system configurations and operate them efficiently.

As more and more organizations are modernizing their industrial processes by connecting these ICS components to the cloud and internet to improve system efficiency, employ open technologies and universal operating systems to reduce the cost of maintenance, they are also unknowingly giving threat actors more ways to compromise these systems through ransomware and extortion attacks.

Per the findings of VMware’s “The State of Incident Response” survey, 49% of organizations lack adequate tools (including staff and expertise) to detect cyberthreats. And it reflects a harrowing scenario in incident response. How can security leaders overcome this core challenge?

With the ever-growing threat landscape and attack vectors that the threat actors will leverage to attack an organization, the ability to detect, triage, contain, and respond to an incident in a timely manner will always be a pain point for the security leaders for the foreseeable future. Some of the ways to alleviate and overcome these challenges are:

  • Enhance visibility of the system events within the organization.
  • Implement a structured incident response process. Employ automation wherever possible.
  • Continue and enhance employee awareness programs to include the latest types of attacks.
  • Partner with an external incident response firm who are experts in the field and has been doing this day in and day out to do the heavy lifting during the incident response process.
  • Partner with key internal stakeholders like legal, finance, crisis communication, and business groups to ensure they are prepared when needed.
  • Test and practice the incident response process through simulated cyberattack exercises to ensure that the incident response process is working effectively and as designed.

While on this topic, could you shed light on the evolution of incident handling, incident management, and incident response? And what are some of the qualities to look for when hiring incident response personnel?

Knowing the how, why, and where of cyberattacks is a strong quality of the incident response (IR) professional. Having a finger on the pulse of the ongoing threat landscape and different cyberattacks happening across the globe will be a core criterion of any cybersecurity professional.

  • Problem Solving and Analytical Skills: Not all incidents are similar, and IR professionals need to be able to adapt to changing situations, new leads that are uncovered, and a variety of attack scenarios to respond as quickly as possible. Strong problem-solving and analytical skills coupled with out-of-the-box thinking will aid in their ability to face and resolve the most sophisticated attacks and unexpected situations.
  • Teaming and Collaboration: IR is a team sport. So, the ability of the member to collaborate and work in a team setting can aid in responding to an incident effectively and efficiently. This is important because these days, attackers have assembled teams of skilled like-minded individuals that have varied levels of experiences and perspectives themselves, so accumulating an internal team in a similar manner enables the organization to quickly identify tactics and anticipate the next move.
  • Technical Capability: While the IR team member will be analyzing a wide range of systems and artifact types, like RAM, network traffic, and many different log sources. Ability to find and correlate small digital footprints “breadcrumbs” left behind any time anyone does something on a system or network is an essential quality of the IR professional. Furthermore, understanding the know-how and having intrinsic knowledge on the working of the operating systems, kernels, network protocols, middleware, application software and malware will come in handy when performing advanced forensics and planning the containment and response strategy.
  • Communications: Although lower on the list, this is as important and, in some cases, more important than others. Incident Response professionals are working in a high-paced and stressful environment. The IR personnel should be able to articulate the technical details into something that the executives can understand when updating them of the incident. Furthermore, the IR personnel should provide clear guidance and action items for the other stakeholders like Business Groups, Legal, Crisis communications, etc. throughout the response process.

It is said, “data is the oil of 21st century,” and with more business moving online, cloud storage to some extent assures reliability compared to local storage. But is it cost-effective? And how can IT teams alleviate a hasty switch to the cloud and ensure a smooth and secure data migration process?

Organizations need to understand the core concept of maintaining the Confidentiality, Integrity, and Availability of the data they are the guardians of. They can transfer the risk by moving it to the cloud but will not be able to eliminate the risk completely. Organizations will still need to implement appropriate security controls to protect the data in the cloud.

Some of the common misconceptions regarding moving to the cloud are that “Cloud provider is responsible for the Security,” “Organization can meet compliance requirement on the cloud,” etc. The organization needs to understand that although a cloud service provider (CSP) provides the necessary tools and technologies required to secure the environment and meet the compliance obligations, it is the responsibility of the organizations to do proper due diligence when moving their applications workloads and data to the cloud.

