Home Blog Page 54

Cybersecurity Incidents Declined by 28% in FY 2020-21: ACSC Annual Cyber Threat Report

Cryptocurrency scams in Australia

The government of Australia has implemented several cybersecurity measures to thwart rising cyberthreats in the nation. As a result, the country has now reported fewer security incidents than last year. According to the Annual Cyber Threat Report 2020–21 from the Australian Cyber Security Centre (ACSC), the number of cyberattacks in financial year 2020–21 has declined by 28% compared to the previous financial year. However, organizations sustained significant losses due to various cyberattacks. Business Email Compromise (BEC) was reported as one of the top cybercrimes, with a 7% increase than last year. The ACSC also highlighted that threat actor groups leveraged sophisticated techniques to increase their reach and cause maximum damage to the targeted victims.

The ACSC has produced the report with contributions from the Defense Intelligence Organization (DIO), Australian Criminal Intelligence Commission (ACIC), Australian Security Intelligence Organization (ASIO), and the Department of Home Affairs and industry partners.

Top Cybersecurity Threats

  • Ransomware
  • Exploiting unpatched vulnerabilities
  • COVID-19-themed scams
  • Supply Chain attacks
  • BEC attacks

Other Key Findings

  • Over 67,500 cybercrimes were reported, an increase of nearly 13% from the previous financial year
  • Self-reported losses from cyberattacks totaled $33 billion
  • Over 1,500 cybercrime reports per month of malicious cyber activity related to the coronavirus pandemic
  • More than 75% of pandemic-related cybercrime reports involved Australians losing money or personal information
  • Nearly 500 ransomware attacks were reported, an increase of 15% from the previous financial year
  • Fraud, online shopping scams, and online banking scams were the top reported cybercrimes
  • Received over 22,000 calls on the Cyber Security Hotline – an average of 60 per day and an increase of more than 310% from the previous financial year

 How ACSC Contributed to Strengthening Cybersecurity

  • Published more than 40 security guides to support older Australians, families, and businesses to implement cybersecurity practices
  • Supported 18 cybersecurity exercises involving over 50 organizations to strengthen Australia’s cyber resilience
  • Provided advice or assistance to over 1,630 cyber security incidents
  • Undertook 34 high-priority operational tasking activities in response to identified and potential cyber threats or significant events – this included scanning for vulnerable Australian devices
  • Removed over 7,700 websites that were hosting cybercrime activity from the Internet
  • 16 Australian Government agencies were signed to the Australian Protective Domain Name Service, processing more than 5.5 billion queries and blocking over 400,000 malicious domain requests
  • Disrupted over 110 malicious COVID-19 themed websites, with assistance from Telstra and Services Australia

Remediations

In addition to the Essential Eight Maturity Model,  the ACSC has recommended all organizations in Australia to implement the following security measures:

  • Report all cybercrime and cyber security incidents via Reportcyber
  • Become an ACSC Partner to receive threat insights, advisories, and advice to enhance their situational awareness
  • Review all networks to establish where valuable or sensitive information and infrastructure is located, and apply appropriate cybersecurity measures proportionate to the risk of compromise
  • Patch within 48 hours where an exploit exists
  • Evaluate risks associated with cyber supply chains
  • Prepare for a cyber security incident by having an incident response, business continuity and disaster recovery plans in place and testing them

How Australia is Boosting Cybersecurity 

Australian government implemented several security initiatives after cyberattacks became prevalent in the country. The government passed the Surveillance Legislation Amendment (Identify and Disrupt) Bill 2020, allowing the Australian Federal Police (AFP) and the Australian Criminal Intelligence Commission (ACIC) to spy on potential cybercriminals online. Besides, Australia, the U.K., and the U.S. recently came together to form a trilateral security partnership known as AUKUS. The security pact is committed to maintaining diplomatic, security, and defense cooperation in the Indo-Pacific region.

Hardening Cyber Insurance Market Makes Cybersecurity More than a Tech Problem

cyber insurance in SMEs

The hardening of the cyber insurance market is forcing enterprises to come to terms with the impact their cybersecurity posture has on the bottom line and thus viewing it as more than just an IT issue. As ransomware and other cyberattacks capture daily headlines and wreak havoc, it’s hard to ignore the dependent relationship developing between enterprises and insurers. Insurer hesitancy to take on more cyber risk and added coverage limitations and exclusions leave enterprises exposed or paying higher premiums. It’s important to take a look at what has changed in cyber insurance and how enterprises can adapt to and address these uncertainties.

