Home Blog Page 63

T-Mobile Investigates Illegal Security Intrusion

T-Mobile data breach

It seems like the famous American telco T-Mobile is cursed to suffer constant security incidents. After sustaining a data breach in February 2021, T-Mobile recently announced that it is investigating an unauthorized intrusion that could have allowed access to its user data that is otherwise inaccessible.

In an official statement, the telco said, “We have been working around the clock to investigate claims being made that T-Mobile data may have been illegally accessed. We take the protection of our customers very seriously, and we are conducting an extensive analysis alongside digital forensic experts to understand the validity of these claims. We are coordinating with law enforcement.”

While T-Mobile did not reveal the details about the kind of data breached or the number of affected users, a report claimed that attackers obtained sensitive information related to over 100 million users from T-Mobile servers. The accessed information includes customers’ names, contact details, social security numbers, addresses, IMEI numbers, and driver license details. Threat actors are allegedly selling the obtained data on darknet forums and asking for Bitcoins.

However, T-Mobile stated it has not yet determined whether any customer data has been exposed. “We are confident that the entry point used to gain access has been closed, and we are continuing our in-depth technical review of the situation across our systems to identify the nature of any data that was illegally accessed. This investigation will take some time, but we are working with the highest degree of urgency. Until we have completed this assessment, we cannot confirm the reported number of records affected or the validity of statements made by others,” T-Mobile added.

An Act of Revenge

Alon Gal, the CTO of cybercrime intelligence firm Hudson Rock, claimed that attackers performed this leak to cause damage to the U.S. critical infrastructure.

Mitigations

Customers of T-Mobile services, who are concerned about their private data being vulnerable, can apply the following security measures to prevent potential cyberthreats:

  • Monitor all your accounts to find any unauthorized/fraudulent activity. Don’t forget to report if you find any suspicious activity.
  • Use a credit monitoring service to ensure data privacy.
  • Do not respond to suspicious emails/messages received from unknown sources.
  • Change passwords of all your online accounts.

Data breaches can result in loss of trust among customers and impact the brand value of a business. Hence, paramount security is critical in ensuring the protection of confidential data.

How to Know When it’s Time to Break Up with Your Tech Provider

tech, tech provider

Even if your organization doesn’t want to address it, there comes a time when every company needs to take a step back, take stock of their tech stack, and ask themselves if it’s time for a change.

By Tim Bandos, Chief Information Security Officer and VP Managed Security Services, Digital Guardian

It’s not your fault – let’s say your organization has grown, not just in size but in business maturity, since you first implemented your current vendor. It may be the case that the provider hasn’t had the capacity or means to scale along with you.

While not always easy to know when the time is right, there are three tell-tale signs that you’ve outgrown your provider.

Lack of innovation

If your provider isn’t staying on top of the latest technology – solutions that can add value to your business and empower employees to learn new skills and execute their work at a high level – it may be time to look elsewhere. Maybe your company has grown too comfortable with legacy technology. Its drawbacks may seem like slight annoyances to you. Still, it could indicate a larger problem or a missed opportunity to cut costs or add customer value with new alternative technology. Your vendor should be proactive in keeping you apprised of the latest technology and solutions, especially if they can help your company become more economical and productive.

Every organization wants to stay focused on maintaining its competitive edge, especially in a market as volatile as the one today. If your vendor isn’t doing their part – investigating in interoperability, so your organization can get a greater return from the sum of your tech investments – it should set off a red flag.

Does your vendor have a CISO? Do they use safe APIs? Are they using DevOps? Have they moved to the cloud for added speed and flexibility? If you answered “no” to any of these questions, you might want to ask them – why not?

Maybe your provider was recently bought and absorbed by another corporation. Whenever a company is acquired and a business changes hands, there’s a lot in flux. With change, it’s not unusual to have some questions about the direction your vendor may be going. With an acquisition, corporate reshuffles are commonplace. Could this impact leadership, engineering, and budget at a vendor you use? Are you willing to trust a company and its vision despite these changes?

