Home Blog Page 56

Zero-day Vulnerability in Windows MSHTML Exploited

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

An unpatched Windows 10 vulnerability has been exploited once again and the bounty shared on hacking forums. A security advisory from Redmond shares that the security hole CVE-2021-40444 affects the “MSHTML” component of Internet Explorer (IE) on Windows 10 and many Windows Server versions.

According to an announcement the zero-day Windows 10 vulnerability in Windows MSHTML allows attackers to create malicious documents, including Office and RTF documents and give control to the attacker to remotely execute commands on a victim’s computer.

Although no security updates are available for the vulnerability CVE-2021-40444, Microsoft has decided to disclose the vulnerability and provide mitigation to the threat to prevent further exploitation.

In its statement Microsoft said, “An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.”

If the ActiveX controls and Word/RTF document previews are blocked in IE, the threat can be mitigated. But the attackers were able to modify the exploit and not use ActiveX, and bypass Microsoft.

Exploits shared

Taking the immediate lead from the disclosure by Microsoft on the Windows MSHTML Zero-Day, tracked as CVE-2021-40444 vulnerability, hacking forums and security researchers got into action and discovered the malicious documents used in attacks online and who was further abusing them.

They had a field day reproducing, exploiting and further modifying these documents for more functionality and vulnerabilities. This gave advantage to threat actors who further exploited these samples posted online and shared them with their fellow attackers on hacking forums.

According to a report on Bleeping computers, the information is easy to follow and allows anyone to create their own working version of the CVE-2021-40444 exploit, including a Python server to distribute the malicious documents and CAB files.

Microsoft advises

  1. Block ActiveX control in IE by disabling it
  2. Deactivate document preview in Windows Explorer

Users still have to be cautious till an official security update is released as threat actors have further modified the vulnerabilities to bypass Microsoft.

Spate of Microsoft Vulnerabilities

Every cybersecurity site has been reporting Microsoft vulnerabilities since the beginning of the year. In the month of August alone Microsoft released 44 security patches. Some of the reported affected tools include .NET Core & Visual Studio, ASP.NET Core & Visual Studio, Azure, Windows Update, Windows Print Spooler Components, Windows Media, Windows Defender, Remote Desktop Client, Microsoft Dynamics, Microsoft Edge (Chromium-based), Microsoft Office, Microsoft Office Word, Microsoft Office SharePoint and more.

Microsoft Vulnerabilities Report 2021 by BeyondTrust highlights, unpatched vulnerabilities are the cause of 1 in 3 breaches around the world.

Key findings

  • 1,268 Microsoft vulnerabilities were discovered in 2020, a record-high number with a 48% increase YoY
  • Reported vulnerabilities has risen 181% in the last five years (2016-2020)
  • For the first time, “Elevation of Privilege” was the #1 vulnerability category, comprising 44% of the total, nearly three times more than in the previous year

Microsoft being the most widely used platform is an obvious target and open to vulnerabilities given its large user base. There have been high number of zero-threats being reported and we need to see more proactive patching and response to these exploits.

Meris Botnet Hits Russian Search Engine Yandex Again with 21.8 Mn RPS

DDoS attack on VoIP Providers , DDoS Attacks , DDoS Attack on Yandex

The Russian internet service provider Yandex admitted that it had sustained a Distributed Denial-of-Service (DDoS) attack that temporarily affected its operations. The attack is denominated as the largest DDoS attack in the history of the Russian Internet (RuNet). Security experts claim that the attack was implemented via a new botnet tracked as Meris.

RuNet is the Russian internet infrastructure created to provide internet services in the territory of Russia. Also known as the Russian-language Internet, RuNet provides a unified country-wide Internet and communications and shields the country from foreign adversaries.

“Yandex did indeed undergo a DDoS attack, which was repelled by our network infrastructure and system for filtering unwanted requests. The attack did not affect the operation of the services, user data was not affected,” Yandex said in a media statement.

Meris Botnet

In a DDoS attack, cybercriminals make a targeted network or service unavailable to its users by flooding it with unwanted incoming traffic from different sources. Joint research from Yandex and Qrator Labs revealed that the DDoS attack power was more than 20 million requests per second (RPS), affecting over 30,000 host devices. Yandex observed that the attack on its servers relied on 56,000 attacking hosts, which might have compromised over 250,000 devices.

“We suppose the number to be higher – probably more than 200,000 devices, due to the rotation and absence of will show the ‘full force’ attacking at once. Moreover, all those being competent devices, not your typical IoT blinker connected to Wi-Fi – here we speak of a botnet consisting of, with the highest probability, devices connected through the Ethernet connection – network devices, primarily,” the research stated.

The DDoS mitigation services provider Cloudflare also mentioned that the attack reached over 17 million requests per second.