It is always recommended that the organizations perform in-depth due diligence of their cloud migration strategy using industry-leading frameworks. Although not a comprehensive list of controls, some of the questions that the due diligence assessment should address are:

  • WHAT – What data or application is the organization moving? Is it sensitive, regulated, or restricted data?
  • WHERE – Where will the data be stored? Are there any data protection regulations that restrict the movement of data?
  • WHO – Who will have access to the application and the underlying data? Will it only be internal resources or any third parties? Will the data be shared publicly or restricted to specific groups of people?
  • HOW – How will the data be protected? How will the organization detect and respond to the security events/incidents? How will the organization recover the data in the event of an incident? How will the organization protect the Confidentiality, Integrity, and Availability of the data being moved to the cloud?

Cybersecurity is often a fleeting thought for small businesses. And hackers commonly target them because their financial capacity (security budgets) is limited. How can small businesses re-think security preparedness in a post-pandemic world?

Cyberattacks are a growing threat for small businesses. According to the FBI’s Internet Crime Report, the cost of cybercrimes exceeded $4.1 billion in 2020 alone.[2] Small businesses are attractive targets because they have sensitive information that threat actors can leverage without breaking into security infrastructures like that of big enterprises and corporations. cyberthreat vectors are constantly evolving, but some of the most common types of attacks that small business owners should be aware of are malware infection, viruses, business email compromise (BEC), ransomware, and phishing.

Cyber Hygiene: Organizations and their leadership should have a holistic view of their critical assets, systems, services, and third-party partners to determine the security risk and exposure. Hence, the organization must maintain strong cyber hygiene by keeping inventory of critical assets, ensuring that their systems are patched and protected, and is continuously monitored for security threats.

Multi-factor Authentication (MFA) – Enforce Multi-factor Authentication on accounts that store, process, or transmit sensitive information. It is always recommended to enable and enforce MFA on all internet-facing resources of the organization.

Security Awareness Training: Educate the employees to create strong passwords, follow good browsing practices, avoid suspicious downloads, protect sensitive customer, employee, and vendor information, spot phishing emails, and maintain good cyber hygiene. Perform periodic training on cybersecurity best practices for the employees.

Supply Chain Risk Management: Organizations should evaluate their current business partners and vendors and the level of access they have to their IT systems, network, and data. Ensure that the partners have sufficient security controls to protect the organization’s assets.

Protect sensitive data and back up the rest: Identify the critical data for the organization and ensure that they are constantly backed up to a secure location on a continuous basis. If possible, back up the data to an offsite location periodically in the event that the online copy is corrupted or unusable. Consider rendering the sensitive data unreadable when possible.

Secure Payment Processing and Fund Transfer: Work with the banks or card processors to ensure the most trusted and validated tools and anti-fraud services are being used. Isolate the systems that store, process, or transmit payment information from other systems within the organization. Implement strong validation checks and controls when making vendor payments to protect the organization from wire transfer fraud.

DHS offers free cybersecurity toolkits for Risk and Vulnerability Scanning and Phishing Campaign Assessment toolkit here – https://us-cert.cisa.gov/resources/ncats and Supply Chain Risk Management Toolkit here – https://www.cisa.gov/ict-supply-chain-toolkit.

Could you give us your top cybersecurity predictions for the remainder of 2021?

Considering that the cyber threat landscape is continuously evolving, one cannot make true predictions on where the industry is heading. However, trends and security research by various organizations indicate that:

  • Ransomware threats will continue to dominate the rest of 2021 and into 2022. Cyberthreats actors will continue to get creative, and their attacks will become more sophisticated to ensure that the organizations cannot recover normal business operations without paying the ransom.
  • Social engineering, specifically phishing, will continue to dominate the mode of infiltration for the foreseeable future until organizations enforce a multi-layered defense approach to protect their users from falling prey to such social engineering attacks.
  • Supply chain risks will be at the forefront with organizations evaluating their exposure and ability to protect and respond to attacks to or via their third-party partners.
  • Even though cyberattacks continue to occur, cybersecurity investments will continue to rise. Organizations and solution providers will continue to innovate to stay ahead of the curve. Governments and law enforcement agencies will step in, propose policy solutions to protect their economies, organizations from ransomware extortion attacks.

Note: Views or opinions expressed by the interviewee are his own and doesn’t represent those of the people, institution, or organizations that the interviewee may or may not be associated with in professional and personal capacity, unless explicitly stated.


About the Author

Pooja Tikekar is the Sub Editor at CISO MAG, primarily responsible for quality control. She also presents C-suite interviews and writes news features on cybersecurity trends.