In some instances, when a tech company is acquired, innovation is stifled, and the acquiring company does little more than maintain the product. Acquisitions can also result in cutbacks on support resources and failure to invest in new features that help ensure the security of their software.

That’s not to mention that old, depreciated technology can put your employee and customer data at risk. As more and more companies can attest these days, experiencing a data breach can pose a risk to your company’s brand and have a serious effect on carrying out day-to-day business. Your organization is part of a supply chain; it’s essential to ensure that every vendor you partner with is following best practices.

It’s not you, it’s me (your needs have changed)

As I hinted earlier, maybe your organization has grown since you first implemented your current technology vendor, and they haven’t been able to keep up. Perhaps your business has grown so fast that your needs have changed from what they once were.

If your vendor isn’t keeping up by periodically performing audits to ensure that policies and procedures you have in place are effective in meeting those needs, you may have blind spots in your coverage. Your vendors’ IT services should be tailored to meet you. The old marketing slogan, “set it and forget it,” rarely applies to your technology stack. Staying with a vendor that isn’t constantly evolving alongside your business could be hurting your company’s bottom line.

Perhaps your organization has elected to move away from the rigidness of the waterfall software development method and go the agile route to deliver products rapidly and to better respond to changes in your environment. If so, you know that creating a truly agile team requires a big cultural shift and reduced organizational resistance. If your vendor isn’t agile or does something to hold you back from fulfilling that cultural change, you may need one better suited to complement your needs.

Depending on your space, shifting regulatory compliance requirements can often dictate a company’s needs. Satisfying governance, risk management, and compliance (GRC) requirements demand a higher degree of attention. It’s one thing to tick checkboxes associated with regulations like HIPAA, GLBA, and SOX. All of them, in addition to state, federal, and global legislative requirements, require organizations to have the appropriate technical safeguards in place.

To keep up with evolving regulations, especially those slated to take effect soon, organizations need a higher level of engagement, planning, and collaboration from their vendors. Ensuring there’s visibility across all your critical assets to identify data, the organizational policies they’re governed by, and whether it complies, is essential to navigating the risk landscape, too. Your provider should be aware of these changing regulations and offer advice and guidance on satisfying them if they’re not already.

The vendors you use are integral to your company’s success – they help drive growth, revenue, and goals. If yours aren’t, it’s time to reevaluate those relationships…To read the full article, subscribe to CISO MAG.

This story first appeared in the June 2021 issue of CISO MAG.


About the Author

Tim BandosTim Bandos is the Chief Information Security Officer (CISO) and and VP Managed Security Services for Digital Guardian. He has over 15 years of experience to the position including his five years as VP of cybersecurity at Digital Guardian. Prior to joining Digital Guardian, Bandos was Director of Cybersecurity for Dupont where he was responsible for overseeing internal controls, incident response, and threat intelligence.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Everything You Need to Know About the Evolution of Cyberthreats

cyberthreats, bug

The theory of evolution proposed by Charles Darwin is based on the concept of change in characteristics of a population over successive generations. An apt example of this is that of the homoserines, where the achievements of the descendants are nothing but the further development that of their predecessors. The same holds true for all other aspects, including technology, and yes, even cybercrime. With advancements in technologies, there has also been a direct proportional development in their related misuse. With digital technologies focused on computer systems, networks, the internet, etc., impacting our day-to-day lives, cyberthreats have also evolved to become more aggressive, stealthy, and potent.

By Rahil Karedia, Global Head – Threat & Security Intelligence and Security Advisory, Network Intelligence, Inc.

Cyberthreat has been in existence since the early stages of communication and is evolving since then with the subsequent development of technology. From Landline hacking in the 1970s to cryptojacking in 2021, cybercrimes tend to become more and more sophisticated with time. With every passing decade, the technological society and cybersecurity professionals find themselves amidst highly coordinated and relentless attacks on digital assets and infrastructure, where the existing solution or defense either fell short or was not scalable enough for the implementation of emerging technology.