Features of Meris Botnet:

  • Socks4 proxy at the affected device
  • Use of HTTP pipelining technique to launch DDoS attacks
  • Making the DDoS attacks themselves RPS-based
  • Open port 5678 enabled

It is found that several Meris botnetbased DDoS attacks are primarily reported in New Zealand, the U.S., and Russia.

Timeline of Botnet Attacks on Yandex

This is not the first time for Yandex to suffer an attack from Meris botnet. The history of attacks from the same botnet against Yandex were reported on:

  • 2021-08-07 – 5.2 million RPS
  • 2021-08-09 – 6.5 million RPS
  • 2021-08-29 – 9.6 million RPS
  • 2021-08-31 – 10.9 million RPS
  • 2021-09-05 – 21.8 million RPS

DDoS Attacks on Rise

From small businesses to the largest enterprises, all kinds of industries encounter DDoS attacks once in a while and are growing at a rapid pace. The Meris botnet could grow in force to cause even more severe disruptions via various kinds of attacks exploiting the vulnerabilities in the system.

Alexander Lyamin, CEO of Qrator Labs, said, “The victims of these attacks are different, but the perpetrator, apparently, is the same, and he operates a botnet that has recently appeared in the industry. Some industry players have already announced that the Mirai botnet, which made a splash five years ago and was built on the basis of video cameras, has returned. Having devoted the last few weeks to studying the new botnet, we can say that a completely new botnet has appeared and it is built on the network equipment of a very popular vendor from the Baltic States. It spreads through a vulnerability in firmware and already numbers up to hundreds of thousands of infected devices.”

Intrusions Increase by 60% Across all Sectors: CrowdStrike Report

Threat Hunting Report, security breach, data breach, data breach management

CrowdStrike has just released its annual report that confirms an explosion in adversary activity, both in volume and velocity. The CrowdStrike Falcon OverWatch annual report is titled, “Nowhere To Hide, 2021 Threat Hunting Report: Insights from the CrowdStrike Falcon OverWatch Team.” CrowdStrike’s threat hunters tracked a 60% increase in attempted intrusions spanning all industry verticals and geographic regions.

The report also showcases a significant drop in average breakout time – the time it takes for an intruder to begin moving laterally outside of the initial beachhead to other systems in the network – of just one hour 32 minutes, a threefold decrease from 2020. These sobering statistics show how threat actors are constantly adapting tactics, techniques, and procedures (TTPs) to accelerate their march toward their objectives.

Key Findings:

  • Adversaries have moved beyond malware. They are using increasingly sophisticated and stealthy techniques tailor-made to evade detections — of all of the detections indexed by CrowdStrike Threat Graph® in the past three months, 68% were malware-free.
  • China, North Korea and Iran were the most active state-sponsored groups. The report reveals the majority of targeted intrusion activity from adversary groups were based out of China, North Korea, and
  • A massive surge in interactive intrusion activity targeting the telecommunications industry. This activity spans all major geographic regions and has been tied to a diverse range of
  • WIZARD SPIDER was the most prolific cyber criminal. In fact, this group was seen in nearly double the number of attempted intrusions than any other eCrime group. WIZARD SPIDER is behind targeted operations using Ryuk and, more recently, Conti ransomware.
  • A 100% increase in instances of cryptojacking in interactive intrusions year-over-year, correlating with increases in cryptocurrency prices.
  • Access Brokers had a banner year. eCrime actors who specialize in breaching networks to sell that access to others played a growing and important role for other eCrime actors to stage their attempted.

“Over the past year, businesses faced an unprecedented onslaught of sophisticated attacks on a daily basis. Falcon OverWatch has the unparalleled ability to see and stop the most complex threats — leaving adversaries with nowhere to hide,” said Param Singh, vice president of Falcon OverWatch, CrowdStrike. “In order to thwart modern adversaries’ stealthy and unabashed tactics and techniques, it’s imperative that organizations incorporate both expert threat hunting and threat intelligence into their security stacks, layer machine-learning enabled endpoint detection and response (EDR) into their networks and have comprehensive visibility into endpoints to ultimately stop adversaries in their tracks.”

The report is comprised of threat data from Falcon OverWatch, CrowdStrike’s managed threat hunting team, with contributions from CrowdStrike Intelligence and Services teams, and provides an inside look at the current threat landscape, notable adversary behavior and tactics, and recommendations to increase cyber resiliency. In the 2021 report, CrowdStrike’s threat hunters directly identified and helped to disrupt more than 65,000 potential intrusions – approximately one potential intrusion every eight minutes.

