Home Blog Page 62

Japan-based Liquid Crypto Exchange Hacked; Nearly $100Mn Stolen

Liquid Exchange Hack

Japanese cryptocurrency exchange Liquid admitted that it is a victim of a crypto heist in which unknown hackers accessed digital currency from its digital wallets. Hackers reportedly transferred the compromised cryptocurrency into different wallets. Liquid stated that it’s investigating the incident.

While Liquid did not reveal the number of cryptocurrencies stolen, an analysis from Elliptic, a blockchain analytics firm, claimed that threat actors make off over £73 million    (around $97 million) worth of cryptocurrency.

Elliptic stated that attackers pilfered digital coins in different forms such as Ether ($32.5 million), XRP ($12.9 million), Bitcoin ($4.8 million), Tron ($200K), Stablecoins ($9.2 million), and other Tokens ($37.4 million). To avoid detection, they further converted the stolen Ethereum tokens into Ether using decentralized exchanges like Uniswap and SushiSwap.

“Elliptic has added the addresses associated with the thief to our system, ensuring that our clients will be alerted if they receive any of these funds. Our investigators are also aiding Liquid with tracking the stolen funds,” Elliptic said.

Cryptocurrency Vs. Cyberattacks

The Liquid crypto heist report comes days after an unknown hacker named Mr. White Hat stole approximately $600 million in Bitcoins from the Poly Network platform and took control of the user assets. However, the hacker returned the stolen tokens to the company in less than 48 hours after the hacking incident.

Security experts opine that the rise of cryptocurrency value indirectly resulted in many cyberattacks and ransom demands. A survey from Barracuda revealed that a staggering 192% rise in cryptocurrency-related cyberattacks had been registered after the Bitcoin surge in October 2020. The volume of cryptocurrency-related attacks was associated with the rapidly rising price of Bitcoin. Read More Here

CISA Release Guidelines to Prevent Ransomware Attacks

CISA, cybersecurity, cybersecurity technologies

Cyber intrusions are inevitable, and evolving ransomware variants and double-extortion techniques make it even more difficult for organizations to secure their critical digital infrastructure. However, practicing strong security practices will help organizations against ransomware and exfiltration attempts.

With an aim to assist public and private organizations in addressing security breaches stemming from ransomware attacks, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently released a security fact sheet to safeguard critical corporate data from various exfiltration attempts.

The fact sheet helps individuals and organizations understand the severity of the ransomware threat landscape and how to defend against it. CISA highly recommended businesses to adopt the guidelines, which include:

  • Maintaining offline, encrypted backups of data and regularly testing backups
  • Creating, maintaining, and exercising a basic cyber incident response plan, resiliency plan, and associated communications plan
  • Mitigating internet-facing vulnerabilities and misconfigurations to reduce the risk of hackers exploiting this attack surface
  • Employing best practices for the use of Remote Desktop Protocol (RDP) and other remote desktop services
  • Conducting regular vulnerability scanning to identify and address vulnerabilities, especially those on internet-facing devices
  • Updating software, including operating systems, applications, and firmware, regularly
  • Disabling or blocking inbound and outbound Server Message Block (SMB) Protocol and remove or disable outdated versions of SMB
  • Reducing the risk of phishing emails from reaching end users by enabling strong spam filters and implementing a cybersecurity user awareness and training program

Ransomware Emergency

The security recommendations from the federal agency come after multiple ransomware and extortion attacks were reported on critical business sectors like the meat-processing giant JBS and the U.S. Colonial Pipeline. Ransomware cartels continue to target various critical infrastructures across the globe with new ransomware variants.

“All organizations are at risk of falling victim to a ransomware incident and are responsible for protecting sensitive and personal data stored on their systems. This fact sheet provides information for all government and private sector organizations, including critical infrastructure organizations, on preventing and responding to ransomware-caused data breaches,” CISA said.

Why Skills Gap is an Opportunity for a New Approach to Building Strong Cybersecurity Teams

security, teams, skills

The cybersecurity skills gap could hardly have come at a worse time. According to a study by the Centre for Strategic and International Studies (CSIS) focusing on IT decision-makers across eight major countries, 82% of employers have a shortage of employees with cybersecurity skills. Similarly, the 2019/2020 Official Annual Cybersecurity Jobs Report reported a 350% growth in open cybersecurity positions between 2013 and 2021.

By Russ Kirby, CISO, ForgeRock

Meanwhile, the threat posed by malicious actors is also growing and evolving. The head of the UK’s National Cybersecurity Centre warned in June that the danger posed by ransomware hackers to businesses and society now outranks the threat of cyberattack by hostile states. This echoes findings in ForgeRock’s own recent research, which found that UK ransomware attacks increased across all sectors in 2020, with the financial services sector being particularly badly hit, with a 471% increase in attack volume.

