Home Blog Page 60

Cyber Incident and Data Breach Management Workflow

Threat Hunting Report, security breach, data breach, data breach management

These days, it’s not a matter of if, but when an organization experiences some kind of data breach. Incidents are increasing in number and severity.  Data breaches have become more expensive to resolve and more challenging to defend against.

See also: How to Ensure Data Management Excellence

The stakes are high for organizations who experience a breach — loss of revenue, lost customers, and a negative impression in the market are just a few of the consequences. That’s why your first step in incident response should start long before anything happens. Being well prepared and having a comprehensive plan in place with optimal workflows, like the basic incident and breach management workflow offered here, will allow your organization to get the job done accurately and efficiently.

To avoid the fallout that organizations face after a cyberattack – which could range from public mistrust and volatile stock positions to regulator penalties and/or large ransom payouts – organizations are best suited to ensure that their breach response and notification processes are ready to kick off a moment’s notice.

The following infographic highlights:

  • The 6-step process to a defensible incident and breach response, and,
  • How technology can orchestrate a strong and defensible breach response process

Cyber Incident and Data Breach Management Workflow

Cyber Incident and Data Breach Management Workflow

Schedule a demo at https://marketing.accessdata.com/l/46432/2021-08-10/8qkk4t

7 in 10 Facility Managers Consider OT Cybersecurity a Major Concern

Credential Abuse Attack, credential harvesting campaign

The rise in connected buildings has exposed operational technology (OT) and industrial control systems (ICS) to various cyberthreats. Improving cybersecurity for active technology systems has become a top priority to facility managers lately.  According to research from Honeywell, 7 in 10 (71%) facility managers consider OT cybersecurity a severe security concern.

The research “Protecting Operational Technology in Facilities from Cyber Threats: Constraints and Realities” revealed that only 44% of companies currently have a cybersecurity solution in place to protect their OT systems from potential threats. Nearly 33% plan to invest in OT cybersecurity products over the next 12 to 18 months.

In general, OT systems monitor, control, and protect processes and operational environments from potential threats. If not secured, connected building equipment like HVAC, building management, and security systems could become entry points for threat actors.

“Cybersecurity conversations often focus only on IT and safeguarding data and assets, but OT cybersecurity is just as critical when you think of the potential effects. Imagine an entire data center team being denied building access or a hospital that can’t properly manage airflow in critical areas. A building’s OT environment should be monitored and maintained as rigorously as an IT system. Still, often the importance of practicing strong cyber and digital hygiene in OT systems is overlooked and underfunded,” said Mirel Sehic, global director cybersecurity, Honeywell Building Technologies.

Key Findings:

  • 27% of facility managers have experienced a security breach in their OT systems in 12 months.
  • Around 66% of respondents view managing OT cybersecurity as one of their most challenging responsibilities.
  • Over 56% of respondents are currently more willing to invest in safety-focused solutions (including OT cybersecurity) than they were before the onset of the pandemic.

The research findings are based on the responses of facility managers across the U.S., Germany, and China in the education, health care, data center, and commercial real estate sectors.

“While the survey findings indicate that facility managers understand the importance of OT cybersecurity, they lack sufficient, consistent investments to protect their buildings and assets fully. The impact of cyber incidents can go beyond financial loss; operational and reputational damage can be equally critical, if not more so. As more building owners understand the potential effect of an OT attack on operations and infrastructure, facility managers will be in a better position to make smart buying decisions and heighten cyber resilience across OT environments,” Sehic added.

Biden Administration and Tech Giants Come Together to Raise Bar on Cybersecurity

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

Mitigating the rising cyberthreat landscape has become a national priority for the Biden Administration. Several government agencies and private tech companies such as Google, Microsoft, Apple, and IBM recently came together at the White House to discuss cybersecurity initiatives to thwart cyberattacks across the U.S.

Security leaders, insurance providers, and non-profit organizations committed to implementing cybersecurity strategies, announced their plans and initiatives in the summit chaired by POTUS.

Cybersecurity Commitments

The summit discussed various possibilities to boost the nation’s cybersecurity. The participants announced their commitments to prevent cyberattacks, individually and in partnership. The initiatives range from executing new industry standards to deploying better security tools and providing cybersecurity skills training. Some of the commitments announced at the summit include:

  • Google to invest $10 billion over the next five years to expand zero-trust programs, help secure the software supply chain, and enhance open-source security. It would also help 100,000 Americans earn industry-recognized digital skills certificates that provide the knowledge that can lead to secure high-paying, high-growth jobs.
  • IBM will train 150,000 people in cybersecurity skills over the next three years and partner with more than 20 Historically Black Colleges & Universities to establish Cybersecurity Leadership Centers to grow a more diverse cyber workforce.
  • Amazon will make available to the public at no charge the security awareness training it offers its employees.
  • Resilience, a cyber insurance provider, would require policyholders to meet a threshold of cybersecurity best practice as a condition of receiving coverage.
  • Apple would establish a new program to drive continuous security improvements throughout the technology supply chain.
  • Code.org will teach cybersecurity concepts to over three million students across 35,000 classrooms over three years, teach a diverse population of students how to stay safe online, and build interest in cybersecurity as a potential career.