More from the author.

Microsoft Exposes Iran-linked APT Targeting U.S., Israeli Defense Tech Sectors

microsoft, flaws in SonicWall SRA SMA

Microsoft Threat Intelligence Centre (MSTIC) observed DEV-0343, a new activity cluster, conducting extensive password spraying against more than 250 Office 365 tenants, with a focus on U.S. and Israeli defense technology companies, Persian Gulf ports of entry, or global maritime transportation companies with business presence in the Middle East.

Per MSTIC, “Less than 20 of the targeted tenants were successfully compromised, but DEV-0343 continues to evolve their techniques to refine its attacks. MSTIC noted that Office 365 accounts with multifactor authentication (MFA) enabled are resilient against password sprays.”

DEV-0343 emulates Firefox browser and uses IPs hosted on a Tor proxy network to perform extensive password sprays. It was observed that more than thousand unique Tor proxy IP addresses were used in attacks against each organization.

DEV-0343 operators typically target two Exchange endpoints – Autodiscover and ActiveSync – as a feature of the enumeration/password spray tool they use. This allows DEV-0343 to validate active accounts and passwords, and further refine their password spray activity.

Guidelines from Microsoft Threat Intelligence Centre

MSTIC has issued a few guidelines that can mitigate the threat:

  • Enable multifactor authentication to mitigate compromised credentials.
  • For Office 365 users, see multifactor authentication support.
  • For Consumer and Personal email accounts, see how to use two-step verification.
  • Download and use passwordless solutions like Microsoft Authenticator to secure accounts.
  • Review and enforce recommended Exchange Online access policies.
  • Block ActiveSync clients from bypassing Conditional Access policies.
  • Block all incoming traffic from anonymizing services where possible.

Critical infrastructure, essential services, financial sector, and health care were, and continue to be the core target for premediated cyberattacks. The vicious will to disrupt a country and its services has been motivating state-sponsored-cyberattacks. Though government policies and regulations are being put in place to tackle the cyberattacks on critical services, the attacks continue unabated.

Also Read:

  1. Iranian APT Group “Siamesekitten” Targets Israeli Firms in a Cyberespionage Campaign
  2. Iranian Hackers Impersonate U.K. Academia in “SpoofedScholars” Phishing Campaign

How To Find a Phishing Email [INFOGRAPHIC]

Phishing email

Protecting personal information from adversaries has become a challenge for both individuals and organizations. Cybercriminals are leveraging advanced phishing and social-engineering techniques to trick users and break into corporate networks.

Despite necessary protective measures and awareness campaigns, threat actors continue to outsmart the security perimeters. With threat actors constantly updating their phishing skills, users must be vigilant and cyber aware to defend against ever-growing phishing baits.

Also Read: Five Phishing Baits You Need to Know

Acknowledging the second week of the Cybersecurity Awareness Month, we present you with five security tips to Phight the Phish.

5 Steps to Phight the Phish

Most phishing emails voice a sense of urgency, hence make the most of the firewall and antivirus solution on your device because it’s better to be careful than sorry.

About the Author:

Rudra SrinivasRudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from Rudra.

 

7 Tips for Implementing a Personnel Security Program

Microsoft 2022 flaw, Cybersecurity interest, Personnel Security Program

Why does it seem that some of the most important things in life are often those that are the most overlooked? For example, a Personnel Security Program is a vital part of any organization, but personnel security is often the part of the overall corporate Security Program that is lacking the most. An effective Personnel Security Program is necessary to protect your people, information, and assets by enabling your organization to reduce the risk of harm to your people, customers, and partners, as well as reduce the risk of your information or assets being lost, damaged, or compromised. The objective of an effective Personnel Security Program is to help an organization make a reasonable determination that individuals granted access to classified information or assigned to sensitive positions are and will remain loyal, trustworthy, and reliable.

By Bryon Miller, Co-founder and CISO at ASCENT Portal

To help you implement and maintain a strong personnel strategy and program for your organization, consider the following tips. They will help you have greater trust in people who access your official or important information and assets and deliver services and operate more effectively.