This confluence undoubtedly poses challenges: how can businesses build a strong – and crucially adaptable – cybersecurity team amid an acute skills shortage? I think a better perspective is to view it as an opportunity to take a new approach to hiring within the cybersecurity sphere, focusing on soft skills and personality traits rather than technical skills and experience, as a route to long-term resilience.

Using the Interview to Get Under the Hood

What does that mean in practice? The first stage of the process is usually reading CVs, but, looking through this lens, CVs aren’t that helpful. They tell you where someone studied and what experience they have, not who they are and how they operate.

So, I recommend using interviews to get a sense of who a candidate really is. Don’t treat the interview as a technical assessment. Instead, ask questions that tell you about the candidate’s personality type and their communication style. I like to go off-topic in interviews so I’m seeing the person rather than the practiced and polished professional. I ask questions like “If you won the EuroMillions, what would you do with the money?”

These kinds of questions might sound trivial but they help answer perhaps the most important question of all: how would this candidate work and interact with the rest of my team and the wider business? In my view, having a well-functioning team who works effectively together is far more important in the long-term in creating cybersecurity resilience than any single technical skill.

It’s not just a question of employees getting on with each other. Modern cybersecurity increasingly means building a culture across the business in which every stakeholder prioritizes data security and feels empowered to act. If you hire a team who are technically gifted but introverted, you’re going to struggle to engender that approach very meaningfully. Personality matters.

Soft Skills Have Hard Benefits

The interview can also be a good moment to identify those candidates who have the other most important attribute in my alternative to traditional skills-based hiring: solutions-focused adaptability.

It’s almost a cliche to say that technology is changing all the time, but it’s true. When I started my career, the skills we needed to do our jobs were very different from those needed now – and in five- or ten years’ time they’ll be different again. If you hire inflexible candidates who have the single piece of experience you think you need today, you’re not building resilience for tomorrow.

Core knowledge of cybersecurity is of course necessary but don’t be dazzled by CV unicorns over the promise of a candidate who demonstrates open-mindedness and the ability to apply their knowledge to problems in a proactive and inquisitive way. That kind of professional will take you away from having ad-hoc technical skills you need to fill and towards a team who can mold their work to fulfill any emerging need.

Problems and Pitfalls

Of course, this all sounds perhaps more straightforward than it is in reality. There are a number of common stumbling blocks. Some are common to the more ‘traditional’ approach to cybersecurity hiring. For example, inflated expectations on the part of junior candidates. Some unscrupulous recruiters feed ambitious young professionals’ fantasies about astronomical salaries and starting on day one in senior positions of responsibility.

My antidote is total transparency, from the very beginning of the process to the end. I include salary ranges in job descriptions and I’m always happy to discuss them in interviews. Candidates’ expectations might be warped by geographical disparities too. It’s not uncommon for a junior role in San Francisco to pay more than a senior position in the UK, but that’s a reflection of differing local economies and living costs – not a golden ticket.

A Roadmap to Success

As far as expectations about responsibilities and progression go, the best thing you can do is set out a roadmap for the candidate’s professional development over a number of years. Yes, they’ll start in junior position X but with Y years’ experience doing A, B and C tasks, they can expect to be in position Z.

Turning this plan into reality will require time and effort. You’ll need to arrange for them to shadow more senior colleagues in other functions and to build up experience across a range of skill areas. But, if you’re hiring adaptable and proactive candidates, the team member you’ll end up with at the end of the process will be stronger professionally and the team as a whole will operate more smoothly and effectively.

Conclusion

Some hiring managers may be reluctant to shift their focus from technical experience to soft skills and character traits. In normal circumstances, they’d be free to do so. But with those very technical skills in such short supply – and the need for well-oiled cybersecurity teams to be able to switch up and adapt to new threats – the case for a new approach is growing. Adjusting hiring practices now will help address the cyber skills shortage in the near term and create a more adaptable team over the long run.


About the Author

Russ KirbyRuss Kirby has more than 15 years of experience in security and compliance for very large enterprise organizations as well as startups. Based in the UK, he is in charge of ForgeRock’s comprehensive security strategy that encompasses managing information technology, global risk and compliance and security operations. In his most recent role, Kirby served as CISO at CreditSafe, a global provider of company business intelligence. Before CreditSafe, he was at Hewlett Packard Enterprise Services in a variety of global security roles including head of payment card security strategy and global head of information security.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Iranian APT Group “Siamesekitten” Targets Israeli Firms in a Cyberespionage Campaign

Siamesekitten threat group

Security researchers uncovered a new cyberespionage campaign by Iranian hackers targeting IT and telecom companies in Israel with supply-chain attacks. Tracked as Siamesekitten (also known as Lyceum or Hexane), the Iranian APT group imitated HR personnel to lure unwitting users with fake job offers.