By Yakir Golan, Co-founder and CEO of Kovrr

How has cyber insurance changed?

When cyber insurance emerged in the 1990s, carriers did what they commonly do before understanding a new market: engaged in cash flow underwriting to pad their book with premiums and competed by lowering costs. For enterprises, this meant a wide safety net for diverse cyber events at very little cost to the business. Fast forward to 2021. Amidst a ransomware epidemic, insurance carriers are tightening the reins, asking more granular and invasive questions, diving deeper into a company’s history, and hitting enterprises with capacities, exclusions, and segmented coverages – all with higher premiums. Fitch Ratings found that direct cyber insurance premiums increased by 22% in 2020, reaching almost $3 billion.

See also: Demystifying Cyber Insurance to Enable Adoption

Insurers are reassessing their approach to cyber, and enterprises are becoming hyper-aware of their vulnerability to a cyberattack. According to research by Telia Carrier, 51% of global organizations feel more vulnerable to cyberattacks after COVID-19, with the U.S. and U.K. feeling the most at risk. Insurers are pondering if there is enough demand and premium that can offset devastating cyber risk catastrophe claims just when enterprises realize they need coverage more than ever before. There is also the matter of regulatory uncertainty with regard to ransomware reimbursement payments. If they were outlawed, the cyber insurance business would escalate further dramatically. One of the challenges insurers face is the perception that there isn’t enough historical data to appropriately write cyber risk. But there are data and correlations that can help them gain a better picture.

How insurers view and write enterprise cyber risk

Insurers are constantly looking to diversify their cyber portfolios and mitigate the chances of large accumulations. If they can stack their book with policies that don’t share hazard characteristics, that’s one way to be careful. This is not so different from the way insurers approach natural catastrophes, such as hurricanes and wildfires, where they broadly write disasters based on regional zones. There are three primary indicators that can help insurers do this successfully with cybersecurity: location, industry sector and company size.

These variables are heavily correlated to cyber risk assessment because of the depth and breadth of third-party relationships in organizations today. It’s no surprise this is a critical area given that some of the largest and most disastrous cyber attacks in recent memory, including Solar Winds and Kaseya, began with third parties and their links to hundreds or thousands of organizations. Companies within a geographic location and industry sector tend to use the same third-party service providers and technologies, naturally leaving them exposed to corresponding cyber attacks. Organization size is important because it indicates the kinds of technologies used, cyber preparedness, security policies, cybersecurity spending, and the level of sophistication of cyberattacks.

Why is this important for enterprises to understand? Besides getting more insight into how insurers are looking at their business, many of these modeling techniques and data used to help inform insurance carriers of their cyber risk accumulation can also be used by enterprises, to help them better understand their own financial cyber risk exposure.

How can enterprises learn and adapt cybersecurity exposure?

Enterprise cybersecurity posture in the current attack landscape can change moment to moment, and companies must be smarter about how that can financially impact their business, especially because of the limited cyber insurance coverage that is either available or affordable. Thus, organizations must become proactive in understanding their own cyber risk posture in order to identify shortcomings and also be strategic about what parts of their business (and for what type of attacks) insurance is most beneficial. For example, if an organization is investing most of its IT budget in mobile security, but is more susceptible to attacks in its cloud environment, then resource allocation may be misaligned.

Fortunately, cyber risk quantification models are capable of developing analyses that show enterprises a maximum probable loss, which can be used to understand the business impact and inform mitigation in specific areas of their business. Three primary forms of data are used in this quantification.

The first is company mapping, which is equivalent to a company’s ancestral tree. Understanding parent entities and subsidiaries and how they work together inform cyber integrity. The second type is technographic data, which showcases the technologies, services, and data centers that the company relies on. Digital asset data is commonly used to understand the scale of a company’s digital footprint, and thus understand the magnitude of a cyber event, but diligence data is needed to see the potential company exposure to different cyber events. Since organizations face a constantly evolving attack surface, it’s nearly impossible to manually gather this data. Leveraging consortiums from security rating providers that have information on open ports, server configurations, and publicly disclosed security incidents can help fast-track this process. The third type of data is firmographic, which consists of business information about the company. Some examples of this data are revenue figures, employee count, business location, industry type and number of customers.