Cybersecurity – The Need of the Hour

The cybersecurity discussions come in the wake of multiple high-profile attacks such as  SolarWinds supply chain attacks and ransomware attacks on Colonial Pipeline and food processing giant JBS. The Biden Administration is prioritizing cybersecurity by considering it a national and economic security imperative. On May 12, 2021, Biden issued an Executive Order to modernize Federal Government defenses and enhance technology security. On July 28, he issued a National Security Memorandum establishing voluntary cybersecurity goals for critical infrastructure enterprises.

“The Administration has also engaged with the private sector on the importance of prioritizing cybersecurity as a central part of their efforts to maintain business continuity. And internationally, the Biden Administration has rallied G7 countries to hold accountable nations who harbor ransomware criminals and to update NATO cyber policy for the first time in seven years,” the White House said in a statement.

NortonLifeLock and Avast merger is surprising, yet unsurprising: Allie Mellen

NortonLifeLock and Avast merger

There has been a significant traction in the security industry with growth in the antivirus market.  According to the “Industry Arc Antivirus Market – Forecast (2021 – 2026) report,” the global antivirus market is expected to grow at a CAGR of 20% from 2018-2023. The industry is experiencing some kind of consolidation in the otherwise largely fragmented market. There have been significant collaborations in recent times like Thoma Bravo‘s $12.3 billion takeover of Proofpoint, Broadcom’s $10.7 billion acquisition of Symantec’s enterprise business, and now we have the NortonLifeLock and Avast merger on the anvil.

By Minu Sirsalewala, Editorial Consultant, CISO MAG

Where we see these billion-dollar deals being announced, is the market conducive for their sustenance and growth? Or will they bleed?

Allie Mellen
Allie Mellen, Analyst – Security and Risk, Forrester

In an exclusive interaction with CISO MAG, Allie Mellen, Analyst, Security and Risk, Forrester, discussed the cybersecurity market landscape and how “the NortonLifeLock and Avast merger is surprising, yet unsurprising.”

At Forrester, Mellen supports security and risk professionals, covering security infrastructure and operations to assist clients in building and maturing their threat detection and response strategies. Her coverage includes the people, processes, and tools of the security operations center (SOC); security analysts; security information and event management (SIEM); security user behavior analytics (SUBA); security analytics (SA); security orchestration, automation, and response (SOAR); endpoint detection and response (EDR); extended detection and response (XDR); and SOC metrics. Her research focuses on the current state and evolution of analytics, detection, automation, and response in security.

Consolidations and M&A Drivers

Concerns over cybersecurity are at an all-time high given the recent breaches of Colonial Pipeline, Kaseya, and T-Mobile. These events are shaping public perception over the security preparedness – or lack thereof – of companies’ consumers share their data with. As these concerns get larger, so too does the market for consumer security solutions.

“However, consumers want something simple – generally speaking, they don’t want to have to buy ten different security products from ten different vendors. These consolidations and M&As signal the importance of providing a holistic security solution for consumers,” says Mellen.

NortonLifeLock and Avast Partnership Value

According to Mellen, the deal seems to be betting on the importance of offering a consolidated consumer security portfolio that incorporates identity theft protection, antivirus, and other security tools like VPNs. They seem to be attempting to address the consumer security market more comprehensively, while also expanding their customer base and geographical regions.

Unfavorable Winds of Change

Security and privacy are becoming a larger consumer priority, but this runs in parallel to an increased focus by large consumer brands on improving their built-in security controls, which are direct competitors to companies like NortonLifeLock and Avast. To stay ahead of built-in security controls, companies like NortonLifeLock need to innovate or build out their portfolio.

The consumer antivirus solutions are under deep strain as users turn to built-in operating system security capabilities in lieu of third-party solutions.

“As Microsoft and Apple prioritize native security built into their products, traditional antivirus providers have no choice but to look for new features and popular offerings that may differentiate them. However, this merger is unlikely to stop the bleeding when it comes to loss of customers for traditional antivirus players due to the convenience and credibility of larger brands,” articulated Mellen.

Standalone Consumer Security Players – Challenging Times

Public perception, especially that of the built-in security of large operating systems and computer hardware manufacturers, has changed dramatically in the past 5 to 10 years. When it comes to standalone antimalware, we are past the point where individual consumers must pay a subscription for basic antimalware.