According to research from cybersecurity firm ClearSky, threat actors are specifically targeting IT professionals to pilfer their credentials and then leverage that to break into the company’s network systems. It is found that attackers are diverting the victims to a fake website hosted on the impersonating server. The website presents two phishing files – an Excel file that deploys the malicious macro and an executable file that delivers the backdoor onto the targeted device. The downloaded malware will then connect the compromised machine and the hacker-operated C&C server, eventually deploying the RAT.

Old Group New Malware

Since 2018, the Siamesekitten group has mainly targeted organizations in oil, gas, and telecom industries across Africa and Middle Eastern countries. ClearSky stated that it detected two Siamesekitten attacks in May and July 2021 with a new malware variant – Shark.

Siamesekitten Attack Sequence

ClearSky researchers also detailed how the Siamesekitten group initiates its attack vector. This includes:

  • Directing the victim to the phishing website that impersonates the targeted organization.
  • Creating lure files compatible with the impersonated organization.
  • Setting up a fraudulent profile on LinkedIn, impersonating the mentioned HR department employee.
  • Contacting potential victims with an alluring job offer, detailing a position in the impersonated organization
  • The DanBot RAT is downloaded to the infected system.
  • The group gathers data through the infected machine, conducts espionage, and attempts to spread within the network.

“This campaign is similar to the North Korean ‘job seekers’ campaign, employing what has become a widely used attack vector in recent years – impersonation. The group’s main goal is to conduct espionage and utilize the infected network to access their clients’ networks. As with other groups, it is possible that espionage and intelligence gathering are the first steps toward executing impersonation attacks targeting ransomware or wiper malware,” ClearSky said.

Do Phishing Attacks Cost More Than Ransomware?

Phishing Kits, Cost of Phishing Attacks

With increased internet usage during the new normal of remote working, phishing attacks continue to challenge business security defenses. Cyberthugs often distribute malicious codes via various kinds of phishing baits, causing severe consequences to organizations’ critical digital infrastructure. A joint study from Proofpoint and Ponemon Institute revealed that the financial damages from phishing attacks have skyrocketed amid distributed work environments. The 2021 Cost of Phishing Study found that phishing attacks cost organizations nearly $14.8 million (over $1,500 per employee) annually, up from $3.8 million in 2015.

Cost of Phishing is more than Ransom  

In addition to financial damages, phishing attacks cause multiple harms to organizations. Fixing compromised systems and performing forensic investigations consume a lot of time and planning. Loss of productivity is one of the expensive consequences. The study revealed that an average-sized U.S. organization wasted around 63,343 hours every year due to phishing attacks.

“When people learn that an organization paid millions to resolve a ransomware issue, they assume that fixing it cost the company just the ransom. We found that ransoms alone account for less than 20% of the cost of a ransomware attack. Because phishing attacks increase the likelihood of a data breach and business disruption, most of the costs incurred by companies come from lost productivity and remediation of the issue rather than the actual ransom paid to the attackers,” said Larry Ponemon, Chairman and Founder of Ponemon Institute.

Other Key Findings

  • On average, security awareness training reduces phishing expenses by more than 50%.
  • Costs for resolving malware infections have more than doubled since 2015. The average price of fixing malware attacks is $807,506 in 2021, increasing to $338,098 in 2015.
  • The average cost to contain phishing-based credential compromises increased from $381,920 in 2015 to $692,531 in 2021.
  • Business Email Compromise (BEC) attacks cost nearly $6 million annually for a large organization.
  • Ransomware annually costs large organizations $5.66 million. Of that, $790,000 accounts for the paid ransoms themselves.

“Until organizations deploy a people-centric approach to cybersecurity that includes security awareness training and integrated threat protection to stop and remediate threats, phishing attacks will continue. Because threat actors now target employees instead of networks, credential compromise has exploded in recent years, leaving the door wide-open for much more devastating attacks like BEC and ransomware,” said Ryan Kalember, executive vice president of cybersecurity strategy Proofpoint.

Different Types of Ethical Hackers: White, Black, and Grey Hats Explained

types of ethical hackers

There are several types of ethical hackers depending on the hacker’s intent and goal. This article highlights the concepts of hacking and the different types of ethical hackers. But before that, let’s learn what ethical hacking is to understand its categories.

Hacking vs. Ethical Hacking 

Hacking is often perceived as an illegal or malicious cyber activity performed by cyberterrorists. But it may not always be the case.

Hacking can be lawful or unlawful. 

Hacking is generally considered an unlawful or illegal activity. It attempts to exploit a computer or network to steal data, corrupt files, breach security or compromise data integrity.