1. Define roles and responsibilities. Security roles and responsibilities for all appropriate personnel should be defined and documented. Every position throughout the organization that plays a role in managing or complying with security controls should have their applicable roles and responsibilities documented. Your CISO, or similarly titled role, should partner with the HR team to ensure roles and responsibilities are appropriately outlined and to maintain a plan for talent recruitment and retention. Succession planning is also important to ensure the Security Program continues to succeed as personnel are promoted, transferred, or depart the organization.

2. Perform pre-employment screening for personnel. All personnel need to be screened prior to starting employment to ensure organizations hire knowledgeable, ethical individuals with the appropriate skill sets and experience to fill open positions. Whatever screening process is deemed appropriate for an organization, procedures should be documented to ensure organizations follow standard processes to successfully complete personnel screening in a repeatable and reliable manner.

3. Document terms and conditions of employment. As part of their contractual obligations to an organization, personnel should agree to, and sign the terms and conditions of their employment. This ensures organizations are protected and supports the organizations’ abilities to hold personnel accountable if any issues arise during employment. Terms and conditions should state that all personnel provided access to protected or sensitive information are required to sign a confidentiality or non-disclosure agreement prior to being provided access.

4. Define and communicate management responsibilities. Managers of all departments should be responsible and accountable for ensuring their teams perform the assigned functions within their areas of responsibility in accordance with defined Security Program controls. Security risks and control requirements should be actively discussed at business unit meetings. Managers often lead by example, so if a manager “colors outside the lines,” it is a safe bet that their teams will eventually do the same. Managers should ensure their teams have a clear understanding of how to identify and escalate potential security issues to appropriate security personnel.

5. Spearhead a Security Awareness Training Program. Organizations should develop, document, and maintain a comprehensive Security Awareness Training Program. This needs to include security control updates made to the organization’s security policies, plans, and procedures that are relevant to their job function. Training should also include information on security best practices. At a minimum, security awareness training should be completed as part of initial training for newly hired personnel and annually thereafter for all personnel. Training should also be provided whenever required by the system, security control, or operational changes.

6. Ensure a disciplinary process is in place. Organizations should implement, communicate, maintain, and provide training on a formal disciplinary process for personnel that violates controls contained in security policies or commits a security incident. While punitive actions are not ideal, if “bad” behavior is not corrected, it is likely to continue, putting organizations at risk unnecessarily. All appropriate personnel should be aware of the potential discipline associated with not following prescribed controls. Organizations need to ensure the same types of situations are handled in a comparable manner to preclude unfair treatment of personnel.

7. Plan for termination of employment or position changes. A process needs to be defined by organizations to address the security control requirements associated with the termination of personnel or changes in the position of personnel from one role to another. This is required to ensure access is terminated in a timely fashion, or appropriately adjusted when personnel transfer from one role to another. A documented termination checklist helps to ensure all planned steps are taken upon the termination of personnel. Organizations put the confidentiality of information at risk if appropriate access revocation or modification is not completed in a timely manner.

Your organization should ensure that a comprehensive Personnel Security Program is developed and implemented consistently across the organization. Organizations that do not could potentially overlook a pivotal security function or leave a control unaddressed. By developing a personnel security strategy and building a comprehensive Personnel Security Program, supported by all organizational stakeholders, organizations can avoid key personnel security pitfalls for effective overall security.


About the Author

Bryon MillerBryon Miller is the Co-founder and CISO at ASCENT Portal, a leading Software-as-a-Service (SaaS) platform for comprehensive security and continuous compliance management. An expert in security and compliance best practices, Miller is also the author of the book, “100 Security Program Pitfalls and Prescriptions to Avoid Them,” available on Amazon.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Indian Bank Users Victim of Drinik Android Malware – Use Tax Refund as Bait

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Indian Computer Emergency Response Team (CERT-In) released an advisory related to a new malware called Drinik.

The Android malware targets Indian Bank customers through a hacking process using Phishing emails to steal sensitive user data.

Detailing the process, the advisory describes the attack vector to pose as an Income Tax Department message. The SMS is a phishing message that asks the user to enter personal information and download and install the malicious APK file for verification. Personal and financial details like PAN card number, Aadhaar, date of birth, email address, bank details, IFSC code, card details, PIN and CV are all entered, stored, and stolen through the malware.

To lure the victim the malware displays a refund amount message and seeks further permission to transfer the amount to the user’s bank account.