The three types of data are used and utilized to understand the likelihood of the company to experience a cyber event, and also to estimate the severity an event will have on the company, in the case, it will be affected by one. To calculate the likelihood and severity from the data, we use machine learning models that are developed and trained based on threat intelligence data that is collected and updated periodically.

None of this matters if the model can’t be simulated against event scenarios hundreds of thousands of times that largely mimic the kind of real-world attacks we are seeing today. The process is required in order to build an accurate statistical model. This is why cyber risk modeling vendors need to update event catalogs to include evolving attack techniques and the thousands of characteristics of each recent event involved with third-party service providers. For example, an event catalog must account for double or triple ransomware extortion scenarios that recently became a phenomenon. The way the catalog is built is unique to organizations based on security posture and company intelligence data.

Whether enterprises like it or not, an increasingly dangerous attack landscape means they require cyber insurance at a time where it’s hard to secure. Board members, the C-suite and IT departments must work closely together to navigate the burgeoning challenge because it’s only going to escalate. Introducing an organization to financial quantification of cyber risk establishes a common language among board members and security and IT staff that historically haven’t seen eye to eye about the impact or importance of cyber risk on their business. Approaching cyber risk management in this way means businesses can make more informed decisions about which gaps in their posture should be mitigated immediately. In the modern world, cyber risk must be viewed as a business risk. Insurers are rightly becoming more careful about the risk they take on, and enterprise execs must also be smarter about understanding their own cyber risk and have a clear understanding of how specific actions can reduce their financial exposure.


About the Author

Yakir GolanYakir Golan is Co-founder and CEO of Kovrr. He started his career in the Israeli intelligence forces. Following his military service, he acquired multidisciplinary experience in software and hardware design, development and product management. For the past few years, he has been focused on bringing cyber risk management solutions based on advanced machine learning and artificial intelligence to the market. Golan holds a BSc in Electrical Engineering from the Technion, Israel Institute of Technology and an MBA from IE Business School, Madrid, Spain.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Web Application Risks You Are Likely to Face

Web application risks

While there is no guarantee to evade web application risks completely, having a basic idea of the risks can go a long way in mitigating them. It is crucial to know the common types of risks like SQL injections, weak access controls, weak authentication, cross-site request forgery etc., and their potential to minimize the risks.

Here are some of the potential web application security risks you need to know to strengthen your organization’s web application security posture:

  1. A dictionary attack happens when the attacker tries multiple passwords combination uses an existing list of frequently-used words in the dictionary to access confidential information until the correct one is found. If you use common password variations like a large chunk of users, you might be at risk.
  2. Remote File Inclusion is a web application security risk imposed when the attacker exploits vulnerabilities in a web application that references external files or scripts. Such a type of attack is common in web applications that are poorly coded. It is a lethal attack that can even lead to a full system compromise.
  3. Given how easily preventable and curable SQL injection is, it is surprising that it is still quite common. An attacker can bypass authentication, steal confidential data, and cause severe disruptions by leaving an SQL injection.
  4. Arbitrary file download is another web app risk. Some web applications or web browsers allow the option for viewing or downloading files on your server. If this is not restricted or the input is not scrutinized, threat actors can send malicious requests or download confidential files from your server by exploiting this vulnerability.

These are just a few of the web-based application security risks. We are sure you want to know all about web application security risks to ensure that your company stays ahead of cyberattacks, and we are here to help you out with that. By enrolling in the Web Application Hacking and Security Certification at EC-Council, you will learn the emerging web application vulnerabilities and have the skills required to hack, test, and secure your enterprise from web application risks.

Web-Application-Potential-Risks

Become a Certified Web Application Security Professional today.  

Get Certified

What Does a Digital Forensics Investigator Do in an Investigation?

digital forensics

Digital forensics is an essential aspect of tracing computer-based crimes. With the rise in digital transformations and reliance on the web and mobile applications, there’s an augmented need for digital forensic investigators in cybersecurity. Every organization that uses cloud-computing technologies and devices needs computer forensics or digital forensics expert. Any device which stores digital data or is connected to the Internet forms a part of the investigation and can be crucial evidence in cracking a case.

Digital forensics is a branch of forensic science concerned with data acquisition, investigation, and analyzing digital devices for gathering evidence. Identifying, collecting, storing, and documenting computer data using digital tools to produce the necessary evidence that may be utilized in a court of law, is known as digital forensics investigation. For instance, a digital forensics examiner investigates cases related to an illegal intrusion in your organization’s network and tracks the digital footprints to trace the attacker.