The 50s ad 60s

Cyberthreats in the Pre-millennial era looked completely different than what we know or imagine today. Even before the internet was introduced, cybercrimes were being conducted through targeting telecommunications. The fact that people could reach out to other people over a large distance while being unseen.

Landline Hack: Throughout the 1950s and 60’s the wired telecommunication technology was booming, and landlines were available in the majority of households across developed countries. This decade also marked the onset of the first digital-based crime known as “Phreaking,” where the perpetrators exploited the tone system used in telephone networks [1]. The episode dates back to the late 1950s, where a group of phreaks, a short form for the term “Phone Freaks” [2], decided to hack telephone networks by making unauthorized and unauthenticated long-distance phone calls by reverse-engineering the tones used by the telephone organizations. They also set up special party lines to help other fellow phreaks. Perpetrators often impersonated officials, an extensive search of the Bell Telephone company garbage to find any secret information or data, and experimented on the early telephone hardware to learn how to exploit them meticulously, which results in free long-distance telephone calls [3].

The 70s

“The introduction of computer virus”

The decade of over-the-top fashion and new genres of music also saw a new change in the digital landscape. Though research on self-replicating programs was in progress since the ’50s, the first practical implementation, i.e., a computer virus attack was seen in the early 1970s [4]. Bob Thomas, an engineer at BBN Technologies, wrote an experimental self-replicating program, which could move between computers connected by the ARPANET — the technical foundation of the internet [4].

As it could move from one system to another, it was termed as ‘Creeper,’ and while coping itself to the remote system of the 33 ASR teletype model, it left a message that read: “I’M THE CREEPER: CATCH ME IF YOU CAN,” [5]. The techniques which were used in the Creeper were later used in the McROSS — Air traffic simulator to allow certain parts of stimulation to move across the network. The invention of Creeper was soon followed by the development of its enhanced versions. Ray Tomlinson later coded an enhanced version of the Creeper and also went on to write a program called the Reaper, which moved through the ARPANET removing the existing copies of the Creeper.

With the trend of developments and enhancements that defined this decade, programmers with malicious intent for destruction began to emerge, and soon various other viruses were coded and deployed. One of the progenies of such a trend was the rabbit virus that came to light in 1974. This virus is also considered by some as the foundation to early malware, as it was coded to self-replicate until the system crashed [6].

The 80s

The decade that was witness to the birth and propagation of personal computers and wireless telecommunication was also witnessing a prominent growth of destructive viruses. In the same year of 1981, when IBM released its first personal computer, a ninth-grader from Pittsburgh wrote a program called “Elk Cloner” that attached itself to Apple DOS 3.3 OS and was designed to be activated on its 50th use. This was the first virus to appear in the wild and was spread through the mean of the floppy disk.

The term ‘Computer Virus’ was coined by Leonard Adleman, and research termed “Computer Viruses – Theory and Experiments” was first published by his student Fred Cohen in 1984. With the passing years and constant evolution of technologies, viruses started becoming more sophisticated and destructive every year. In 1986, the PC platform was struck with the first-ever “Global epidemic” called the “brain virus,” as the internet was connecting many systems across the globe, hence, scaling up the spread of the virus. The propagation of the brin virus depicted the lack of security of the systems and was followed by the Vienna virus in the 1987’s, the first-ever virus which was meant to destroy the data.

This decade saw the actual rapid evolution of computer viruses that began to be classified into different categories based on their behavior, such as worms, trojans, etc., that developed with time. The first-ever worm— Morris Worm, was released in November 1988 by Robert Tappan Morris. Morris wasn’t aware of his creation as to what capabilities it held, as it was not designed with an intent of malice. In 1988, the Morris worm, which replicated itself soon with time, evolved into the world’s first large-scale Denial-Of-Service (DOS) attack. It spread through the world and brought many organizational servers and personal computers to a halt. Though Morris released the solution soon enough, for shutting down the program, severe damage caused by the worm was already done and evident. Morris was prosecuted and charged with violating the Computer Fraud and Abuse Act in 1989 [8].