When the victim enters the amount and clicks on transfer, the app shows an error and demonstrates a fake update screen. While the screen for installing updates is displayed, the Trojan in the backend sends all the user details including SMS and call log to the attacker’s device. These details are then used by the hacker to generate the bank-specific mobile banking screen to render it on the user’s device. The victim is then requested to enter the mobile banking credentials that will be captured and then used by the attacker.

Best Practice

As per Gadget Bridge:

  • Avoid downloading any potentially harmful apps on your device, limit your download to official app stores like Google Play and Apple Store.
  • Verify app permission and grant permission relevant to the app. Avoid checking the Untrusted Sources checkbox to install sideloaded apps.
  • Use safe browsing tools and filtering tools in your antivirus, firewall and filtering services.
  • Be cautious towards shortened URLs like bit.ly and TinyURL. Hover your cursor over the shortened URLs to see the full website domain before clicking on the link.
  • Report any suspicious activity to the respective bank with the relevant details to take further appropriate actions.

Indian Banking Cyber Incidents

Per CERT-In more than 2.9 Lakh (290,445) cybersecurity incidents related to digital banking have been reported in 2020, within India. The cybersecurity incidents related to digital banking include phishing attacks, network scanning and probing, viruses, and website and URL hacking/hijacking. Banking continues to be a soft target for attackers with an increased number of digital platforms for financial transactions. The ease of use has also resulted in the ease of attacks for the vectors, with a high number of people having their bank details linked and stored on their devices.

Cox Media Group Validates Ransomware Attack that Pulled Down its Broadcasts

ransomware, ryuk ransomware, cox media

On June 3, 2021, American media company Cox Media Group (CMG) experienced a cyberattack in which the malicious threat actor encrypted the network servers and forced the systems to go offline.

In the initial investigation, the company did not mention the nature of the attack; however, in a notification letter released on October 8, CMG acknowledged the breach as a ransomware attack. The company also stated that it did not pay ransom to the threat actors.

Over 800 individuals were believed to have been impacted. Personal information exposed in the breach included names, addresses, Social Security numbers, financial account numbers, health insurance information, health insurance policy numbers, medical condition information, medical diagnosis information, and online user credentials. The attack also resulted in disruption of the streaming of its live TV and radio broadcasts streams. As a security measure, the company took down the systems to mitigate the further spread of the threat.

Improved Security

Post attack, the company took measures to improve its security posture by adopting multi-factor authentication, enterprise-wide password reset, and implementation of endpoint detection solutions.

Ransomware Attacks   

In its Ransomware Index Update Q2 2021, Cyber Security Works states that six vulnerabilities have become associated with seven ransomware strains; among them are the infamous Darkside, Conti, FiveHands, and the newly christened, Qlocker.

With this update, the total number of vulnerabilities associated with ransomware has increased to 266. It also noticed a 1.5% increase in the number of actively exploited vulnerabilities that are trending currently, reiterating that a risk-based approach for the remediation of vulnerabilities is the need of the hour.

One of the most compelling observations during the quarter was the exploitation of zero-day vulnerabilities even before vendors published their discovery or released patches.

We have witnessed dangerously disruptive ransomware attacks in 2021. The ransomware attacks on Colonial Pipeline, JBS USA Holdings, Kaseya, and Accenture — the most recent victim of LockBit — are proof that the lack of cyber hygiene is rampant. These attacks highlight the need for the continual assessment of vulnerabilities and the prioritization of remediation.

See also: Conti Ransomware Attacks on Rise – CISA, FBI, NSA Issue Joint Alert

Russia-linked APT28 Phishes 14,000 Gmail Users in a State-sponsored Phishing Campaign

Gmail, apt28

APT28, a threat group attributed to Russia’s General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165, is targeting Google users through a phishing attack to steal their data and extort money.

Google has identified this campaign and has put out a warning notification to over 14,000 targeted users to stop the attacks in track.

The campaign was detected in late September and accounts for a larger than usual batch of government-backed attack notifications that Google sends to targeted users every month.

Google issued a warning message, indicating these are not compromised notifications but safety measures; the warning was issued after part of the campaign was blocked.

“If we are warning you there’s a very high chance we blocked. The increased numbers this month come from a small number of widely targeted campaigns which were blocked,” said Google.

The campaign from APT28 lead to a larger number of warnings for Gmail users across various industries.