“There are capabilities built natively into the operating system, as my colleague has written about, that can provide beyond basic antimalware protection. A good example of this is Windows Defender, which is built-in to Windows 8, Windows 8.1, and Windows 10,” said Mellen.

There is a small number that still pays subscriptions for basic antimalware protection, but as large brands like Apple and Microsoft prioritize security and privacy, this trend will likely drop off. For other kinds of consumer security, this remains to be seen. However, it is clear that big brands like Apple and Microsoft are heavily prioritizing built-in and free consumer security.

Exploring Avenues

Inevitably, even larger brands must ensure consumers have choices outside of their portfolio when using their products. Mellen opines that partnership possibilities will always exist between these standalone security providers and prominent brands, especially in areas with no competitive overlap.

She adds, “The question is, will it be enough of the consumer market to keep the standalone security product market growing? This question also speaks to the importance for companies like NortonLifeLock to diversify their portfolio. Better to have a variety of offerings, rather than one that may be direct competitors with a partner.”

Avast – Controversial Past

Data breaches and privacy controversies can have a significant impact on consumer trust. Any organization that struggles with a controversy like the Avast data harvesting row, must show transparency in the wake of an incident. Specifically, this means outlining what happened when a breach or privacy event occurs, clearly defining why it happened, and presenting and executing on next steps to ensure it doesn’t happen in the future. The worst thing an organization can do is sweep privacy matters or breaches under the rug, as it will inevitably destroy trust with consumers.

Outlook

This is an instance where things are more complicated than simply consolidating a customer base and receiving double-digit revenue growth. This merger will give the brand a substantial presence in the market and access to a new set of customers interested in standalone consumer security products.

“However, the winds of change are against standalone consumer security brands as consumers look for simple, effective ways to secure their data: using already built-in security from a brand that knows the operating system inside and out.”

On the other hand, if these larger brands fail to build trust and live up to consumer expectations, there may be an opportunity for standalone consumer security products to maintain and expand their foothold.

NortonLifeLock and Avast merger


Minu

About the Author

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

Over 13 Mn Malware Attacks Targeted at Linux Servers in H1 2021: Trend Micro

Linux

The Linux operating system is famous for its flexibility and open-source nature. It also powers many cloud infrastructures. However, the popularity of Linux grew along with its threat landscape. Like other operating systems, Linux systems are not immune to cyberattacks. The latest analysis, “Linux Threat Report 2021” from Trend Micro, revealed that over 13 million malware attacks were targeted at Linux-based cloud environments in the first half of 2021.

Linux Threat Landscape

Today, most of the IoT devices and cloud-based applications run on Linux platforms, making them a primary target for threat actors. According to the report, the top five malware threats affecting Linux servers include coinminers (25%), web shells (20%), ransomware (12%), Trojans (10%), and others (3%). More than 65% of the malware variants were found in systems running end-of-life versions of the Linux platform with unpatched vulnerabilities.

The top four Linux distributions where the top threat types were found include CentOS Linux (51%), CloudLinux Server (31%), Ubuntu Server (10%), and Red Hat Enterprise Linux (3%). Most of the malware detections came from the U.S. (40%), followed by Thailand (19%) and Singapore (14%).

Other Key Findings

  • Over 100,000 unique Linux hosts reported security events, showcasing a concerning amount of criminal activity targeting Linux hosts.
  • In 2020 there were approximately 20,000 vulnerabilities reported. However, only 200 (1%) have publicly known exploits. This gives a clear path forward for security teams of which vulnerabilities should be the patching priority.
  • Detections were found from end-of-life versions of Linux. These unsupported systems no longer receive critical security patches, making them significantly more vulnerable to future exploits and attacks.
  • In July 2021, almost 14 million exposed Linux servers were detected by Censys.io, and Shodan caught nearly 19 million Linux servers with port 22 exposed, leaving plenty of openings for attackers to target.

“It’s safe to say that Linux is here to stay, and as organizations continue to move to Linux-based cloud workloads, malicious actors will follow. We have seen this as a main priority to ensure our customers receive the best security across their workloads, no matter the operating system they choose to run it on,” said Aaron Ansari, vice president of cloud security for Trend Micro.

Australia Passes Surveillance Legislation (Identify and Disrupt) Amendment Bill 2020

Surveillance Legislation (Identify and Disrupt) Amendment Bill

Australia is constantly trying to boost its cybersecurity capabilities to mitigate rising threats of remote access scams and identity thefts. The government recently passed the Surveillance Legislation Amendment (Identify and Disrupt) Bill 2020, allowing the Australian Federal Police (AFP) and the Australian Criminal Intelligence Commission (ACIC) to spy on potential cybercriminals online. The coalition bill provides three exclusive warrants to AFP and ACIC to modify, add, copy, or delete data linked to cybercriminal suspects and even take control of their online accounts.