Ransomware attacks first became known to the public in 1989, where the “Aids Trojan” was used to hide files. It was written by Joseph Popp and coded so that the files were encrypted with their names and, when done, displayed a message that stated: “User license to use the software has been expired.” The victims were asked to pay 189 dollars to the PC Cyborg Corporation to receive the repair tool that decrypted the encrypted files [9]. Though this was not considered extremely damaging as encrypting files with names backfired and was easy to restore, this gave rise to the idea of extortion through encryption which soon caught on. Since then, ransomware attacks have evolved and have become more sophisticated, as seen in recent times. Ransomware has grown to be the biggest cyberthreat in today’s time.

On the positive side, this decade witnessed the rise of cybersecurity, with many antivirus products becoming commercially available in the market. Many businesses targeting this market emerged around this period, which includes renowned cybersecurity giants such as Avast, McAfee, etc.

The 90s

As the world went online through the boom of the internet, this decade witnessed the first polymorphic viruses that replicated themselves while the original algorithm was intact in order to avoid any kind of detection.

As organizations began to digitalize and incorporated this into their marketing strategy, i.e., providing free disk, this gave malware a platform to spread further. By 1996 many viruses evolved like the stealth capability, polymorphic viruses, macro viruses, etc. They kept multiplying and spreading in the wild in such a way that by 2007, there were more than five million viruses and malware [7].

Towards the end of the 1990s, emails were a booming trend, and almost everyone with a system and internet connection possessed an email-id for themselves to communicate with ease. This became one of the most popular platforms for threat actors to spread malware and spam. Phishing attacks made the most use of this platform to trick victims into providing sensitive information or downloading malicious attachments.

In 1999, the Melissa Virus surfaced, which initiated the victim’s system via a Word document. It emailed copies of itself to the first 50 email addresses in Microsoft Outlook. It is still one of the fastest spreading viruses, which caused a damage of 80 million dollars to rectify and fix the damages.

The Turn of the Century

AS time progressed, viruses started becoming more progressive and sophisticated, which was evident throughout the 2000s. Numerous viruses came into existence, targeting specific functions of the system via the internet, network, and techniques, ranging from keystroke logging to advanced ransomware attacks.

The Distributed Denial of Service (DDOS) was the epitome of network-based attacks, as the world noticed a breakpoint in Feb 2000, where a series of DDOS attacks surfaced when a 15-year-old Canadian hacker known as the “mafia boy” mounted and executed the DDOS attacks which targeted the e-commerce websites (including Amazon and eBay). The attack led to a loss of 1.7 billion dollars and forced organizations to shut down their websites to regulate legitimate traffic flow.

With the start of the 2000s, a new era of malware emerged as emails were seen as exploitable access points for the perpetrators, who aimed at causing more destruction. The ‘ILOVEYOU’ worm infected nearly 50 million systems which corrupted the data and self-propagated itself by exploiting the victim’s email contacts. This gave an insight into how cybersecurity was crucial and the necessity for all systems to have antivirus software installed to safeguard their systems and data.

The 2000s came to be known as the carding era [10], where digital cash was still a new thing, and people using their Debit Credit cards to purchase various items online. With people relying on the internet for various purposes and digital transactions becoming a trend, Carding attacks increased. Speculations started with the Russian carding forums and marketplaces used by the perpetrators to steal card details and utilized sensitive information for multiple purposes like identity theft and phishing attacks. Cardholders who often used e-commerce platforms were susceptible to carding and phishing attacks, allowing perpetrators to access sensitive information critical to their personally identifiable information (PII). The stolen details were often sold to other criminals or put on sale on various hackers’ platforms and the dark web. The stolen details are often used to make new, fake cards. One such website was the CarderPlanet, founded by Golubov D.I. et al. in the year 2001.