Shane Huntley, Google’s Threat Analysis Group, said, “Fancy Bear’s phishing campaign accounts for 86% of all the batch warnings delivered this month. So why do we do these government warnings then? The warning really mostly tells people you are a potential target for the next attack so, now may be a good time to take some security actions.”

Who is APT28 or Fancy Bear?

APT28 has had multiple identities, such as Pawn Storm, Sofacy Group, Tsar Team, and STRONTIUM. However, it is now infamously known as Fancy Bear. The name comes from a coding system security researcher Dmitri Alperovitch uses to identify hackers.

Known to be operational since the mid-2000s, Fancy Bear’s methods are consistent with the capabilities of state actors. It is known to target government, military, and security organizations, especially Transcaucasian and NATO-aligned states for data theft and espionage activity.

Fancy Bear has carried out cyberattacks on the German parliament, the Norwegian parliament, the French television station TV5Monde, the White House, NATO, the Democratic National Committee, the Organization for Security and Co-operation in Europe and the campaign of French presidential candidate Emmanuel Macron.

Classified as an advanced persistent threat (APT), the threat actor uses zero-day exploits, spear phishing and malware to compromise targets.

See also: Russia-based APT28 Linked to Mass Brute-force Attacks Against Cloud Networks


Reference: https://en.wikipedia.org/wiki/Fancy_Bear

Explore 4 Key Elements of Network Security

network security, BlackMatter ransomware, privilege

Network security and threats are of primary concern during the ongoing pandemic and are increasingly becoming sophisticated and complex. No home or corporate network is safe from cyberthreat or intrusion. Modern-day cybercriminals devise new and complex strategies to launch an attack and exploit network vulnerabilities to steal classified information and business data.

Data leakage is a significant risk that can result from unlawful network access. Data breaches are detrimental to a company’s financial and business reputation. The recent Facebook data breach exposed the personal information and data of over 500 million users from 106 countries. Therefore, organizations are ramping up their cybersecurity strategies to protect their digital assets from malicious network intrusions.

This article sheds light on network security functions, network security components, and common types of network security attacks.

What Is Network Security? 

Network security encompasses directives and guidelines to safeguard network data integrity, including various devices and technologies. These rules are designed to securely access network data and protect the usability and confidentiality of systems and networks. The aim is to prevent intrusions and mitigate lurking security threats and curb lateral movement. Therefore, implementing network security tools and technologies is crucial to strengthening your organization’s security posture.

Organizations need to envision and anticipate network security threats to defend their system against threats. To devise new strategies and prevent network security vulnerabilities, one must understand the fundaments of networks and network security attack types.

Common Types of Network Security Attacks 

As individuals and businesses rely on internet-based services and applications for ease of use and convenience, the threat landscape has also expanded. The pandemic-induced remote work culture also adds to the growing incidents of network attacks and threats. Attackers can easily exploit vulnerabilities in these networks or systems and use the gaps to further their nefarious goals. The current increase in data breaches and theft underlines the importance of network security and how illegal network breaches may cost businesses reputational and financial damage.

A few widespread threats to our network and computer systems are:

  • Distributed Denial of Service attacks (DDoS)
  • Computer worms
  • Malware threats
  • Botnets
  • Spyware
  • Man-in-the-middle attacks
  • SQL attacks
  • Adware

Cybercriminals often deploy malicious activities or target systems and networks with security flaws – unprotected wireless networks, poorly coded websites, or accounts with poor password security.

If the network security threats are left unchecked, they can later escalate into major cyber breaches. Ensuring a safe network reduces the risk of unauthorized intrusions and data theft.

The following section discusses four network security components or elements crucial for enhancing an organization’s security.

Elements of Network Security 

Neglecting the existing or possible vulnerabilities in your network can have far-reaching effects on your business. Reputational damage is one major effect arising from weak links in network security, apart from financial loss.  Here are the four essential elements of network security to keep in mind:

1. Network Access Control (NAC)

NAC is a viable security tool that gives administrators network visibility into who can or cannot access the network. NAC solutions let them monitor network traffic for any suspicious activity. As the use of electronic devices like mobiles and applications accessing organizations’ networks are increasing to meet the compliance regulations and changing norms of work-from-home, intrusion risks are also quite high. Therefore, NAC solutions can help admins better grasp network traffic visibility and access management to secure their networks.