“The bill introduces account takeover warrants to enable the AFP and ACIC to take over a person’s online account to gather evidence to further a criminal investigation; and make minor amendments to the controlled operations regime to ensure controlled operations can be conducted effectively in the online environment,” the Parliament of Australia stated.

Minister for Home Affairs, Karen Andrews, stated that the new legislation gives more authority to the law enforcement agencies in the country in identifying cybercriminal activities online. “Under our changes, the AFP will have more tools to pursue organized crime gangs to keep drugs off our street and out of our community, and those who commit the most heinous crimes against children,” Andrews said.

The three warrants that give additional powers to the AFP and the ACIC include:

1. Network Activity Warrant – This warrant will enable the AFP and the ACIC to collect intelligence on the most harmful criminal networks operating online, including the dark web, and when using anonymizing technologies.

2. Data Disruption Warrant– This will enable the AFP and the ACIC to disrupt serious criminality online – authorizing the AFP and the ACIC to modify data belonging to individuals suspected of criminal activity to frustrate the commission of serious offenses such as the distribution of child exploitation material.

3. Account Takeover Warrant– This warrant powers the AFP and the ACIC to control a person’s online account to gather evidence about criminal activity, to be used in conjunction with other investigatory powers. Right now, law enforcement agencies rely on a person consenting to the takeover of their account.

All the three warrants will be supervised by the Commonwealth Ombudsman and the Inspector-General of Intelligence and Security to ensure the agency uses them appropriately and reviewed by the Independent National Security Legislation Monitor and the Parliamentary Joint Committee on Intelligence and Security (PJCIS).

How does PCI DSS Prevent Supply Chain Attacks?

supply chain attacks

In today’s evolving digital world, a supply chain attack, in particular, is not a new threat. In fact, 80% of the retail data breach is due to supply chain attacks. Today, a growing number of hackers are adopting sophisticated tools and techniques to attack a company’s Supply Chain Management and wreak havoc in business operations. These attacks can be devastating and may at times have an irreversible impact on the business.  In the online retail business, the supply chain is an essential part of business operations. Most businesses today rely on third-party services that often span a large and diverse network across national and international boundaries. So, having in place a robust cybersecurity measure across this large span of the network is challenging. Especially when cyberattacks are evolving to be sophisticated and highly advanced. This provides attackers an open door to many loopholes and weak points for exploitation.

By Narendra Sahoo, Founder, and Director, VISTA InfoSec

Although organizations are heavily investing in cybersecurity measures, little is done to curb the root cause of the attack which involves evaluating and monitoring the security of Third-Party Service Providers.  Yes, organizations are taking measures to minimize the damage caused by supply chain attacks, but the only way to deal with it is by preventing such attacks and incidents of breach is by building a strong defense. Explaining this in detail, let us understand the risk of a supply chain attack with outsourcing of credit card payment processing and ways to mitigate and manage the risks associated with third parties having access to Cardholder Data (CHD) with compliance to PCI DSS. But before that let us first understand the nuances of a supply chain attack.

What is a Supply Chain Attack?

A supply chain attack, which is also popularly known as a third-party attack, happens when a hacker/attacker infiltrates an organization through a third-party service provider’s systems or networks, and gains unauthorized access to business-critical and sensitive systems and data. This technique of hacking changes the entire dynamics of the attack surface for a business, making cybersecurity measures more complex and challenging. With this, the risks concerning the supply chain attack are higher, especially with the types and sophistication of attacks, and increased oversight from regulators.

However, with an immense number of advanced tools and techniques at their disposal, hackers have become more creative in their attacks and are constantly evolving their techniques to infiltrate into their target’s systems and network. To that, the supply chain has made it easier for hackers to compromise larger business groups and organizations. With detection of supply chain attacks being inherently difficult due to the easy backdoor to software applications that masks the malicious nature of the software, the threats simply go undetected with the traditional security measures.

How does compliance to PCI DSS prevent a Supply Chain Attack?

It is common in the online payment industry for businesses to avail of third-party services for processing credit card payments given the cost and operational efficiencies it offers. Moreover, the convenience that it offers business in terms of cutting the scope of PCI DSS Compliance made the option more viable for them. However, most of these service providers are excluded or not subject to the appropriate levels of due diligence. This opened doors to a high level of risk exposure for organizations availing their services. PCI Council recognized the growing level of risk exposure and so, in its PCI DSS 3.2 iteration highlighted the significance of mitigating and management of the third-party risk. The PCI DSS requirement calls for measures ensuring compliance throughout the data supply chain. Addressing this, the PCI Council outlined a list of requirements that third-party service providers are required to follow to ensure PCI DSS Compliance. The following list of requirements outlined in the PCI DSS 3.2 highlights the emphasis placed by the Council to ensure continuous management and maintenance of security measures for the third-party services availed by organizations who process sensitive cardholder data (CHD).