The Twen’tē-tens

Data breaches soon became the center of attraction for the information security landscape due to the emergence of various malware attacks in the decade. In contrast to the previous era where the threat landscape saw the evolution and drastic changes occurring in the time frame of few years, the 2010s and the subsequent decade would see a change in trend every year. There were not any notable novel cyberthreats in this decade, but the development in the existing threat and attack vectors, and their aspects such as mode of dissemination, target, counter anti-cybercrime strategies contributed to the exponential growth of the threat landscape. As time passed by, various new attacks were witnessed with the bypassing years like [10]:

  • The year of the data breach – 2011
  • The post PC era – 2012
  • The year of online banking threats – 2013
  • The year of cyberattacks – 2014
  • The year of botnets – 2015
  • The year of digital extortion – 2016
  • The year of global ransomware outbreaks – 2017

This decade saw numerous organizations become victims of data breaches and malware attacks. Especially the initial years were known to be the most challenging for organizations and cybersecurity professionals as the victims of data breaches lost reputation due to the loss of confidential and sensitive information and bore resulting financial burdens and losses towards stabilizing the situation and fixing the damages. Conditions were adverse where organizations like RSA and Sony Play Station had no other options other than disclosing the details and facts about the attack against their organization to assure their customers that proper mitigation steps are taken to resolve the issues.

After initial years the digital data and online presence of users started to move away from personal computers and towards mobile and virtual machines. This change is marked as the post-PC era and also noticed a significant rise in the cybercrimes focused on Android platforms, social networking sites, cloud, etc. As it took less than three years for android devices to reach the threat level of the PCs, which took nearly 14 years for the same, mobile-based cyberthreats and attacks rose in recognition.

The Twen’tē-20s

The future of cyberthreat is projected to be similar to that of the previous decade, where the existing threat vectors and attacks will be developed upon with unique implementation across emerging technologies such as the Internet of Things (IoT), cloud computing, and virtual machines, and blockchain technology. Attack vectors such as phishing and social engineering are here to stay, and the cybersecurity experts do not see them going away any time soon.

Apart from this, the IoT and blockchain technology has given rise to a new form of threat known as crypto-jacking. Crypto-jacking is an evolved form of botnet attacks and is an attack carried out by perpetrators who gain unauthorized access to the victim’s devices (PCs, Tablets, Mobiles, serves of an organization, etc.) to mine cryptocurrencies. Cryptocurrency is digital or virtual money in tokens or coins based on blockchains, and Bitcoin is one of the most popularly known cryptocurrencies. The main of crypto-jacking is to benefit from crypto mining without bearing the vast costs (mining hardware, high electricity costs) of the mining process [11]. Cybercrimes related to cryptocurrencies are seen from 2009 till date, but the cryptocurrency sector is booming, and many individuals investing in cryptocurrencies (especially the ones that have larger values such as bitcoin) have drawn the attention of many attackers. It embeds itself on the victim’s device and uses its resources to mine cryptocurrency.

Conclusion

Cybercrimes have evolved drastically! And malicious use of programs and exploitation of vulnerabilities has greatly modified the cybersecurity landscape. From small viruses that were created as pranks to their use as a threat evolved with time and then scaled to spread across the globe with change from ARPANET to the internet. With the introduction of platforms such as email, networks, cloud, IoT, blockchain, etc. that connected people and data across the globe with lightning speed, the attackers were on the run to create the perfect virus, malware, and other attacks which would compromise on the authenticity, integrity and the confidentiality of the data and cause great harm to the victim and systems.

With the development of technology and integration of security standards, attackers pushed themselves to be a step ahead and create advanced malware, trojans, ransomware, and protocols and procedures that successfully bypassed the security mechanisms. This has been a recurring stance since the technology started developing. Cybercrimes, like cybersecurity, are a forever developing and evolving process. Perpetrators are constantly working on building sophisticated threats, malware, etc., on infiltrating the prevalent and upcoming security measures. It is essential to enhance security measures and protect ourselves from becoming a victim of the ever-growing cybercrime.


About the Author

Rahil KarediaRahil Karedia, Global Head – Threat & Security Intelligence and Security Advisory, Network Intelligence, Inc. Rahil is a trusted, responsible and knowledgeable cyberspace veteran with more than five years of experience in operational security domains such as Security Operations Centre (SOC), Threat Intelligence (TI), Threat Hunting (TH), and Incident Response (IR). He is currently leading Threat Intelligence, Security Intelligence, and Security Advisory services.