Falcon OverWatch

The mission of Falcon OverWatch is to augment the powerful, autonomous protection of the Falcon platform with smart, mission-focused expertise to deliver the outcomes necessary to stay safe. Falcon OverWatch harnesses the massive power of the CrowdStrike Threat Graph®, enriched with CrowdStrike threat intelligence, to track, investigate and advise on sophisticated threat activity. The cloud-scale telemetry of approximately 1 trillion endpoint-related events collected per day, coupled with the detailed tradecraft on over 160 adversary groups, and enriched by automation of the CrowdStrike Falcon® platform provides the OverWatch team with the unrivaled ability to quickly identify and stop the most advanced threat actors. OverWatch’s insights into new and novel adversary behaviors help to continuously advance the protection provided by Falcon, resulting in the proactive prevention of malicious activity on approximately 248,000 unique endpoints.

Download a copy of the report here.

Blue Team Security Certifications in 2021: Grow Your Career

Blue team security certification

IT and Security professionals with blue team security certifications can be part of an organization’s blue team and build defensive security measures. The blue team and the red team are an integral part of cybersecurity, and both the teams work to defend against an attack but operate on two different security mechanisms. The red team takes an offensive approach, while the blue team employs defensive measures to identify security issues. Organizations need to adopt both offensive and defensive cybersecurity strategies to deter malicious attacks. We will learn about these approaches later in the article.

However, the demand for an individual with blue team security certifications is expected to rise in 2021. People with these certifications can expect a rewarding career path because of the numerous opportunities in cybersecurity.

Organizations prefer individuals with blue team security certifications because their mechanisms ensure the long-term safety of their digital assets with frequent monitoring and checks for intrusions.

This article explains everything you need to know about blue team security and certifications, along with career prospects in 2021.

What Is Blue Team Security?

Blue Team Security, sometimes known as the “blue team,” oversees an organization’s internal and external security. They conduct an in-depth study of the networks and system infrastructure to identify and fix security problems. Blue team professionals deploy several techniques like network segregation, deploying firewalls, managing access control, among other countermeasures to defend against an intrusion or cyberattack. A Blue Team security certification validates a candidate’s potential and skills acquired during the course training.

An organization has a blue team and a red team. The goal of both groups is to ensure that adequate security measures are taken and followed to ensure data security. Although they have the same goal, their functions are completely the opposite.

Red Team vs. Blue Team 

The Red Team is a group of security professionals who take an offensive or proactive approach to foil a cyberattack. Offensive security techniques like pen testing and threat hunting can identify existing vulnerabilities before threat actors do. Besides, they exploit system vulnerabilities and derive strategies based on objective observations. So, red team groups think like ethical hackers or black hat hackers.

On the contrary, Blue Team experts deploy defensive techniques to safeguard the companies’ network or system from cyberthreats. Moreover, they operate from an insider point of view and monitor and block suspicious activities that could lead to an attack. So, they think like the internal security team.

While the red team implements the same techniques as malicious attackers to identify network flaws, the blue team implements different strategies to defend from those attacks.

Next, we shall learn of a few tasks that blue team professionals perform to test the security of the organization.

What Exercises Do Blue Team Security Professionals Conduct?

The blue team works on simulated threats to determine the risk factors that could arise in real-world attack scenarios. Their role is to identify and mitigate the threats arising from both internal and external factors. Additionally, blue team professionals are trained to defend their organization’s network during a breach by isolating the infected systems and preventing them from spreading to other devices. The blue team participates in the following exercises:

  • Monitor any suspicious actions on the network and identify compromised systems.
  • Use specialized defensive techniques to study web traffic logs for attack analysis.
  • Use IPS and IDS tools to check and report intrusions in IoT devices or network activity.
  • Identify potential breaches in the system and network’s infrastructure.
  • Monitor and assess your organization’s incident response procedures.
  • Acquire information about the existing security structure via risk assessments.
  • Strengthen security measures in processes.

Key Skills of Blue Team Professionals

Blue team experts are network defenders who perform periodic security checks and assess vulnerabilities through specialized tools and control measures. Therefore, to be a qualified blue team professional, one must undergo appropriate training and possess the skill set to excel at their work. So, let’s look at the skills one requires to get onboard.

  • Strategic: One must gauge an attack or threat’s impact and come up with an apt security strategy that would help prevent or minimize the damage after a data breach or attack.
  • Meticulous: Paying attention to the minute details and analyze situations based on experience and preliminary case analysis to improve security standards and defense structure.
  • Knowledge about appropriate tools and detection methodologies: Should have in-depth knowledge about the various tools like Rapid7, AlienVault, or Spunk, software such as SIEM, and detection systems such as Intrusion Detection System and Intrusion Prevention System, etc., which can be used to prevent/reduce the impact of an attack.
  • Attention to detail: A blue team expert is organized and carries a detailed mindset. If you have an eye for detail, you can identify and close security gaps in your information systems.