But hacking can also be done with good intentions to find security flaws in applications, networks, or systems. And this is a legitimate or lawful intrusion.

The lawful/legitimate intrusion to acquire access to a system, application, or network for this purpose is defined as Ethical Hacking. The goal is to find potential vulnerabilities or cyber threats. Many organizations or companies hire ethical hackers to secure their networks from potential threats and breaches by malicious hackers. Cybersecurity professionals can opt for a Certified Ethical Hacker (CEH) career to gain the skills required in modern malware analysis.

So how did the words “hacker” and “hacking” come into existence? Interestingly, a hacker is someone who studies systems with a curiosity to find out how they work – perhaps with the intention of making improvements or just to manipulate the system for fun. In the 1980s, hackers studied how phone networks and analog modems worked – and manipulated these networks just to have fun and to make free phone calls from a phone booth! Over the years, the words “hacker” and “hacking” got a negative connotation by the media. So, remember, a hacker is not necessarily a bad person.

Types of Hackers Around the Globe 

People interested in the cybersecurity domain need to know of the three significant hats – white, black, and grey – to understand the types of ethical hackers.

1. Black Hat Hackers (the bad guys)

Who is a Black Hat Hacker? They are experienced hackers who break into a system without authorization. They exploit a system’s security with malicious intent or for financial gains. Black hat hackers usually work with threat groups or organized crime groups.

They are also known as crackers. Besides, they may also infect the system with malware to steal personal data, credit card information, corrupt files, and disrupt the security network.

2. White Hat Hackers (Ethical Hackers)

Who is a White Hat Hacker? In comparison to black hats, White Hat Hackers are considered good Samaritans who work for enterprises to improve network and system security. They may also aid law enforcement authorities in investigations for cybercrimes. Also known as ethical hackers, they have the skill set needed to test security systems for potential risks before malicious hackers do.

Black hat hacker vs. white hat hacker – Understanding the difference. The difference lies in their intent and objectives. Black hats plant malware to intrude on a system or network with malicious intent. They manipulate users through various hacking techniques to steal data or launch spyware attacks. On the other hand, a white hacker knows how to use the ethical hacking tools required for modern malware detection.

Ethical hackers secure a company’s information and security networks and hunt for backdoors legally. They identify and report the weak links or possible threats in the security system to prevent cyber threats.

3. Grey Hat Hackers

Who is a Grey Hat Hacker? A grey hat hacker performs similar actions as both white hats and black hats. They look for threats and weaknesses in security networks but often without malicious intent. They sometimes need to work incognito and break the law to gain unauthorized access to systems to aid in the investigation – but never with malicious intentions. So, they may sometimes need to wear their “black” hats. Hence the term “grey hat” hacker.

Like white hat hackers, grey hat hackers detect weak links and notify the organization or administrator of potential vulnerabilities in the system in exchange for a small fee.

They also hack into systems to report any flaws or vulnerabilities to law enforcement or intelligence organizations. So, grey hats fall somewhere between white hats and black hats.

Apart from these, several other ethical hacker types like the red hat hackers hunt for black hats to lower the risks of threats. Blue hat hackers have two definitions in cybersecurity; one is that of malicious hackers who launch revenge attacks. The second one defines blue hat hackers as security experts invited by organizations to test new systems and applications and fix weak links.  Heard of the Purple Hat hacker? Yes, they exist! Purple hats test their hacking skills by hacking their own computers.

But all these types of hackers use specialized hacking tools.

Common Hacking Tools

Hackers often use several techniques to achieve their purpose. In order to understand the risks and think like the black hats, ethical hackers must be aware of the popular tools and techniques they use. Some of the common hacking tools include:

1. Rootkits

A rootkit is software that allows cybercriminals to gain access to your computer, and you may not even know it. Hackers gain remote access by either stealing your passwords or infecting your system through phishing attacks. The original purpose of rootkits was to detect and rectify software flaws. However, hackers use this software or application for stealing important data by gaining unauthorized access to an operating system. Rootkits work at the operating system level and can access most of your computer’s functions and take complete control.

For instance, if a rootkit is planted on your smartphone, hackers can remotely switch on your phone camera or voice recorder and then upload the video/voice recording to their server. And you wouldn’t even realize that your conversations are being recorded!

2. Keyloggers

Keyloggers are malware or spyware that monitors or records the sensitive information you type on your keyboard. While most of us may think that entering information on the keyboard is safe from hackers, a keylogger attack can prove otherwise. It considers or records every keystroke. The recorded log file is subsequently saved, containing information such as usernames, website visit details, screenshots, passwords, phone numbers, OTPs, login details, credit card numbers, opened programs, and everything you type on the keyboard.