PCI DSS Requirements

Description

Requirement 10.8 Service providers are required to have in place systems and processes for timely detection and reporting of failures in critical security control systems.

Having a formal process in place is essential to detect issues and alert when there is critical security controls failure. If not, the issue could go undetected for extended periods of time providing an opportunity for attackers to exploit the weak areas and compromise systems and gain access to the sensitive cardholder data environment.

Requirement 12.4 Ensure security policy and procedures clearly define information security responsibilities for all personnel.

Organizations must develop a third-party vendor policy and procedure that clearly outlines the responsibilities of service providers. It should also include the necessary measures to be taken to protect the cardholder data and for ensuring compliance with PCI DSS. After all, anyone having access to sensitive cardholder data must be accountable for its security and be aware of their responsibility. Without clearly defining the roles and responsibilities there can be miscommunication and security lapse in systems, leading to the unsecured implementation of security measures.

Requirement 12.8 Maintain and implement policies and procedures to manage Service Providers with whom the cardholder data is shared, and that could affect the security of the cardholder data environment.

Basically, this requirement of PCI DSS focuses on vendor management for which organizations are required to maintain and implement appropriate policies and procedures for the third-party service providers.

Requirement 12.8.2 Maintain a written agreement that includes an acknowledgment that the service providers are responsible for the security of cardholder data.

This is to define and maintain a clear relationship with the service providers who have access to the sensitive cardholder environment or cardholder data. Having the responsibilities clearly defined will ensure accountability. Besides, ensuring third-party compliance is crucial as they impact the security of the cardholder data environment.

Requirement 12.8.3 Ensure there is an established process for engaging service providers including proper due diligence prior to engagement.

This simply means organizations must thoroughly conduct appropriate due diligence including a risk analysis before establishing any kind of formal relationship with the service provider. The due diligence processes must include reporting practices, breach-notification, and incident response procedures. It should even include details like the PCI DSS responsibilities assigned, measures taken to ensure compliance, and evidence of compliance.

Requirement 12.8.4 Maintain a program to monitor service providers’ PCI DSS compliance status.

Organizations are required to develop and maintain a program to ensure service providers are PCI DSS Compliant and this must be verified at least annually. The service providers the organizations deal with should provide services in a way that is compliant with PCI DSS Standards. This provides an assurance that necessary steps are taken to secure the cardholder data of customers.

Requirement 12.8.5 Maintain information about which PCI DSS requirements are managed by each service provider, and the ones managed by the organization.

This information is critical for vendor management and is based on the agreement with the specific vendor you deal with depending on their service offerings.  This will define responsibilities and give clarity on the PCI DSS requirements for which they have agreed to meet.

Requirement 12.9 Service providers acknowledge in writing to customers that they are responsible for the security of cardholder data the service provider possesses or otherwise stores, processes, or transmits on behalf of the customer, or to the extent that they could impact the security of the customer’s cardholder data environment.

 This requirement works in conjunction with PCI DSS Requirement 12.8 which intends to ensure a level of understanding between the service providers and the customers about their PCI compliance responsibilities. This should be established in a contractual language to have written evidence of the service providers agreeing to provide services in a way that is PCI DSS compliant.

Requirement 12.11 Service providers must perform and review quarterly to confirm personnel is following security policies and operational procedures.

Service providers are required to confirm that they are following the procedures and policies defined as agreed upon for ensuring PCI DSS Compliance. For this, they are required to perform reviews quarterly which should include details of log review, firewall rules set, configuration standards to new systems, response to security alerts, and change management process in place. This is to ensure the policies and procedures are being followed diligently.

 

PCI DSS mandates the inclusion of service providers in the scope who provide payment-related services or provide services that can impact the security of the organization under consideration. Many times, it is enticing for organizations to take the easy way out and exclude service providers under the guise of “not relevant”. However, we strongly advise organizations to be safe than to be sorry by not taking shortcuts.