Career Progression and Job Prospects In 2021

Work-from-home and digital reliance have driven productivity amidst the ongoing pandemic but have also escalated the risks of cyberattacks. Cybercriminals are always devising new methods for launching malware and ransomware campaigns, as well as breaching network security with corporate digitization. Moreover, with cybercrimes going up, businesses are revamping their security strategies. Retraining IT professionals in the latest cybersecurity skills and hiring new cybersecurity recruits is the new mantra. There’s an exponential demand for blue team professionals, which has opened countless opportunities for them. With a Blue team security certification, one can qualify to be a:

  • Entry-level Network Security Administrator
  • Junior Network Security Engineer/Defense Technician
  • Security Analyst/Operator
  • Data Security Analyst
  • Threat Intelligence Analyst
  • Application Security Engineer

Next, we shall highlight the blue team security certifications aspirants and professionals can pursue to further their roles.

Roadmap to Blue Team Security Certifications

EC Council offers a range of certifications that train and test you on defensive security techniques used in real-life scenarios.

There are numerous network security or network defense certification programs that one can pursue to qualify for blue team positions.

Network Security Fundamentals

EC-Council’s Network Security Fundamentals is a good start for entry-level aspirants to learn network security fundamentals. This program is mapped to the skills required to detect network security threats and assess an organization’s security infrastructure challenges. Participants can expand their knowledge in networks fundamentals, various components of the OSI and TCP/IP model, and concepts of identification, authentication, and authorization.

Certified Network Defender (CND v2)

Another promising program for security professionals who aspire to be a part of the blue team is the Certified Network Defender (CND v2). The CND v2 focuses on a unique approach — Protect, Detect, Respond, and Predict, which enables network defenders to anticipate the moves of threat actors. Moreover, it is accredited by the U.S. Department of Defense (DoD), NICF, ANSI, etc., and enhances the chances of being preferred over other candidates. Mapped to the NICE 2.0 framework, CND v2 offers practical, hands-on learning in real-world challenges.

There are other specialized programs offered by EC-Council which can help you grow further in your career.

Career path to blue team certification

For more information about our Blue Team Security Certifications, visit our network Defense page today!

Recognized and Accredited by DoD 8570 & ANSI/ISO/IEC 17024

Get your Network Security Certification at EC-Council


FAQs

  1. What are the essential skills required to be on the blue team?

Blue team individuals should have advanced knowledge of SIEM and be familiar with detection applications and systems to track any suspicious activity.

  1. Do you need a red team or a blue team in your organization?

An organization needs the skill set of both the red team and the blue team to strengthen its system and network security. While both teams have different exercises, their objective is the same. Organizations can reduce cyberattacks by having a combination of both red and blue teams.


References:

  1. https://en.wikipedia.org/wiki/Blue_team_(computer_security)
  2. https://purplesec.us/red-team-vs-blue-team-cyber-security/#BlueDo
  3. https://www.xmcyber.com/what-is-a-blue-team/
  4. https://www.itlab.com/blog/understanding-the-roles-of-red-blue-and-purple-security-teams
  5. https://www.cybervie.com/blog/how-to-be-good-at-blue-team/
  6. https://www.crowdstrike.com/cybersecurity-101/red-team-vs-blue-team/
  7. https://securitytrails.com/blog/cybersecurity-red-blue-team

What Are Network Protocols and How Are They Used?

Network protocols, FIN7 hackers

Network protocols are a set of pre-defined rules and guidelines that computer-related devices follow to enable network communication. These standard rules framework in the Internet protocol suite include identifying and establishing connections among devices. Moreover, they also define how the transfer of data can occur to and from different devices in the same network.

Created according to the industry standards by networking and technology organizations such as IEEE, W3Consortium, ISO (International Standards Organization), and others, network protocols are essential for seamless communication between devices. Additionally, two or more devices based on different infrastructural devices or standards can also communicate through standard network protocols. These protocols include guidelines that monitor access methods, cabling type, data transfer speed etc.

This article explains the use of network protocols, how they work, and a few of their common types.

Use of Network Protocols  

Network protocols can be used for digital and analog communications. Furthermore, these standard communication protocols can check for authorization and detect errors in the communication channel. Network communication is carried out through wireless network protocols, wired network protocols, Internet protocols etc.

Network protocols are used for accessing the Internet, transferring files among devices, automating processes on the network, and sending messages across the internet network.

The Internet protocol suite ensures that the network operates seamlessly and maintains connections among devices. Apart from this, network protocols help network administrators to locate and fix errors. Specific security-based protocols are responsible for securing data transmission, authenticating users on a network, not allowing unauthorized users to bypass the network and spoof the data passed on the network.