2. Firewall Security

Firewall security is one of the most crucial elements of network security. A network security tool, a Firewall serves to monitor both incoming and outgoing traffic. The intent is to block suspicious traffic activity, unauthorized intrusions from threat actors and curb the spread of computer malware or viruses. It acts as a protective fence between non-threatening and untrusted networks or devices, whether home-based or corporate networks; a firewall offers an added layer of protection to network security.

MarketsandMarkets predicts that the global network security firewall market size will increase from $3.8 billion in 2020 to $10.5 billion by 2025. Organizations see the need to configure firewall network security in the wake of spurred data breaches and increasing vulnerabilities ushered in by remote work norms and rapid digitalization.

3. Intrusion Prevention System or IPS

A network security application, IPS detects and blocks suspicious activity or anomalies on the network.   It examines the traffic and identifies suspicious or unknown malware activities on a protected asset.

Furthermore, IPS gathers and analyzes malicious actions before reporting them to the system administrator and other users.

4. Security Information and Event Management (SIEM)

SIEM is a crucial tool to protect your organization’s data and other digital assets. Besides, it lets you monitor traffic and security systems in real-time and gathers data from various traffic sources or databases to detect malicious activity. It also raises an alert and takes the necessary steps to mitigate hazards or prohibit suspicious activities.

SIEM combines SIM (Security Information Management) and SEM (Security Event Management) technologies and works as one comprehensive unit to strengthen an organization’s security posture.

Your business can take a massive hit without a certified network defender to probe network vulnerabilities and devise effective security solutions.

However, aligning your staff to the specific skillset of network security and defense is also crucial to stay abreast of network intrusions and data breaches. EC Council’s accredited program, Certified Network Defender (C|ND) is designed to help students and professionals defend against real-world cyberthreats.

Learn More About Network Security 

EC-Council’s Certified Network Defender program is a vendor-neutral, hands-on, instructor-led comprehensive network security program that teaches participants network security fundamentals. Moreover, this program is curated by industry experts to help IT professionals safeguard their businesses’ digital assets and strengthen their network defense.

Furthermore, it includes hands-on lab training, the latest hacking technologies, and updated models to learn in real-world scenarios.

C|ND program stresses on comprehensive network training and defense training to produce efficient Network Defenders to bridge the skill gap in cybersecurity. This certification teaches participants to use threat intelligence to predict cyberthreats before cybercriminals strike.

Recognized and Accredited by DoD 8570 & ANSI/ISO/IEC 17024

Get your Network Security Certification at EC-Council


FAQs

  1. Name a few threats to network security?

Businesses and organizations face the five common security threats: phishing attacks, ransomware, malware attacks, data breaches, and insider threats.

  1. How can you mitigate network security threats?

With cybercrimes rapidly evolving and increasing at light speed, organizations can take some robust measures to defend their networks. Using network protection measures like installing a firewall, using a virtual private network (VPN) etc., you can protect your network traffic. Other measures include monitoring your access control and keeping your software updated from time-to-time.


References:

  1. https://www.forcepoint.com/cyber-edu/network-security
  2. https://www.imperva.com/learn/application-security/siem/
  3. https://www.cynet.com/network-attacks/network-attacks-and-network-security-threats/
  4. https://www.varonis.com/blog/network-access-control-nac/

Market Trends Report: Implementing Digital Forensics in Emerging Technologies

digital forensics

Computer Forensics is now known as Digital Forensics and the task of uncovering digital evidence is more challenging than ever. It now involves governments and multiple jurisdictions. Today, forensic experts would need to travel to different countries to find digital evidence, as cybercrime is performed across borders. And emerging technologies like blockchain are making the task more difficult.

In pursuit of finding digital evidence, forensics experts would be led to the Dark Web, which is akin to going underground, incognito, to look for criminals and to find clues.

The explosion of data and the growing number of mobile phones and IoT devices also pose challenges. And if the digital evidence is on a cloud service provider’s platform, investigators would need a warrant from the court to access it.

Emerging technologies and borderless cybercrime have made Digital Forensics more challenging than ever.

So how do we counter all this with a completely different strategy?

digital forensics market trend reportTo better understand the challenges and state of readiness in implementing Digital Forensics in emerging technologies, CISO MAG, in collaboration with EC-Council’s CHFI (Computer Hacking and Forensic Investigation), launched a Technology Trends Survey in April 2021. The report offers an in-depth analysis of how important it is to incorporate the effects of digital forensics on emerging technologies into the curriculum of digital forensic education.