3. Vulnerability Scanner

A vulnerability scanner is an automated program or software to identify potential security flaws or weaknesses by monitoring networks and applications. With the rise in cyberattacks, a vulnerability scanner is an effective IT strategy to patch weak security links.

This tool also tries to identify operational characteristics such as the operating system and software installed on each asset.

A vulnerability scanner categorizes and detects numerous system flaws in networks, computers, and communication systems, among other things.

Common Hacking Techniques 

1. SQL Injection Attack

The Structured Query Language is a query language that exploits and extracts information from a database with the help of SQL commands.

This type of attack uses a website interface to hack users, passwords, and other sensitive information.

SQL injection attacks are common in poorly designed applications and websites. Since they contain vulnerable user-input fields (such as search and login pages, product and support request forms, comments area, and so on) that hackers can easily hack by changing the scripts.

SQL injection attack is a severe threat and one of the major attack vectors that hackers use.  It can easily infect or exploit any website that uses a SQL-based database.

2. Distributed Denial-of-Service (DDoS)

DDoS is a disruptive cyberattack that floods the network by distorting normal traffic entering a server. It inflicts intended traffic congestion to the server and is a dangerous attempt to overwhelm the network. Computers, IoT (Internet of Things) devices, mobile phones, and other devices that are easily connected to the network are vulnerable to DDoS. In fact, hacked devices can be manipulated to take part in the DDoS attack (as bots) without the owners’ knowledge.

Start Learning Ethical Hacking with EC-Council

Ethical hacking training is beneficial for aspiring cybersecurity and IT students or professionals. It is one of the most in-demand cybersecurity skills in 2021. Getting trained in the Certified Ethical Hacker program can help aspirants understand the types of ethical hacking phases and attack vectors. Aspirants must understand the types of ethical hackers, the difference between white hats and black hats, the responsibilities of an ethical hacker, the tools and methods used by hackers to begin their career in this field. The need for a white hat hacker or ethical hacker to secure a company’s cybersecurity defenses is critical amidst rising cybercrime. There is a significant demand for ethical hackers at present, as without their contribution, fighting cybercrime can be challenging.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker.


FAQs (Frequently Asked Questions)

  1. What is hacking?

Hacking can be an authorized or unauthorized attempt to penetrate systems and networks and detect vulnerabilities in the infrastructure.

  1. What are the different types of ethical hackers?

There are three major classifications of hackers – white hat hackers, black hat hackers, and grey hat hackers. White hat hackers are ethical hackers who break into systems to prevent cyberattacks. Black hats infiltrate a system or plant malware to exploit the vulnerabilities for personal gain. Grey hat hackers fall somewhere between the white hats and black hats, hence the term grey hats. They break into systems, sometimes without authorization, to discover potential threats and notify the administrator or organization of the same.


References

  1. https://www.atlasobscura.com/articles/the-counterintuitive-history-of-black-hats-white-hats-and-villains
  2. https://www.kaspersky.com/resource-center/definitions/sql-injection
  3. https://sectigostore.com/blog/different-types-of-hackers-hats-explained/

These are the 3 Ps for Thwarting BEC Attacks

BEC Attacks

Business email compromise (BEC) is a prevalent email threat to organizations and a lucrative business for hackers. BEC attacks have increased and become more sophisticated in recent times.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

In a BEC attack, hackers use social engineering tactics to steal the credentials of business email accounts. Further, BEC emails are sent to unwitting employees by spoofing the identity of high-ranking executives. Threat actors trick employees into performing activities under the guise of legitimate business operations.

Increase in BEC Attacks

Though BEC emails do not have any malware payloads, they can cause severe financial damage to the victim organizations via various fiscal fraud campaigns. As per the 2021 Business Email Compromise Report, BEC attacks are the most financially damaging security threats. Out of all security incidents reported by organizations in 2020, BEC attacks accounted for 50%, resulting in other kinds of threats like loss of data (16%), compromised accounts (36%), and payment fraud (16%).

Three Steps to Prevent BEC Attacks

Despite implementing several email security measures, organizations are still suffering from BEC attacks. Here are the three Ps you need to defend your organization from BEC threats:

1. Monitor Your ‘Process’

BEC email attackers usually target employees in the financial department to clear payment approvals by impersonating the company’s C-suite executives. Organizations should enhance their payment approval process to ensure that every payment request is legitimate. Organizations should re-evaluate their payment authorization policy to avoid misuse of the process. Instead of allowing unlimited authorization to a single individual or department, organizations should establish multiple approval levels for any payments.

2. Educate Your ‘People’

Email spoofing and spear-phishing attacks are the most common type of BEC attacks. Employees should be able to identify phishing emails/messages to avoid unnecessary mishaps. A single act of an ignorant employee could cost a fortune to organizations. Employees in every department need to recognize the sender before clicking on links sent via external sources. Human firewall is crucial to disinfect human error.