Several types of protocols are in use today for enabling communication between devices across the network. Let’s understand a few types of network protocols in use today.

1. Transmission Control Protocol (TCP)

Transmission Control Protocol (TCP) is a network communication protocol that allows applications and devices to communicate over a network. TCP integrates with Internet Protocol (IP) for data and communication transmission; therefore, the Internet protocol suite is also known as TCP/IP.

Additionally, it ensures that the data packets sent over the web are delivered from source to destination securely. TCP enables a smooth end-to-end delivery of messages and information. Further, it establishes a connection between source and destination and breaks the data into smaller chunks of packets while maintaining data integrity. Protocols such as FTP, SSH, and Telnet use TCP to transmit data.

Advantages:

  • Ensures data reaches the destination node
  • Timely delivery of data

2. File Transfer Protocol (FTP)

File Transfer Protocol (FTP) is used for transmitting files between devices or applications across TCP/IP connections. To facilitate FTP exchange, the computer (local host) and the server (remote host) should be connected through a network and configured. A standard communication protocol built on a client-server framework, FTP enables file transfer between server and client.

FTP allows users to download and transfer files from one device to another with an established Internet connection. It also will enable systems to move files that are stored remotely on the cloud. FTP functions when a client requests a file supplied by a server. A data channel is established for clients to request files and download, copy, or edit the files. Additionally, FTP enables private file sharing.

Advantages:

  • Allows sharing large files
  • Enables recovery of lost data

3. Simple Mail Transfer Protocol (SMTP)

Simple Mail Transfer Protocol or SMTP, as it is popularly known, is another example of a standard communication protocol that enables email transmission over the Internet.

Even though it can send and receive emails, it is primarily used to send text messages. Moreover, it can also work or integrate with POP3 (Post Office Protocol) and IMAP (Internet Message Access Protocol) to retrieve emails on the destination end, while SMTP serves to send emails from the source.

Apart from this, its primary function is to establish and facilitate communication rules between servers for messaging.

Advantages:

  • Flexible with existing systems
  • Dedicated server for outgoing emails

4. Hypertext Transfer Protocol (HTTP)

Hypertext Transfer Protocol (HTTP) is a network layer protocol that enables data transfer from a web server to a web client. Besides, it is one of the most widely used protocols to set up communication between the browser and server. It lets users communicate data on the world wide web. Furthermore, it transmits hypertext between clients and servers to interact with web browsers and HTML files. HTTP uses task-oriented methods to request a specific source, add content messages, modify existing web resources, or delete a particular resource. Additionally, it establishes a single connection to share files and allows you to send files from one host to another.

Advantages:

  • Provides accessibility by storing content into the cache memory
  • Allows multiple connections to download the same file simultaneously

Implementing Network Protocols  

Network protocols are built on one another. However, they are merely a set of established rules and guidelines and not codes or software pieces.

The network protocols are implemented as services on a system. The system follows the defined set of standard rules while operating over a network and interacting with an application or system. The system hardware works by reading streams of bits and implements the protocols according to the flow of layers in the OSI model. Some network protocols are implemented on hardware (physical layer), while others are programmed in software as part of an operating system or application.

Internet or network protocols govern client-server communications and are the foundation for enabling digital communications. They also set up secure and high-performance network communication. While Internet infrastructure would be crippled without these pre-defined rules and standard frameworks, ensuring network security is also crucial. Massive volumes of data or information are shared over a network, which makes it prone to intrusion. Hence, to defend your network, you need to have a thorough understanding of the application layer protocols and how devices and processes work together. This is where credible programs like Certified Network Defender (C|ND) can help you further your knowledge and skills.

Become a Certified Network Defender 

As previously mentioned, Network protocols play a crucial role in network security. They enable the digital transmission of data over a secured network channel and govern the data transmitting activities on the Internet. Network security protocols also ensure that the data is safe from unauthorized malicious users by encrypting the network channel to access the data packets. Without network routing protocols, the way we engage with people across the globe would be challenging.

A network defender can implement and monitor these network protocols to ensure that data is safe from theft.

An accredited certification such as Certified Network Defender (C|ND), which is 100% focused on network security and defense, enables a network defender or cybersecurity professional to grasp the fundamentals of networking. Understanding networking concepts will help them set up and secure network protocols to ensure endpoint security, tackle network attacks, and maintain technical network security.

Recognized and Accredited by DoD 8570 & ANSI/ISO/IEC 17024

Get your Network Security Certification at EC-Council


FAQs

  1. Who uses network protocols?

While an ordinary man may not limit knowledge of network protocols, still all of us participate in establishing network protocols when we use web resources or use the Internet for digital communications. They are not just limited for use by IT and security professionals alone.