This survey is oriented towards skills, training and industry opportunities, specifically for digital forensics. The aim of this survey is to better understand the forensic readiness and challenges of implementing digital forensics in emerging technologies. The widespread adoption of technologies such as the Internet of Things (IoT), cloud computing, mobile and web applications has changed the way data is being processed and stored. From the perspective of cybersecurity education in digital forensics, this survey attempts to gauge the upcoming challenges that will arise upon the deeper integration of digital forensics with these technologies.

This exclusive report based on the survey showcases the viewpoints of industry experts and their perspectives from across the table.

Key findings

  • 94.83% of the respondents believe that cloud computing technology and its corresponding cloud forensics will have a greater impact on digital forensics education in the future.
  • 60.51% of the respondents feel that gaining evidence files of around 50 GB for digital forensics study and research, will be extensively or quite helpful, as there is a general lack of high-volume data in forensics for the purpose of study and practice.
  • 52.40% of the respondents believe that smartphones connected to, or as an IoT device will be the most challenging while performing IoT forensics.
  • 39.11% of the respondents believe that performing forensics of a network is the most challenging task when conducting TOR forensics.
  • 86.72% of the respondents believe that analyzing and decrypting will be the widely used methods for dealing with the anti-forensics technique of encryption.

    To view the complete analysis and reportage, hit the download button now!

Check out our other Market Trends Reports here.

U.S. DoJ Launches Civil Cyber-Fraud and Cryptocurrency Initiatives

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

Ever since cybercriminal activities surged globally, the U.S. government initiated multiple cybersecurity measures to enhance security and defend against cyberattacks. Deputy Attorney General Lisa O. Monaco recently announced the launch of the Civil Cyber-Fraud Initiative, which will combine the department’s expertise in civil fraud enforcement, government procurement and cybersecurity to combat emerging cyberthreats in the country.

“For too long, companies have chosen silence under the mistaken belief that it is less risky to hide a breach than to bring it forward and to report it. Well, that changes today. We are announcing today that we will use our civil enforcement tools to pursue companies, those who are government contractors who receive federal funds, when they fail to follow required cybersecurity standards — because we know that puts all of us at risk. This is a tool that we have to ensure that taxpayer dollars are used appropriately and guard the public fisc and public trust,” said Monaco.

Civil Cyber-Fraud Initiative 

The Civil Cyber-Fraud initiative aims to develop actionable recommendations to enhance and expand the Department of Justice (DoJ) efforts against cyberthreats. The initiative utilizes the False Claims Act to pursue cybersecurity-related frauds by government contractors and grant recipients.

The operations of the Civil Cyber-Fraud initiative include:

  • Building overall resiliency against cybersecurity intrusions across the government, the public sector and key industry partners
  • Holding contractors and grantees to their commitments to protect government information and infrastructure
  • Supporting government experts’ efforts to timely identify, create and publicize patches for vulnerabilities in commonly-used information technology products and services
  • Ensuring that companies that follow the rules and invest in meeting cybersecurity requirements are not at a competitive disadvantage
  • Reimbursing the government and the taxpayers for the losses incurred when companies fail to satisfy their cybersecurity obligations
  • Improving overall cybersecurity practices that will benefit the government, private users, and the American public

“The initiative will hold accountable entities or individuals that put U.S. information or systems at risk by knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches,” the DoJ said.

Tackling Cryptocurrency Misuse

In addition, the DoJ also created a National Cryptocurrency Enforcement Team (NCET)  to manage investigations and prosecutions of misuses of cryptocurrency. The team is specially focused on crimes committed by virtual cryptocurrency exchanges, mixing and tumbling services, and money laundering infrastructure malicious actors.

The NCET initiative will:

  • Investigate and prosecute cryptocurrency cases and develop strategic priorities
  • Identify areas for increased investigative and prosecutorial focus, including professional money launderers, ransomware schemes, human traffickers, narcotics traffickers, and financial institutions working with cryptocurrency
  • Develop and maintain relationships with federal, state, local, and international law enforcement agencies that investigate and prosecute cryptocurrency cases
  • Train and advise federal prosecutors and law enforcement agencies in developing investigative and prosecutorial strategies

Besides, the NCET collaborates with private sector organizations with expertise in cryptocurrency matters to further the criminal enforcement mission.