3. Enhance Your ‘Protection’

Ask your employees to follow basic email hygiene practices to prevent unauthorized intrusions. While deploying the latest anti-virus software, thwarting malicious payloads distributed by email and implementing email authentication services like DomainKeys Identified Mail (DKIM) and Domain-based Message Authentication, Reporting & Conformance (DMARC) will prevent email spoofing. Besides email security, enforce strong password and authentication management policies to boost the security of business email accounts.

Wrap-up

Simple mistakes could disrupt the entire organization’s security defense and risk its most valuable asset – data.  Hence sound security practices – from authentication to awareness – are key to enterprise cyber hygiene.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

Millions of IoT Devices Using ‘ThroughTek Kalay Network’ Vulnerable to Eavesdropping

vulnerability in IoT devices

The rising security breaches and vulnerability exploits on the Internet of Things (IoT) indicate that connected devices are never 100% secure. Security researchers from Mandiant, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), recently discovered a critical flaw that affects millions of IoT devices connected via ThroughTek’s Kalay network.

Tracked as CVE-2021-28372 and FEYE-2021-0020, the flaw could allow remote hackers to eavesdrop on live video and audio streams and take over control of the vulnerable devices, including connected webcams, baby monitors, and digital video recorders. It is estimated that over 83 million IoT devices are vulnerable to this flaw. Successful exploitation of the flaw could allow attackers to remotely control the targeted IoT devices to launch remote code execution attacks.

Proof of Concept

In a video, Mandiant explained how attackers could exploit the CVE-2021-28372 flaw to break into IoT devices.

https://www.youtube.com/watch?v=PBiW-rg8-LE&t=8s

 Video Courtesy: Mandiant  

“With the compromised credentials, an attacker can use the Kalay network to remotely connect to the original device, access AV data, and execute RPC calls. Vulnerabilities in the device-implemented RPC interface can lead to fully remote and complete device compromise. Mandiant observed that the binaries on IoT devices processing Kalay data typically ran as the privileged user root and lacked common binary protections such as Address Space Layout Randomization (ASLR), Platform Independent Execution (PIE), stack canaries, and NX bits,” Mandiant stated in a post.

Dillon FrankeSpeaking exclusively with CISO MAG, Dillon Franke, Associate Consultant, Proactive Services, Mandiant Consulting said, “Mandiant envisions cybercriminals and nation state actors alike being interested in this vulnerability. Cybercriminals could use a working exploit to steal sensitive data from victims or extort them into paying money, while nation-state actors could potentially use this vulnerability to perform mass surveillance of Kalay network users.”

Remediation

Mandiant urged users to update their devices as early as possible to avoid any potential cyber intrusions. It also recommended users to change the passwords for any associated accounts. In addition, CISA released an Industrial Control Systems (ICS) advisory explaining the severity of the vulnerability.

CISA also recommended security measures to mitigate the risk of exploitation of the flaw. These include:

  • Minimize network exposure for all control system devices and ensure that they are not accessible online.
  • Locate control system networks and remote devices behind firewalls and isolate them from the business network.
  • When remote access is required, use secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also, remember VPN is only as secure as its connected devices.
  • Perform proper impact analysis and risk assessment before deploying defensive measures.

IoT vulnerabilities pose a severe risk to end user data privacy. It’s necessary to secure IoT devices as threat actors can intercept other connected devices in the same grid.

Related Stories:

“Privacy Enhancing Technologies can allow organizations to pursue data sharing while remaining compliant”

Privacy Enhancing Technologies

If we were to participate in a Socrates seminar and deliberate on the importance of securing data, in unison, the response would be: Encryption, the “holy grail” for data security! Data is at the core of all businesses and the most valuable asset for any organization. Reams of data need to be managed, processed and analyzed involving multiple parties for marketing and research purposes. Data is sensitive and has chances of being abused by malicious attackers.

The sheer volume of data that needs to be secured considering factors like consumer privacy, data governance and integration of technologies, is a Herculean task.

Increasing data complexity and the adoption of technologies like AI has fueled the growth of privacy-enhancing technologies (PET) to secure data.

A well-mapped-out PET implementation is expected to minimize the window of exposure and enable secured intelligent data usage.

To get a deeper insight on the importance of PET and its adoption trends, Minu Sirsalewala, Editorial Consultant, CISO MAG, interacted with Dr. Ellison Anne Williams, the Founder and CEO of Enveil. Dr. Williams discusses the pioneering Data Privacy Enhancing Technology protecting data in use.

Recognized as an SC Media Reboot Leadership Innovator Award winner and a Woman to Watch in Security, Dr. Williams founded the startup in 2016 to protect sensitive data while it’s being used or processed. She is also a renowned mentor, and privacy and security thought leader.