Computer forensics tools and strategies serve both, private and criminal investigative purposes. Digital forensics is growing exponentially, and with the rate of cybercrimes rising, this field is spreading its reach to several other branches of databases, malware, firewalls, mobile devices, cloud, and network forensics.

This article explains the skills you need to qualify for a digital forensics job role and what is expected out of a digital forensics’ expert during the investigation.

How Do You Become a Digital Forensic Investigator?

A digital forensic expert needs to have extensive knowledge of data, forensic and legal principles, and procedures. People adept in this branch of forensics can specialize in different roles such as computer forensics technicians, computer forensics investigators. Cyber forensics experts, etc. A report in Mordor Intelligence forecasts the digital forensics market to reach $8,210.5 million by 2026.

In addition to getting a bachelor’s degree in digital forensics or an equivalent, you can also opt for credible online certifications or get a vendor-neutral credential.

You can further your digital forensics career by adding specialized degrees in due time to land high-paying jobs and stay abreast of your competition.

Simply put, the following are the steps required to become a digital forensic expert:

  • Bachelor’s degree or a master’s degree
  • Work experience in related fields
  • Become certified as an EC-Council Computer Hacking Forensic Investigator (CHFI)
  • Get relevant soft and hard skills
  • Apply for a digital forensic position
  • Meet the expectations of the certified forensic interviewer
  • Land the job position

How is Digital Forensics Used in Investigations?

A Digital forensics investigator follows a systematic procedure to unfold a cybercrime. As a forensics analyst, you have to be precise in your observations and ensure that the evidence is isolated and not tampered with. As a part of an organization’s security team, you have to follow meticulous cybersecurity procedures in case of an incident.

There are different uses of digital forensics in an investigation. Let’s look at the general steps required.

1. Planning

The planning phase is perhaps the most important strategy, to begin with. Cybercrimes occur at light speed, and one can never take enough precautions to protect their digital assets and networks from intrusions. Make a layout of your plan and approach them systematically. Identify your target and probable threats to gather evidence. As a digital forensics expert, you would also need to monitor and implement regulatory guidelines frequently.

2. Identification and Preservation

As a cyber forensics’ examiner, next comes the identification phase. You would need to find shreds of evidence or sources from digital devices after a data breach. Procuring key information or data from the crime scene, for example, identifying the location or in which format the evidence exists.

Additionally, preserving digital evidence or data is significant. Investigators should ensure that the evidence is not tampered with and should safeguard the original data or information after isolating the master copy.

3. Analysis

The next step is analyzing the evidence. To recreate the timeline of the crime, you would have to rebuild the pieces of evidence or information you have gathered. Besides, having the timestamps of the individual data or evidence you gathered in chronological order or fashion, you can pinpoint the source or get a clear picture to support your theory.

4. Documentation

Reconstructing the cybercrime scenario is easier when you record all the observations you made during the investigation. The primary purpose of gathering evidence is to be able to produce it in legal proceedings. Hence, your documentation should contain an in-depth investigation report with factual data, timestamps of the incidents followed, dated, and signed.

5. Presentation

The last phase includes presenting a summary of the relevant information or findings. As a digital forensics expert, your job is to ensure that your digital analysis report is free of any bias. Additionally, you need to summarize your data in a concise and chronological fashion, which can be understood by law enforcement and other corporate executives.

Why C|HFI is Your Go-To for All Things Digital Forensics

Digital forensics is an integral part of cybersecurity and is expanding to include network forensics, mobile forensics, firewall forensics, among others. The Internet era is certainly changing the way we store and share data, but on the flip side, cybercrimes are witnessing an upward trend. Therefore, there is a growing need for cybersecurity specialists trained in digital forensics.

So, if you have plans to make a career in this field, you would need to pursue a relevant forensics online course that aligns with industry-demand skills. While there are many credible courses, EC Council’s C|HFI program puts you at the top of the employment ladder.

The Computer Hacking Forensic Investigator (C|HFI) certification program by EC-Council aims to enhance the participant’s competence in identifying an intruder’s footprints. The modules also train individuals to gather all the relevant digital evidence needed to prosecute the perpetrator in a court of law.