He has assisted corporate, government, and defense customers from diverse industries (Banking and Finance, Healthcare and Insurance, FinTech and Biotech, Oil and Gas, Power Grid and Nuclear Facility, Government and Foreign Affairs, Aerospace and Defense, Surveillance and Investigation, etc.), for effectively managing the Cyber Security workforce by providing clear visibility on their cyber risk profile and exposure to the cyber threats. He is currently serving EC-Council’s Global Advisory Board for CTIA and has jointly authored a Cyber Research whitepaper on “Role of a Pen Tester in Ethical Hacking” with EC-Council.

Rahil is also focused on terrorism and cyber terrorism, CBRN terrorism, and human trafficking and migrant smuggling issues. He has jointly collaborated with the U.S. Army, U.S. Army TRADOC, and CSFI on four projects related to cyber intelligence, operational security, and telecommunication and internet surveillance.

Rahil’s key aim is to assist and enable organizations in taking intelligence-driven decisions and actions in cybersecurity operations and management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


References:

  1. https://hub.packtpub.com/the-evolution-cybercrime/
  2. https://www.britannica.com/topic/cybercrime/Spam-steganography-and-e-mail-hacking
  3. https://www.floridatechonline.com/blog/information-technology/a-brief-history-of-cyber-crime/
  4. https://www.latrobe.edu.au/nest/fascinating-evolution-cybersecurity/
  5. https://corewar.co.uk/creeper.htm
  6. https://www.nortonlifelockpartner.com/security-center/evolution-of-computer-viruses.html
  7. https://cybersecurityventures.com/the-history-of-cybercrime-and-cybersecurity-1940-2020/
  8. https://www.webroot.com/blog/2019/04/23/the-evolution-of-cybercrime/
  9. https://resources.infosecinstitute.com/topic/evolution-in-the-world-of-cyber-crime/
  10. https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/evolution-of-cybercrime
  11. https://www.kaspersky.com/resource-center/definitions/what-is-cryptojacking

Mr. White Hat Controls Poly Network’s User Assets for Fun!

Poly Network
Image credit: Freepik www.freepik.com

Reported as the largest Decentralized Finance (DeFi) Platform hack, Poly Network is the most recent addition to the high value list of victims of crypto attack. It was robbed of around $600 million crypto tokens.

Poly Network is a blockchain system that provides a platform for cross-chain interactive services. It allows authorized homogeneous and heterogeneous public blockchains to connect to Poly Network through an open, transparent admission mechanism and communicate with other blockchains.

Going by the name Mr. White Hat, the hacker stole approximately $600 million in bitcoins from the Poly platform and took control of the user assets. According to Twitter updates the company shared that, less than 48 hours into the hack, the stolen tokens were being returned.

The company first announced the breach on 10th August on its official twitter handle @PolyNetwork2

The post read:

Important Notice: We are sorry to announce that #PolyNetwork was attacked on @BinanceChain @ethereum and @0xPolygon Assets had been transferred to hacker’s address.

FireEye Mandiant to Provide Cyber Defense to Alpine F1 Team

Alpine F1 Team

If the pandemic had played a spoilt sport for ardent Grand Prix fans and deprived them of the adrenaline rush, “The Hungarian Grand Prix 2021” more than made up with the action-packed drama from the word “Go.” Right from the rain stalling the start to the big Turn 1 crashes, which resulted in the dismissal of five cars in the first lap, to throwing up the big surprise maiden winner, the race had it all. Esteban Ocon for Alpine witnessed his first-ever F1 victory at the track.  But a security breach or ransomware attack on the information systems enabling the racing operations could bring the F1 cars to a halt or worse, cause them to crash on the track. So, here’s what the Alpine F1 Team does to mitigate the risk of that happening.