Conclusion

Given that 80% of all data breaches today involve a supply chain attack with stolen credentials and unauthorized access through third-party service providers, there is an increased need for organizations to focus on third-party vendor risk management. Availing third-party services from vendors who may have access to information systems, networks, and cardholder data will need to have a certain level of security established to protect the sensitive cardholder data environment. Organizations need to build a sense of trust and ensure that these third-party vendors/service providers take security seriously and accordingly implement necessary measures to prevent attacks and incidents of a breach. That said, performing cybersecurity assessments and validations is a great way to build trust and ensure compliance to industry best security standards across the supply chain. While there are several cybersecurity best practices that businesses can follow to combat the supply chain attack, PCI DSS Compliance is one-way organizations can enhance their Data Security Standard and prevent such attacks. PCI DSS Standards are industry best practices and requirements that involve a robust security practice and rigorous evaluation process that enhances the due diligence expected in the risk assessment of organizations and their third-party service providers.


About the Author

Narendra SahooNarendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the U.S., Singapore and India. Mr. Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, and Compliance services. VISTA InfoSec specializes in Information Security audit, consulting, and certification services which include GDPR, HIPAA, CCPA, NESA, MAS-TRM, PCI DSS Compliance and Audit, PCI PIN, SOC2 Compliance and Audit, PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry. VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Top 5 Internet of Things (IoT) Hacking Tools Explained

IoT Hacking Tools

Internet of Things (IoT) devices raise critical security concerns for ethical hackers as these devices are easy to hack with IoT hacking tools.

More than 70% of IoT devices are soft targets for hackers because of a lack of security measures. The data from these devices are helpful for information gathering and analytical purposes.

This article explains the various IoT hacking tools and how ethical hackers use them.

What Is IoT?

IoT is a network of internet-connected things or objects that use embedded sensors or software applications to collect and exchange data in real-time. IoT includes various devices or objects like home security systems, cameras, refrigerators, etc., that can be connected via the Internet. There is a substantial risk of data being stolen or exploited because of the massive volume of data transmitted over the Internet.

This article highlights some of the popular IoT hacking tools used to detect system vulnerabilities and their use in ethical hacking. But let’s understand what ethical hacking is first.

What is Ethical Hacking?

Ethical hacking is also referred to as penetration testing. It’s an authorized intrusion into systems or networks to identify potential threats and data breaches. White hat hackers, also called ethical hackers, must have various skillsets to hack these devices and look for system threats. While there are many facets of ethical hacking, IoT hack tools can help ease the work of ethical hackers. They can apply these tools to mitigate system threats.

If you want to pursue a career in cybersecurity, you should understand all devices connected to the network, including IoT devices.

Let’s understand the different IoT hacking tools available.

What Are IoT Hacking Tools?

IoT hacking tools entail a wide range of activities, including gathering data on payloads, suspicious behavior, etc.

IoT hacking tools are software or programs that help in exploiting computer security or networks. These tools can identify security patches in the networks, servers, systems, and applications.

We will discuss some examples of IoT tools for hacking later in this article.

What is the Use of IoT Hacking?

Ethical hacking safeguards an organization’s digital assets from malicious malware cyberattacks. Given that a substantial portion of the workforce is embracing a remote work model, one cannot ignore the relevance of cybersecurity. Cyberattacks are rising with the increasing reliance on cloud-based infrastructure and the development of IoT technology. The crux of a company’s security strategy is ethical hacking. IoT tools for hacking aid in the detection of security issues as well as the prevention of data theft.

The Top 5 Tools Used for Testing IoT Systems

IoT hacking tools simplify the tasks of all ethical hackers and save their time. Here, we discuss the top 5 hacking tools.

1.Wireshark

Wireshark is one of the most reliable network packets sniffing tools. In short, it’s an application that captures and analyzes network traffic in real-time. A packet is a unit of data that travels over the digital network. The user can look for individual data packets and study how they travel across their network by searching and filtering for them.

This network analysis tool is an open-source program that is critical to the foundation of security software. Wireshark is a real-time network diagnostic tool used by administrators and IT (Information Technology) security experts. Also, professional penetration testers use Wireshark to gain insights into the target network.

Benefits of Wireshark Tool:

  • Can run on different operating systems.
  • Detects traffic issues you have sent and received.
  • It can decode data shared by someone else.

2. Nmap

Network Mapper (Nmap) is a popular open-source scanning tool for network discovery. Nmap is a free tool that network administrators use to discover available hosts, discover open ports, and detect security flaws. It’s an easy-to-use tool and can operate on several operating systems.

Nmap is a widely used tool by pen testers, and it can scan a single host for 1,000 ports.

Ethical hackers can utilize Nmap to target computers using Nmap scripts during scanning for vulnerabilities in the system.

Benefits of Nmap:

  • Can help identify which hosts are connected to the network.
  • Nmap scripting engine facilitates interaction with the target host.
  • Easy to discover potential threats in the network.
  • Can audit the network for locating new servers.