C|HFI trains its participants in the core concepts of digital forensics, giving a methodological approach to computer forensics and evidence analysis that circles Dark Web, IoT, and Cloud Forensics. The program modules include using ground-breaking forensics tools and techniques to help the learner successfully execute digital investigations, identify complex security threats, and assist in data recovery programs.

Once you complete the training, you can qualify for a multitude of job roles as a certified forensic interviewer, forensics engineer, cybercrime investigator, forensic computer analyst, information technology auditor etc., and land high-paying jobs.


20+ Job Roles | 4,000+ Job Openings | Avg. Salary of $96,000

Start your C|HFI Certification and Explore New Career Opportunities in the World of Digital Forensics.


FAQs

  1. What is the first rule of digital forensics?

The first step in any digital investigation is to isolate the evidence and preserve it so that it is not tampered with. Identification and preserving digital evidence are a crucial step in cracking down on the perpetrators.

  1. How much can one earn as digital forensics professional?

According to PayScale, the average salary for a computer forensic analyst is $75,073. The median salary for an entry-level computer forensic analyst is $65,371, according to Salary.com.


References:

  1. https://www.eccouncil.org/what-is-digital-forensics/
  2. https://www.upguard.com/blog/digital-forensics
  3. https://www.sciencedirect.com/topics/computer-science/forensic-process

Australia, U.K., and U.S. Come Together in a Trilateral Security Partnership

Trilateral Security Partnership

While the cyberthreat landscape is crossing boundaries, multiple nations are coming together to safeguard the cybersecurity landscape. Australia, the U.K., and the U.S. recently came together to form a trilateral security partnership known as AUKUS. The new partnership was announced in a virtual press conference between POTUS Joe Biden, U.K. Prime Minister Boris Johnson, and Australian Prime Minister Scott Morrison. The security pact is committed to maintaining diplomatic, security, and defense cooperation in the Indo-Pacific region.

“Through AUKUS, our governments will strengthen the ability of each to support our security and defense interests, building on our longstanding and ongoing bilateral ties. We will promote deeper information and technology sharing. We will foster deeper integration of security and defense-related science, technology, industrial bases, and supply chains. And in particular, we will significantly deepen cooperation on a range of security and defense capabilities,” the White House stated.

Boosting Cybersecurity Together

In addition to improving undersea and defense capabilities, the three nations also announced their plans to boost the cybersecurity environment against rising cyberattacks. AUKUS is committed to enhancing cybersecurity, artificial intelligence, quantum computing, and other critical technologies.

“The endeavor we launch today will help sustain peace and stability in the Indo-Pacific region. For more than 70 years, Australia, the U.K., and the U.S. have worked together with other important allies and partners to protect our shared values and promote security and prosperity. Today, with the formation of AUKUS, we recommit ourselves to this vision,” the White House added.

Collective Visions for Better Cybersecurity

Governments and organizations across the globe are looking for additional resources and cybersecurity collaborations to deter the evolving cyberthreat landscape. Earlier, the U.S. and Australia signed “The Cyber Training Capabilities Project Arrangement” to strengthen cybersecurity practices and boost partnerships in cyberspace. The Biden administration recently brought various tech giants like Google, Microsoft, IBM, and Apple together to address the rising cyberthreat landscape and improve the security of technology in the U.S.

Cybercrime in India Surges by 11.8% in 2020: NCRB

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

It’s not only about the new normal, but the pandemic is also the beginning of a new era in the cyberthreat landscape. The year 2020 witnessed the emergence of new cybercriminal groups and hacking techniques. Several organizations across the globe encountered a significant number of cyberattacks during the pandemic than ever before. Especially, companies and users based in a densely populated country like India, who suffered different kinds of phishing lures and ransomware threats. According to a recent analysis from the National Crime Records Bureau (NCRB) of India, a total of 50,035 cybercriminal cases were registered in 2020, an increase of 11.8% compared to 2019 (44,735 cases). The NCRB is responsible for collecting and analyzing the cybercriminal data reported in the country.

The report Crime in India-2020” revealed that the cybercrime rate surged from 3.3 in 2019 to 3.7 in 2020. Nearly 60% (30,142) cybercriminal cases reported were financially motivated, followed by sexual exploitation with 6.6% (3,293 cases) and extortion schemes with 4.9% (2,440 cases). In addition to cybersecurity crimes, the report also published the statistics of various other crimes reported to the law enforcement authorities during 2020.