Building on more than a decade of experience leading avant-garde efforts in the areas of large-scale analytics, information security, and computer network exploitation, powered by homomorphic encryption, Enveil’s solutions like ZeroReveal enable previously impossible business functionalities for intelligence-led decision making.

Dr. Williams leverages her deep technical background and passion for evangelizing the impact of disruptive technologies to cultivate Enveil’s capabilities into category-defining solutions that enable secure search, analytics, sharing, and collaboration.

The need for Privacy Enhancing Technologies (PET) has been more compelling than ever today. With increased incidents of surveillance through spyware like Pegasus and ransomware groups like REvil targeting small and medium businesses, what are the technologies that can ensure privacy to consumers and businesses? How can PET minimize personal data use, maximize data security, and empower individuals?

One of the most interesting aspects of Privacy Enhancing Technologies, in general, is their broad applicability. While they are fundamentally a family of technologies that enable, preserve, and enhance the privacy of data, the range of ways in which they can be applied is broad — use cases range from protecting sensitive assets during processing to enabling secure access to third-party datasets to mitigating insider threat risk. Data is the backbone of the digital economy and an organizational asset that impacts teams across the organization. PETs can help security teams protect sensitive assets while still ensuring the data remains usable.

PET has been around as a technology, what is the adoption curve and where does it stand today? What has been the game-changer?

While PETs have long been the subject of research, the increased attention and activity we see now is the result of both market factors and technology breakthroughs. The digital economy has brought data to the forefront, and we’ve also seen a shift in the privacy landscape driven by both global regulations and consumer demand. From a technology perspective, we’re seeing technologies that once were computationally impractical now being implemented at scale. For example, homomorphic encryption, a pillar of the PETs category that allows computations to be performed in ciphertext as though it were plaintext, once required days to perform even the most basic functions. Now those same operations can be done in seconds, opening the door to a number of use cases across verticals.

What are your thoughts on how PET is empowering businesses across geographies and industry verticals?

One of the best use cases for PETs we’ve seen emerge recently is around the category’s ability to help organizations securely and privately share data across jurisdictions or internal/external data silos. While regulations increasingly limit or block such actions completely, PETs like homomorphic encryption (HE) can overcome these challenges by allowing operations (searches or analytics) to be performed without exposing the interaction with the data. HE allows entities to securely collaborate in a decentralized manner without replicating or moving data between jurisdictions, all while prioritizing data privacy. The outcomes are a significant savings of resources and time, as well as a reduction in operational risk relating to the possible mishandling of sensitive or regulated data.

With sensitive data being exposed to open and unsecured networks, how can organizations adopt PET to create a business value and minimize risk?

The emergence of new and varied attack surfaces is driving more organizations toward Zero Trust strategies, which are designed under the assumption that systems are compromised. Encryption plays a key role with this architecture, which includes looking beyond at-rest or in-transit encryption to also protect data while it’s being used or processed. Privacy Enhancing Technologies like homomorphic encryption play a key role in protecting this often-overlooked security gap.

How can PET ensure security for the data life cycle — right from data creation to data in transit, to data processing? Where are the challenges?

PETs uniquely protect data during processing or Data in Use. There have long been solutions geared at protecting Data at Rest on the file system or Data in Transit as it moves through the network, but organizations often overlook the need for protecting it while it’s being used, frankly, because it’s a hard problem to solve. That’s why PETs are such a game-changer — they allow us to securely and privately leverage data in ways that were not previously possible.

Homomorphic encryption, Multiparty computation, Zero-knowledge proofs and Trusted execution environments are some common PETs. Which of these has seen a significant change (evolved) and adoption? Could you share some market figures if available?  

We have seen a significant uptick in both interest and activity related to PETs in recent months. Analysts at Gartner named privacy-enhancing computation as one of the Top Strategic Technology Trends for 2021 and further predict that by 2025, 50% of large organizations will adopt privacy-enhancing computation for processing data in untrusted environments and multiparty data analytics use cases (Gartner “Top Strategic Technology Trends for 2021,” Oct. 2020). Anecdotally, I can speak to what we’re seeing in the homomorphic encryption space since that is the technology the majority of our products leverage. When I founded Enveil nearly five years ago, references to HE would evoke blank stares, but I am pleased to say that is no longer the case. We’re seeing a broad recognition and a real excitement around HE’s power and applicability, the momentum that supports the growing activity we see in the commercial and government market.

What about data masking techniques as compared to the traditional PET-like cryptographic algorithms?  