3. Fiddler

A Fiddler is a powerful tracing tool for web traffic that works on any browser or platform. Ethical hackers or security specialists use Fiddler to perform web penetration tests. It has many features to enable the phases of penetration testing. This tool also enables security assessments of web applications.

It serves as a proxy setting as well as a debugging tool that logs in data transmitted between the device and the Internet.

With the help of this tool, ethical hackers can monitor web traffic and make modifications before the browser receives the request.

Benefits of Fiddler: 

  • Compatible with every HTTP client.
  • Convenient for testing and analyzing websites.

4. Metasploit

Metasploit is a popular security tool that enables penetration testing. It helps in detecting security patches, to discover potential vulnerabilities, and mitigate them. It is an open-source framework that is compatible with most operating systems. Ethical hackers use this framework to test vulnerabilities in the network and access the system remotely to locate threats.

Penetration testers can create custom codes and use them to identify system flaws. Once they identify and report the threats, the bugs are fixed ranked on the priority. Metasploit eases the job of pen testers by automating their tasks compared to manual exploitation tools and techniques.

Benefits of Metasploit:

  • Compatible with most operating systems.
  • Free and easy-to-use.
  • Easy to perform extensive network pen tests.

5. Maltego

Maltego is a powerful data mining application. It gathers data and connects it to investigative tasks in real-time for open-source intelligence and forensics. It is crucial for all security-related activities.

This comprehensive application enables easy information gathering about domains, DNS, websites, people, search engines, IP addresses, etc. This process makes the task of penetration testers or ethical hackers convenient in analyzing relationships between the data. Pen testers can utilize this valuable tool during online investigations and determining the test’s footprints.

 Benefits of Maltego:

  • Presents information in an easy-to-read format.
  • Allows you to extract information from various sources on the web.

Become a Certified Ethical Hacker (C|EH) with EC-Council

Ethical hacking tools help mitigate the potential risks and system vulnerabilities for an organization. IoT hacking tools help developers and security specialists to enable and automate tasks. These ethical hacking tools come in handy to identify network or system flaws and prevent company data from being stolen or damaged.

To hack these devices, security experts need to have a sound knowledge of hardware, operating systems, programming languages, attack vectors, etc., along with an understanding of using hacking tools for IoT devices. The use of these tools in ethical hacking helps automate the tasks of pen testers to identify system flaws and resolve them.

You can know more about the functions of safety tools that enable ethical hacking by enrolling in a suitable course. You can learn how to identify, remedy, and monitor potential attack vectors in ethical hacking. Further, participants also learn how ethical hackers use IoT tools for hacking wireless networks and devices. If you are interested to know more about ethical hacking’s career prospects and roles, join EC-Council’s Certified Ethical Hacker Course.

The training modules offer in-depth knowledge on hacking wireless networks, mobile hacking platforms, IoT hacking, and hacking web applications from the most experienced ethical hacking professionals globally. The Certified Ethical Hacker program gives a detailed insight into various ethical hacking phases, attack vectors, modern malware analysis, etc.

CEH prepares participants to face real-world challenges faced by ethical hackers through a comprehensive training module.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs (Frequently Asked Questions)

  • What is IoT?

IoT (Internet of Things) is a network of internet-connected things or objects that use embedded sensors or software applications to collect and exchange data in real time.

  • Is it possible to hack IoT devices?

Yes, it is possible to hack IoT devices. Hackers can exploit the weak links in IoT devices to create havoc in the infrastructure. Planting malware, spamming, and phishing are some of the techniques used by malicious hackers to infiltrate the devices.


References:

  1. https://www.oracle.com/in/internet-of-things/what-is-iot/
  2. https://content.techgig.com/5-internet-of-things-hacking-tools-for-experts/articleshow/82943035.cms
  3. https://hackertarget.com/maltego-open-source-intelligence-gathering/
  4. https://www.hackingtools.in/free-download-maltego/
  5. https://www.infognana.com/need-know-fiddler-web-debugger-tool/

Watch Out for These 4 Emerging Ransomware Groups

Ransomware gangs

The recent surge in ransomware attacks is an indication that threat actors have become bolder, more sophisticated and equipped with advanced extortion schemes. In their regular ransomware hunting operations, Palo Alto Networks Unit 42 threat intelligence team discovered four upcoming ransomware gangs targeting organizations’ critical digital infrastructure.

“We monitor the activity of existing groups, search for dark web leak sites and fresh onion sites, identify up-and-coming players and study tactics, techniques and procedures. During our operations, we have observed four emerging ransomware groups that are currently affecting organizations and show signs of having the potential to become more prevalent in the future,” Palo Alto said.