Array of Cybercrimes

Around 4,047 online banking fraud cases, including 1093 OTP frauds, 1194 credit/debit card scams, and 2160 cases related to ATMs, were reported during 2020. Threat actors leveraged social media platforms to spread malware and phishing scams. Over 578 cases of fake news on social media, 149 fake profiles, 972 incidents of cyberstalking or bullying, and 98 sensitive data thefts were reported to the NCRB.

Rate of Cybercrimes 

Among all states in the country, the maximum number of cybercrime cases were reported in Uttar Pradesh (11,097), followed by Karnataka (10,741), Maharashtra (5,496), Telangana (5,024), and Assam (3,530). In addition, the highest cybercrime rate was reported in Karnataka (16.2%), followed by Telangana (13.4%), Assam (10.1%), Uttar Pradesh (4.8%), and Maharashtra (4.4%).

“Crime is not only a malafide occurrence which violates the law of the state, but also a negative externality with enormous social and economic costs. Rapid changes in how people interact with each other, especially on a global scale enhanced by the internet, create a social dynamic that criminals can easily take advantage of in extending their reach. The statistics presented in the report will help in the data-based analysis and understanding the complex phenomenon of crime,” Ram Phal Pawar, Director of NCRB, said.

Malware and Vulnerability Trends Report: High-risk Vulnerabilities in Corporate Software Frequently Targeted

Malware and Vulnerability Trends Report, Mobile malware threats

Since devices are connected to the internet more than ever before, exploiting vulnerabilities to cross privilege boundaries has become common. Recently, Recorded Future and Insikt Group released the H1 2021: Malware and Vulnerability Trends Report, which talks about how the marketplace for ransomware matured as more operators began hiring affiliates to increase the effectiveness of their attacks.

With innovative techniques and sophisticated tools, threat groups exploit flaws to deliver, distribute and execute malicious code onto vulnerable systems. Given this scenario, proactively identifying malware and patching vulnerabilities is fundamental to bolstering network and application security posture.

Despite attempts to fortify the systems and maintain stringent security hygiene, the first half of 2021 witnessed several notable cyber incidents that gained mainstream attention due to their wide effect and novel techniques used in attacks.

The modus operandi of the threat actors in these notable incidents was to take advantage of critical vulnerabilities to deploy malware onto compromised systems such as Accellion FTA software, Microsoft Exchange Servers, macOS, and QNAP devices. Ransomware operators have demonstrated increased sophistication by adding DDoS to their attacks, targeting Linux systems, rapidly exploiting newly disclosed vulnerabilities, and even targeting zero-day vulnerabilities in attacks.

Highlighting the botnet activity investigation and taking down of Emotet botnet in January 2021, the report reveals how it opened a gap in the botnet space. This gap, in turn, gave rise to the use of other bots, including Trickbot, IcedID, BazarLoader, and Qakbot over the last quarter.

Deliberating on the trends within the vulnerability landscape, the report stated that vulnerabilities in corporate software were more frequently targeted than consumer-grade software, and high-risk vulnerabilities across major vendors spiked in the first half of the year.

Microsoft and Apple Most Targeted

Microsoft products being most commonly used have historically been a major target of vulnerability exploitation; in early 2020, Microsoft dominated the list of high-risk vulnerabilities. However, in Q1 2021, Microsoft’s high-risk vulnerabilities accounted for less than 25% of the total 39.

According to the report, the number of high-risk vulnerabilities in Recorded Future’s data set spiked from 39 in Q1 to 70 in Q2 2021. The number of vulnerabilities reported to be exploited jumped from 17 to 34.

PrintNightmare, with assigned CVE-2021-1675, was most referenced for the quarter, affecting the Windows print spooler service, largely due to Microsoft’s failure to initially patching the flaw, which is unusual for the company. However, Microsoft has now fixed these vulnerabilities and made an announcement in its September 2021 Patch Tuesday advisory.

Apple, known for its inherent security features in its products, was among the highly affected vendors. In Q2 2021, attackers exploited vulnerabilities in Apple’s MacOS, Safari, iPhone OS, iPad OS, tvOS, and WatchOS. Earlier this week Apple released security updates for two critical zero-day vulnerabilities, tracked as CVE-2021-30860 and CVE-2021-30858. In an urgent update, Apple has urged its customers to run the latest software updates for the fixes to take effect by installing iOS 14.8, MacOS 11.6 and WatchOS 7.6.2.