By Minu Sirsalewala, Editorial Consultant, CISO MAG

The Alpine F1 Team has been evaluating partnerships to improve their performance and have the fastest, safest cars on the track. Amongst these partnerships is their recent association with FireEye Mandiant to protect data across racing operations. As the 2021 season sprang victory surprises, the race was also making headlines for the massive damage to Max Verstappen’s Red Bull, which cost $1.8 million in loss to the Australian racing team.

Could the crash be avoided with more technological advancement or system intelligence? Imagine the magnitude of these losses if there was a hacking incident, critical data breach, or even a ransomware attack.

F1 and Cybersecurity

Formula One is the world’s most significant racing competition, with more than half a billion fans following races in multiple regions around the globe. Formula One is also unlike any other sport: an engineering discipline at the forefront of material science, and many of these technological advancements end up in aerospace and defense after being developed for the track. As a result, a considerable amount of intellectual property could be at risk for F1 teams as a whole.

Alpine F1 Team relies increasingly on technologies like artificial intelligence, connectivity between international locations, digital communication, and advanced data capture across multiple platforms, including telemetry, driver simulators, and its race cars. This is where Mandiant fills the gap to protect its engineering operations.

FireEye Mandiant and Alpine F1 Team Partnership

Alpine F1 Team was looking for a partner to help them mature, and the starting point for them was with Mandiant Solutions & Services. Going forward with the partnership, Mandiant will protect the data coming into the operations room on race day as the Team makes real-time decisions on strategy and performance. All data associated with a Formula One race car is subject to cyber risk.

Kevin TaylorAs we have seen, communities in the world spotlight like Formula One are targets for cyberattacks, and when Alpine F1 Team sought to protect its engineering operations, they turned to Mandiant. Helping Alpine F1 Team tackle the new challenges of cybersecurity is to stay one step ahead of cyberthreats on and off-track.

 

– Kevin Taylor, Senior VP, EMEA, FireEye Mandiant

Cyber Defense for the Digital Ecosystem

Laurent Rossi, Chief Executive Officer, Alpine said, “In Formula One, success is achieved by taking humans and technology to the limit while minimizing risk.” Similarly, with the digital transformation, data also needs to be treated with an approach where we push the intelligence and security limits to create a winning secured environment.

Rossi added, “The fastest cars in the world are also amongst the safest and we needed a strategic partner who could help us extend the same approach to our data, the digital reflection of who we are. Mandiant will thus cover a critical aspect of our engineering operations and is a welcome new member of our Technical Partners family.”

With intellectual property (IP) at the core of all operations at the team, data security was of prime concern. Any vulnerability that could cause a cyberattack will damage IP, brand image, strategy, and finance at Alpine F1 Team. The Mandiant solution will cover everything from design, supply chain, production, simulation, and racing operations. In a hyper-connected digital world, this is no less critical than the advanced and very tangible solutions enforced to protect the drivers.

“Mandiant has a deep-rooted understanding of managing cyber risk. It’s a part of everything that we do. Through this partnership, Mandiant will provide Cyber Defense to Alpine F1 Team’s digital ecosystem,” said Taylor.

Conclusion

Incidents of cyberattacks continue to plague every industry and only exacerbate the situation with the likes of ransomware with higher values at stake. Where damages and payouts are in millions and upward, the list of targeted organizations is no more limited to the financial or health care sector. With IP and digital assets getting targeted, companies need to revisit their security posture and beef up the protection. With technological advancements and innovations, the automotive industry is a lucrative target and has now actively been looking at partnerships to plan and manage cyber defense.

Pierre d’Imbleval, VP IS/IT Alpine, opined, “Formula One Teams are at the forefront of technological innovation and, when you are part of an elite, it is easier to become a target. In Mandiant, we have found a strategic partner who shares our understanding of the importance of planning and managing cyber risk.”