The Four Emerging Ransomware Groups

1. AvosLocker – AvosLocker entered the cybercrime scene in June 2021, providing ransomware as a service (RaaS) and aiming at recruiting new affiliates to perform malicious activities. The AvosLocker ransomware also runs an extortion site, which claims to have targeted six organizations across the U.S., Spain, Lebanon, the U.K., the U.A.E., and Belgium. The ransom demand of this group ranges from $50,000 to $75,000.

2. Hive – Active since June 2021, this double-extortion ransomware has impacted 28 organizations across Europe and the U.S. Hive

3. HelloKitty – First spotted in early 2020, the HelloKitty ransomware group mainly targets Windows systems. Researchers found HelloKitty’s Linux variant in July 2021, targeting VMware’s ESXi hypervisor, used in cloud and on-premises data centers. The group impacted five organizations in Australia, Germany, Italy, the Netherlands, and the U.S. The highest ransom demand from this group was $10 million and has received $1.48 million ransom so far.

4. LockBit 2.0 – LockBit 2.0 group, also known as the ABCD ransomware group, has been involved in multiple extortion schemes lately. LockBit 2.0 affected over 52 victims across the U.S., Mexico, Belgium, Argentina, Malaysia, Australia, Brazil, Switzerland, Germany, Italy, Austria, Romania, and the U.K. The gang operates as a ransomware-as-a-service (RaaS) model appointing affiliates and company insiders to carry out intrusion activities. Recently, the group targeted the global IT consultancy giant Accenture and compromised some of its critical networks. Attackers reportedly compromised servers that held over 6TB of information and demanded a $50 million ransom in exchange for the decryption key.

“With major ransomware groups such as REvil and Darkside lying low or rebranding to evade law enforcement heat and media attention, new groups will emerge to replace the ones that are no longer actively targeting victims. While LockBit and HelloKitty have been previously active, their recent evolution makes them a good example of how old groups can re-emerge and remain persistent threats. Unit 42 will continue to monitor these ransomware families – and new ones that may emerge in the future,” Palo Alto added.

It’s high time governments and organizations collectively disrupt these new ransomware groups before they cause damage to nations’ critical digital assets.

Misconfigured Microsoft Power Apps Inadvertently Exposed 38 Mn Sensitive Records

Microsoft Power Apps

A configuration issue in Microsoft Power Apps resulted in a massive data breach, exposing the sensitive information of millions of users. An analysis from information security firm UpGuard revealed that over 38 million records from 47 different government and private entities that use Microsoft Power Apps portals were accidentally left exposed online. The incident represents the severe risks posed by third-party data breaches.

What is Microsoft Power Apps?

Microsoft Power Apps is a suite of cloud-hosted applications and services that allow businesses to develop custom apps as per their business needs. Apps built using Power Apps help companies to transform their manual business operations into digital and automated processes. Power Apps enable OData (Open Data Protocol) APIs to retrieve data from Power Apps.

A New Vector of Data Leak

As per UpGuard, Power Apps’ product documentation mentions the conditions under which OData APIs can be made accessible to the public and its marketing page lists “the ability to access data either anonymously or through commercial authentication.”

The exposed information includes names, email addresses, other personal data for COVID-19 contact tracing, social security numbers, vaccination appointments, and employee IDs. Entities and government bodies that suffered in the security incident include Indiana, Maryland, New York City, Ford, J.B. Hunt, Microsoft, and American Airlines.

“First, we identified the addresses of Power Apps portals. Power Apps portals are assigned a subdomain of the site ‘powerappsportals.com,’ so using common subdomain enumeration techniques generated a list of customer portals. We also discovered two other primary domains used for similar Microsoft products with the same OData configuration options: powerappsportals.us, which appears to be for U.S. governmental use, and microsoftcrmportals.com, which is for a deprecated version of the product line,” UpGuard said.

Microsoft’s Response

Microsoft is notifying the affected entities and cloud customers about the security incident. The tech giant also released a tool – Portal Checker – for checking Power Apps portals and initiated changes to the product for better data security.

“More importantly, newly created Power Apps portals will have table permissions enabled by default. Tables configurations can still be changed to allow for anonymous access but defaulting to permissions enabled will greatly reduce the risk of future misconfiguration,” Microsoft said.

What Experts Say…

Speaking exclusively with CISO MAG, Ilia Sotnikov, VP of User Experience & Security Strategist at Netwrix, said, “This is a great example of how UI design decisions can have an impact on the decisions users make. The anonymous access enabled in Power Apps results from two settings in different tabs in a configuration dialog box. If you enable one and skip the other, you allow everyone on the internet to access your table contents. Vendors should invest in user experience (UX) research and usability testing to minimize the risk of such issues for their customers. This news should hopefully lead to both vendors and companies think more about the balance between time to market and security of their solutions.”