Threats to Expect

As per the threat analysis:

  • Ransomware will continue to make headlines, with its evolution and development in the ransomware market.
  • Apple products will continue to be susceptible to more vulnerability exploitation.
  • Botnet malware delivery may see a surge.

For more information, download a copy of the report here.

Microsoft Account Passwords Might Soon Be a Thing of the Past

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

Almost every cyberattack report mentions user credentials and passwords being stolen and sold on dark web forums. Be it ransomware, malware or any phishing attack, the core of all these attacks is stolen passwords. Microsoft, with one of the largest user bases, has announced that you will not need passwords anymore to access your Microsoft accounts.

See also: Dump the Password! 80% CISOs say They are Not an Effective Means of Data Protection

Microsoft had rolled out this initiative earlier in March 2021 as a pilot, for its enterprise users to adopt alternative secured authentication methods and discontinue the usage of passwords.

It recommends alternative authentication options such as:

  • Security keys
  • Verification codes sent via email or SMS
  • The Windows Hello biometrics system
  • Or the Microsoft Authenticator mobile app.

This feature of not having to use passwords has been long anticipated, a widely requested ask by Microsoft’s enterprise customers. With brute-force attacks becoming the order of the day, and billions of user data and passwords being shared online, system administrators and security teams have been grappling with improving the security hygiene of their organizations.

Vasu Jakkal Corporate Vice President, Security, Compliance and Identity, Microsoft, shared that by going “passwordless” with Microsoft, consumers can have more convenient and secure access to their favorite apps and services like Outlook, OneDrive, Family Safety and more.

Use of Windows Hello, the Microsoft Authenticator app, SMS or email codes, and physical security keys provide a more secure and convenient sign-in method.

A YouGov survey commissioned by Microsoft found that 30% of people preferred to stop using an account or service rather than go through the process of a password reset. In the same survey, it was disclosed that the inability to remember a password is the number one password problem for one-third of the respondents.

Password Conundrum

As per The Record, Microsoft is currently seeing a whopping 579 password attacks every second, amounting to 18 billion every year. Jakkal blamed the situation on today’s authentication conundrum where users struggle with remembering account passwords and for a matter of convenience use and reuse the same password for multiple accounts or use simple passwords like pet’s name, birthdays, family names or 123456 — which are easy to remember and equally easy to guess by attackers.

Bret Arsenault, Chief Information Security Officer (CISO) at Microsoft says, “Hackers don’t break-in, they log in.”

The password problem has been attributed primarily to human nature. As passwords get more complex to mitigate the exposure risk, they are also becoming more challenging to be memorized and managed across platforms. This problem also has direct ramifications on the business as users prefer to ditch the account completely instead of doing a password reset task which translates into customer loss. Most users continue to rely on simple combinations that are easy to remember and common across accounts. Hackers also find it easier to hack these combinations and sell the exploits on the dark web.

Passwords have been the most common and important layer of security and authentication for years for digital life. The Microsoft announcement is a welcome change but how fast and error-free will the adoption be, is yet to be ascertained. It would be interesting to watch how the threat actors will react to this feature and find a workaround to continue leveraging the vulnerabilities and what will they put up for ransomware?

How to Go Passwordless

Quick steps:

  • Ensure you have the Microsoft Authenticator app installed and linked to your personal Microsoft account.
  • Next, visit your Microsoft account, sign in, and choose Advanced Security Options.
  • Under Additional Security Options, you’ll see Passwordless Account. Select Turn on.
  • Follow the on-screen prompts, and then approve the notification from your Authenticator app.
  • Once you’ve approved, you’re free from your password!

And, in case you prefer to use a password, you can always add it back to your account.

Learn more about enabling passwordless sign-in with the Microsoft Authenticator app here.

South Africa’s Department of Justice Network Under Ransomware Attack

Accenture ransomware attack, South Africa Justice Department

The Department of Justice and Constitutional Development of South Africa admitted that its IT systems and operations were disrupted in a ransomware attack. The security incident encrypted all the information systems, making their services unavailable to employees and the public. The department’s entire electronic services, including bail services, email, and websites, went offline that caused authorities to go for manual operations.

Cybercriminals often spread ransomware via phishing emails that contain Trojans or malware, infecting the targeted systems and encrypting critical files.