  1. What are the primary functions of network protocols?

While there are numerous types of Internet protocols, all types of network protocols have three principal functions:

  • Network communications
  • Security
  • Network management

References:

  1. https://www.comptia.org/content/guides/what-is-a-network-protocol
  2. https://searchnetworking.techtarget.com/definition/protocol

Never Trust, Always Verify: White House to U.S. Agencies

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

The Office of Management and Budget (OMB) released a Federal Zero Trust Strategy to push federal agencies’ networks and systems to zero-trust security architecture. The Cybersecurity and Infrastructure Security Agency (CISA) also released its Cloud Security Technical Reference Architecture (TRA) and Zero Trust Maturity Model to guide the U.S. Government agencies in boosting their cybersecurity posture.

OMB’s zero-trust strategy requires organizations to perform:

  • Consolidating agency identity systems
  • Combatting phishing through strong multifactor authentication
  • Treating internal networks as untrusted and encrypting traffic
  • Moving protections closer to data by strengthening application security

The initiatives from OMB and the CISA are designed to provide government agencies with the roadmap and resources required to implement a zero-trust model. The authorities of OMB and CISA requested feedback from the public on zero-trust strategy drafts and technical guidance to enhance enterprise security across the federal government. Interested civilians can provide their inputs at zerotrust.cyber.gov.  While OMB accepts public comments until September 21, 2021, the CISA’s comment period will run until October 1, 2021.

Improving Nation’s Cybersecurity

All three new proposed strategies are released in support of the Executive Order recently signed by POTUS Biden to improve the nation’s cybersecurity. The Biden administration and tech giants such as Google, Microsoft, Apple, and IBM, have come together to discuss ways to enhance the security of technology and address the rising cyberthreat landscape in the U.S.

“The goal is to provide agencies with guidance on the shared risk model for cloud service adoption, how to build a cloud environment, and how to monitor such an environment through robust cloud security posture management,” the White House said.

Commenting on the latest initiative, Clare Martorana, Federal Chief Information Officer, said, “Never trust, always verify. With today’s zero trust announcement, we are driving home the message to federal agencies that they should not automatically trust anything inside or outside of their perimeters. They must verify anything and everything trying to connect to their systems before granting access. This is an expectation in a modern technology environment, and we look forward to this public comment process to make our strategy even stronger.”

Millions of Bluetooth Devices Affected by BrakTooth Flaws

BrakTooth Flaws

Bluetooth technology (BT) has encountered severe scrutiny due to various design flaws and vulnerabilities. Security experts from the Singapore University of Technology and Design recently revealed a group of security vulnerabilities, tracked as BrakTooth, in the Bluetooth Classic (BR/EDR) protocol, affecting millions of Bluetooth-enabled devices. These devices are manufactured by Intel, Qualcomm, Texas Instruments, Infineon (Cypress), Zhuhai Jieli Technology, and Texas Instruments, and Silicon Labs.

After analyzing 13 BT devices from 11 vendors, the researchers found 16 security vulnerabilities, which, if successfully exploited, could allow a remote hacker to launch multiple attacks, including Denial of Service (DoS), firmware crashes, deadlocking, and  Arbitrary Code Execution (ACE) on vulnerable devices.

“All the vulnerabilities are already reported to the respective vendors, with several vulnerabilities already patched and the rest being in the process of replication and patching. As the BT stack is often shared across many products, many other products are probably affected by BrakTooth. Therefore, we suggest vendors producing BT system-on-chips (SoCs), BT modules, or BT end products to use the BrakTooth proof-of-concept (PoC) code to validate their BT stack implementation,” the researchers said.

Vulnerabilities Discovered

  • Feature Pages Execution (CVE-2021-28139)
  • Truncated SCO Link Request (CVE-2021-34144)
  • Duplicated IOCAP (CVE-2021-28136)
  • Feature Response Flooding (CVE-2021-28135/28155/31717)
  • LMP Auto Rate Overflow (CVE-2021-31609/31612)
  • LMP 2-DH1 Overflow
  • LMP DM1 Overflow (CVE-2021-34150)
  • Truncated LMP Accepted (CVE-2021-31613)
  • Invalid Setup Complete (CVE-2021-31611)
  • Host Connection Flooding (CVE-2021-31785)
  • Same Host Connection (CVE-2021-31786)
  • LMP AU Rand Flooding (CVE-2021-31610/34149/34146/34143)
  • LMP Invalid Max Slot Type (CVE-2021-34145)
  • Max Slot Length Overflow (CVE-2021-34148)
  • Invalid Timing Accuracy (CVE-2021-34147)

Affected Devices

  • Industrial equipment like programmable logic controllers (PLCs)
  • Smartphones
  • Infotainment systems
  • Laptop and desktop systems
  • Audio devices
  • Home entertainment systems
  • BT enabled keyboards and toys

How the Attack Works

Cybercriminals could exploit the BrakTooth flaw by leveraging an ESP32 development kit (ESP-WROVER-KIT) along with a custom (non-compliant) LMP firmware and a computer to run the PoC tool during their attack.