While it’s tough to generalize, data masking techniques and cryptography serve different purposes. While I thoroughly believe in the power of encryption, I am not a person who advocates for encrypting everything. In most cases, that approach is just not practical. Organizations are better served by understanding what information or interactions are truly sensitive and focusing their efforts on ensuring that information is secure throughout its lifecycle — at rest, in transit, and in use. Data masking can be an effective way to fill in some of the gaps, but it will never offer the same level of protection as encryption.

Now that companies can securely access data sets, it broadens the application possibilities. Which are some areas where we see increased PET application? (For example, financial transactions; health care-clinical data; data transfer with multiple entities and parties) 

Here are several examples of practical business use cases from an article I wrote on the topic last year, which continues to apply in current times:

  • Secure Data Monetization — Organizations looking for new revenue streams are increasingly examining how they might leverage existing data assets; however, the data can only be securely and ethically monetized if the privacy of both the customers of the monetization service and the underlying data itself is respected. Because HE uniquely allows data to be processed in a privacy-preserving manner without risk of exposure, it opens the door for such secure monetization to occur. This allows existing sensitive or regulated data assets to be used in ways that may have previously been determined as too risky to pursue.
  • Third-Party Risk — Third parties can present the greatest risk of exposure for both data security and associated regulatory compliance. To use and share data with an ecosystem of third parties to accelerate performance, enhance agility and realize cost savings, the ability to effectively share data assets with these third-party collaborators is critical. Homomorphic encryption allows this collaboration to occur in a secure, decentralized manner while protecting against the risk of data breaches, regulatory penalties or brand/reputational damage.
  • Secure Data Sharing and Collaboration — Homomorphic encryption enables organizations to securely collaborate across organizational or jurisdictional boundaries without introducing new sensitive variables into the organization’s data holdings. This is important because exposure to these indicators could trigger additional reporting requirements or expose competitive advantage. By protecting data while it’s being processed, HE allows these organizations to securely leverage external data assets in a decentralized manner without exposing sensitive indicators. The technology also can be configured to allow them to continue respecting the access and verification controls established by the data’s owner.

How are data protection laws such as GDPR and CCPA influencing the importance of PET implementation?  

At its core, PETs are a family of technologies that enable, enhance, and preserve the privacy of data throughout its lifecycle. Beyond locking down the data, some of these technologies allow data assets to be securely and privately used, overcoming the very regulatory barriers that have in many ways spurred a renewed interest in their usage. Organizations that have seen business functionalities inhibited by the surge in privacy regulations see PETs as a way to extract critical insights without the need to move or replicate data, which is often not feasible. PETs can also allow organizations to pursue data sharing and collaboration practices while remaining in compliance.

What are some technology business drivers and strategies that are affecting or influencing innovation in the security realm?

While there were many challenges associated with the pandemic, it did cause us to take a second look at the security, access, and usability of our organizational data assets — which I think is a good thing. Technologies that may have previously been viewed as “nice to have” started to look more like necessities. The need for remote access caused us to rethink the way things have always been done, and in many cases, the technology was ready to provide a solution. As the world starts to look more normal in the months ahead, I hope we can keep that drive to innovate.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

Secret Terrorist Watchlist with 1.9 Mn Records Exposed Online

Secret Terrorist Watchlist Leak, Aruba

Sometimes, misconfigured servers and unsecured databases go unnoticed until security researchers report about them. Bob Diachenko, Head of Security Research at Comparitech, recently discovered an unsecured Elasticsearch server containing a terrorist watchlist of over 1.9 million records. The server was left online without any password protection, allowing anyone to access the information.

Diachenko stated that the watchlist belongs to the Terrorist Screening Center (TSC), an FBI multi-agency group. The TSC maintains a watchlist of suspected terrorists and no-fly members, which is a subset of a larger watchlist. Officials are authorized to access the watchlist and perform terrorist screening.

The exposed records contained confidential information such as full names, TSC watchlist ID, citizenship, gender, birthdates, passport number, country of issuance, and no-fly indicator. The database is now secured after Diachenko reported the issue to the Department of Homeland Security (DHS).

Potential Risks Involved 

While search engines like Censys and ZoomEye indexed the leaky server, Diachenko stated that he is unsure if any unauthorized party has accessed it. Since the exposed data belongs to the people suspected as terrorists, there could be severe repercussions if the data falls into the wrong hands.

“The terrorist watchlist is made up of people who are suspected of terrorism but who have not necessarily been charged with any crime. In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families. It could cause any number of personal and professional problems for innocent people whose names are included in the list,” Diachenko said in a post.

Bob DiachenkoSpeaking exclusively with CISO MAG, Diachenko said, “While it is unknown what party was responsible for the exposure of this watchlist, one thing is clear – no matter what size is your organization and how well established is your security posture, there should always be a place for additional checkups using quite simple cyber hygiene rules.”