“The Department would want to assure all affected parties that our IT teams are working tirelessly to restore services as soon as is practically possible. Child Maintenance payments for month-end have already been processed and will therefore not be impacted by the current system outage,” the department said in a statement.

No Sign of Data Misuse

While the threat actors behind the ransomware attack are unknown, the department’s security experts are working together with state agencies to investigate the cyberattack. “The Department has activated its Business Continuity Plan and put contingency measures in place to ensure that the IT system challenges do not affect court operations around the country. Manual recording equipment will be used to ensure that court seating continues as scheduled,” the statement added.

This is not the first time South Africa has sustained a cyberattack. Earlier, a survey revealed that businesses in South Africa suffered various network attacks between March 15 to March 21, 2020, affecting 310,000 devices in one week.

Why Hackers Target Govt. Bodies

Ransomware operators targeting government agencies have increased in recent times. From the U.S. Colonial Pipeline to the Indian energy sector, several cyberattacks by various cybercriminals groups have been reported lately since critical infrastructure in any country is operated under government departments. Threat actors deliberately target government agencies to cause maximum damage and demand high ransom, expecting public agencies to pay ransom to continue their critical operations.  For instance, Colonial Pipeline reportedly paid a $4.4 million ransom to cybercriminals to restore the paralyzed operations and avoid trouble to the citizens.

Microsoft September 2021 Patch Tuesday: Mitigations and Workarounds

Microsoft September 2021 Patch Tuesday

Microsoft released fixes for 60 security vulnerabilities in its latest September 2021 Patch Tuesday update. Out of 60 vulnerabilities, 56 were determined as important, and four as critical bugs existing in Microsoft Windows, SharePoint Server, Edge browser, Azure Sphere, Microsoft Edge for Android, Microsoft Visio, Visual Studio, Windows BitLocker, Microsoft Windows DNS, and the Windows Subsystem for Linux. The security update also patched a critical zero-day vulnerability CVE-2021-40444 in Windows  MSHTML (Trident) engine that was exploited in the wild lately, along with three elevations of privilege vulnerabilities CVE-2021-38667, CVE-2021-38671 and CVE-2021-40447 in Windows Print Spooler.

Other critical flaws resolved in the update

  1. CVE-2021-38647 – This remote code execution (RCE) vulnerability affects the Open Management Infrastructure (OMI) program. If exploited, the vulnerability could allow an attacker to execute RCE attacks by sending malicious messages via HTTPS to port 5986.
  2. CVE-2021-36968 – Microsoft stated there is no sign of exploiting this Windows DNS privilege escalation zero-day vulnerability.
  3. CVE-2021-26435: Attackers could exploit this Windows Scripting Engine Memory Corruption vulnerability by sending a specially crafted file to the user and convince the user to open the file. An attacker could host a website containing a specially crafted file designed to exploit the vulnerability in a web-based attack scenario.
  4. CVE-2021-36967: Attackers could exploit this critical Windows WLAN AutoConfig Service Elevation of Privilege vulnerability to obtain the elevation of privileges on the targeted devices.

Diversity of Vulnerabilities

Microsoft stated that Elevation of Privilege (EoP) vulnerabilities accounted for 41.7%, followed by remote code execution (RCE) vulnerabilities (26.7%), information disclosure (16.7%), Spoofing (10%), Security feature bypass (3.3%), and Denial of service (1.7%).

Microsoft strongly recommended users and organizations apply the patches to fix the flaws and prevent potential hacker intrusions.

What Experts Say

Satnam NarangSatnam Narang, Staff Research Engineer at Tenable, said, “This month’s Patch Tuesday release includes fixes for 60 CVEs, four of which are rated critical. So far in 2021, Microsoft patched less than 100 CVEs seven out of the last nine months, which is in stark contrast to 2020, which featured eight months of over 100 CVEs patched. This month’s release includes a fix for CVE-2021-40444, a critical vulnerability in Microsoft’s MSHTML (Trident) engine. This vulnerability was disclosed on September 7, and researchers developed several proof-of-concept exploits showing the ease and reliability of exploitation. An attacker would need to convince a user to open a specially crafted Microsoft Office document containing the exploit code. There have been warnings that this vulnerability will be incorporated into malware payloads and used to distribute ransomware. There are no indications that this has happened yet, but with the patch now available, organizations should prioritize updating their systems as soon as possible.”