The researchers also detailed the attack scenario in a video.

“All the vulnerabilities can be triggered without any previous pairing or authentication. The impact of our discovered vulnerabilities is categorized into crashes and deadlocks. Crashes generally trigger a fatal assertion, segmentation faults due to a buffer or heap overflow within the SoC firmware. Deadlocks, in contrast, lead the target device to a condition in which no further BT communication is possible,” the researchers added.

3 Ways the Federal Government Is Using Technology to Advance Cybersecurity

Harness Your System, Free Decryptor, federal government, cybersecurity

When it comes to cybersecurity, the federal government is putting out fires every day — and it can be exhausting. Like most organizations, the government has traditionally defended the network perimeter with tools like firewalls and antivirus software. Unfortunately, it has become clear that adversaries have long since broken through those barriers using modern techniques such as social engineering, phishing, drive-by downloads, identity theft and impersonation.

By Todd Helfrich, Vice President of Federal, Attivo Networks

Protecting any enterprise against today’s cybercriminals — let alone nation-state threats — is a challenging task, given the volume, variety, and age of many government systems. With the rise of third-party breaches, the government now needs to ensure its vendors and suppliers can protect their own systems. Attivo Networks works closely with the government to help them implement innovative cybersecurity technology and steers best practices and policy conversations in a more secure direction.

Collaborating with Experts to Better Secure the Government and Its Partners

It is important for cybersecurity organizations to be more than just manufacturers supplying technology to the government. Attivo Networks has built collaborative relationships with government agencies to help deliver stronger, more tailored solutions. This is essential in areas of critical infrastructure, intelligence, defense, and others that have specific needs that can only be addressed by a partner with a thorough understanding of the particular challenges they face and gaps they need to fill.

Information sharing has also become a priority within the government, and the recent executive order on cybersecurity emphasized the need to share threat information. Today’s technology is better than ever at collecting adversary intelligence, especially when an adversary is tricked into interacting with decoy assets while safely cordoned off from the rest of the network. Studying indicators of compromise (IoCs) and the related tactics, techniques, and procedures (TTPs) and sharing that information effectively can help defenders detect and defend against specific attack tactics, even if those tactics have not yet been used against them.

Active cyber defense enables enterprises to curate relevant internal threat intelligence that accelerates persistent hunt operations. Effective cyber threat intelligence sharing means the intelligence shared must be both timely and relevant. Within the government, classified indicators often don’t receive a “tear-line” in a timely fashion or receive the same aggregated data available through open-source and commercial unclassified sources. Improving cyber threat intelligence means collaborating on analysis and applying risk scores and decay windows to IoCs.

With many third-party breaches in the news, trust in third-party partners is increasingly critical for the government. This is increasingly relevant as attackers often breach vendors of widely used technology to infiltrate the software development life cycle, rather than target the government head-on. This happened with SolarWinds, which resulted in a major breach with extensive reach across government and the corporate world. Attivo has worked closely with the government to identify appropriate solutions capable of identifying attackers that have breached perimeter defenses or arrived via third-party compromise, including, and especially, increased identity detection and response capabilities.

Working Closely with Regulatory and Advisory Bodies

Organizations like MITRE and the National Institute of Standards and Technology (NIST) issue cybersecurity guidance for modern enterprises, including the government. It’s created awareness around Active Defense measures, with MITRE releasing MITRE Shield to complement its long-running MITRE ATT&CK framework. MITRE Shield highlights active defense tactics such as deception and concealment technology to trick attackers into interacting with decoy network objects while hiding real assets from view.

MITRE has now taken things one step further with the recent release of MITRE Engage beta, additional guidance centered around denial, deception, and adversary engagement, and they are far from the only ones. NIST has updated special publication 800-160, doubling down on deception capabilities as an essential way to mitigate today’s most pressing threats, and the National Security Agency (NSA) recently released guidance of its own. These initiatives affirm the value of cyber deception technology, lending further credence to the need for stronger active defense tools.

The frameworks provided by organizations like MITRE and NIST can also provide the basis for meaningful government regulations. The Colonial Pipeline hack was an eye-opener, highlighting that not enough focus has been on securing industrial control systems (ICSs) and other large-scale assets. Attivo has spent years improving the technology used to monitor programmable logic controllers (PLCs) to help secure ICS devices and has worked with the government to use that expertise to support policies that create a stronger security baseline for those systems. The White House released a memo last month intended to emphasize the importance of securing ICS assets, bringing them more in line with industry best practices. Whether an organization secures enterprise IT, ICS/SCADA, or cloud infrastructure, active cyber defense helps drive adversary activity to decoy systems and away from production assets. When it comes to critical infrastructure, adequate security measures help limit physical impacts on human safety.

Making Innovation a Priority

Attivo has worked closely with the Department of Defense (DoD) and other government entities over the years, many of which have specific cybersecurity needs and benefit from outside perspectives, expertise, and technology. By providing direct support, Attivo learned about the specific challenges facing each agency while working together to secure their systems better and educate their users. Attivo has conducted defense exercises with DoD to educate its personnel on executing denial and deception techniques while also gaining a stronger understanding of the specific environment being protected. Emulating adversary attacks has highlighted the value of quickly detecting the adversary and extrapolating valuable intelligence supporting ‘defend forward’ operations.

The COVID-19 pandemic also spurred the adoption of cybersecurity technologies to enable a remote workforce within the government and its partners. Cloud adoption significantly increased but has resulted in situations where users have access to cloud applications and resources they do not need, creating vulnerabilities. Problems like overprovisioning, group policies, orphaned credentials, and others have all become major issues. Attivo has worked with these groups to emphasize identity protection, focusing on discovering identities and entitlements and using them within the network and cloud environments. Looking across last year’s cyberattacks, nearly every compromise harnessed a legitimate credential and exploited the openness of Active Directory to accomplish the attacker’s objective. Working with the government to better understand the issues it faces has helped Attivo Networks prioritize innovative new solutions to address these unique problems.

Strong Relationships Benefit All Involved

The government is a sprawling entity, and securing it is a challenge. The need to protect against third-party breaches creates a further challenge, especially given the number of partners and suppliers the government works with across its many departments and agencies. Attivo has found that collaborating directly with the government to advise on specific technology solutions and potential regulatory measures can greatly benefit both sides.

Close partnerships have helped Attivo better understand the government’s specific needs and challenges while allowing the government to better understand the solutions available to it. The government remains a vulnerable target, but it can now take concrete steps to address many of the critical challenges it faces.


About the Author

Todd HelfrichTodd Helfrich, Vice President of Federal at Attivo Networks, has 20+ years of experience on the front lines of cybersecurity and has advanced a wide range of cybersecurity resiliency initiatives across the industry that protect commercial and federal government enterprises. In his current role, he is responsible for all federal government-related activities and the leadership of a team that supports industry mission partners across the government.  His focus is on strategies for deploying active cyber defense capabilities and empowering cyber defenders through adversary management. He advises innovation technology providers and currently supports the AFCEA Cyber Committee, which is a volunteer group of public and private sector information technology and security experts that enable collaboration between government and industry. His work crosses all branches of the federal government and helps to influence government policy, requirements development, and technology adoption.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers Target Microsoft Office Users in a New Zero-Day Attack

CISA vulnerabilities, Zero-Day Attack, zero-day vulnerabilities, Apple

Researchers uncovered active exploitation of a zero-day remote code execution vulnerability in the main HTML component of the now-discontinued Internet Explorer browser. Microsoft warned that unknown hackers are exploiting the vulnerability tracked as CVE-2021-40444 to compromise vulnerable Windows systems by using weaponized Microsoft Office documents.

“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights,” Microsoft said in a security advisory.

ActiveX is a software framework from Microsoft that adapts its earlier Component Object Model and Object Linking and Embedding technologies for content downloaded from a network.

Zero-Day Flaw Discovery

The critical vulnerability CVE-2021-40444 was first discovered by exploit detection service provider EXPMON. The company stated that they found the issue after detecting a “highly sophisticated zero-day attack” targeting Microsoft Office users.

Mitigation

Microsoft stated that systems with active Microsoft Defender Antivirus and Defender for Endpoint (build 1.349.22.0 and above) are protected against the exploits of CVE-2021-40444. “Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protection for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments,” said Microsoft in a statement.

Microsoft also confirmed that it will provide a security patch or an out-of-cycle security update after investigating the incident.

How Microsoft Plans to Protect Trusted Office Docs

Microsoft is also planning to boost the security of the Trusted Office Documents and prevent their misuse in malicious campaigns.

“We are changing the behavior of Office applications to enforce policies that block Active Content (ex. macros, ActiveX, DDE) on Trusted Documents. Previously, Active Content was allowed to run in Trusted Documents even when an IT administrator had set a policy to block it. As part of ongoing Office security hardening, the IT administrator’s choice to block Active Content will now always take precedence over end-user set trusted documents,” Microsoft stated.