Minu

About the Author

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

 

Threat Actors Turning to RDDoS Attacks as a New Ransom Vector

DDoS Attacks in Russia , RDDoS attacks, DDoS attack on New Zealand Banks

While ransomware attacks are taking the corporate world by storm, a latest analysis revealed that over 44% of businesses sustained a ransom distributed denial of service (RDDoS) attack in the past 12 months. The Neustar International Security Council (NISC) analysis disclosed that nearly 70% of organizations were targeted with RDDoS attacks, and 36% agreed to pay the ransom.

What’s an RDDoS Attack?

A ransom DDoS attack is an extortion scheme in which malicious actors demand organizations or individuals pay the ransom by threatening the victims with a DDoS attack. In an RDDoS attack, cybercriminals either launch a DDoS attack and then demand ransom to stop, or they may ask for the ransom first by threatening with a DDoS attack if not paid.

Ransomware Operators Turning to RDDoS Attacks

NISC highlighted that several cybercriminal groups are leveraging RDDoS attack techniques to target various industries, including financial services, telecommunications, and government agencies. The research revealed that only 24% of organizations said they know how to respond to RDDoS attacks. Over 56% of organizations stated they outsource their DDoS mitigation to third parties. The research findings indicate that threat actors are using RDDoS as an effective ransom extortion technique.

“Rather than spending a lot of time and careful planning on infecting an organization’s network with malware or ransomware, cybercriminals are taking an easier approach and using DDoS as a ransom vector. For bad actors, launching a DDoS attack is relatively simple and has the added benefit of being harder to trace back to its origin,” said Rodney Joffe, Chairman of NISC, SVP and Fellow.

“It’s common for organizations to feel pressure to pay to get their website back up and running and avoid disruption. However, with attackers targeting the same company multiple times, paying the ransom only makes it more likely that you will fall victim again. Instead, businesses must take an ‘always on’ approach to DDoS security, ensuring that their site remains protected even in the event of an attack.”

Accenture Hit by LockBit 2.0 Ransomware! Attackers Demand $50 Mn

Accenture ransomware attack, South Africa Justice Department

Cyber intrusions by LockBit 2.0 ransomware operators are increasing across the globe. The Australian Cyber Security Centre (ACSC) recently warned about the rise in LockBit 2.0 ransomware attacks in Australia. The latest company to fall victim to LockBit is Accenture.

The global IT consultancy giant admitted that it identified unusual activity in its network systems after a report claimed that attackers would leak the compromised files on the dark web. While Accenture didn’t reveal what kind of data has been affected, cyberthreat research firm Cyble stated that attackers compromised servers that hold over 6TB of information, and demanded a $50 million ransom to decrypt it.

No Impact

While multiple reports claimed that LockBit operators got hold of Accenture’s sensitive data, the company clarified that it’s not impacted by the security incident and restored its systems, retrieving data from backups.

“Through our security controls and protocols, we identified irregular activity in one of our environments. We immediately contained the matter and isolated the affected servers. We fully restored our affected systems from backup, and there was no impact on Accenture’s operations or our clients’ systems,” Accenture said in a statement.

LockBit 2.0 Ransomware

LockBit 2.0 is the latest variant from LockBit and ABCD ransomware groups. The LockBit gang operates as a ransomware-as-a-service (RaaS) model appointing affiliates and malicious insiders to carry out intrusion activities. It is found that the LockBit group has been working on Russian-language cybercrime forums since January 2020. Attackers have been advertising its latest version, LockBit 2.0 ransomware, with built-in information stealing feature dubbed StealBit.

What Experts Say…

Commenting on the security incident, Dirk Schrader, Global VP of Netwrix, told CISO MAG, “This form of ransomware attack will become even more dominant in the future; companies are getting less likely to pay a ransom for any decryptor, and their preparation for an encryption attack is also getting better. Threatening to release confidential customer data as the blackmailing tactic of choice plays too many aspects in areas like lawsuits related to breach of contract confidentiality, loss of customer confidence or reputation.”

“Accenture’s own slogan ‘Make every part of your business more resilient’ should ring loud in their halls. Being cyber resilient does not necessarily mean that a company won’t get breached, but it means that – should it happen – the company learns from the event to become better. Accenture can do more in this by sharing as much detail about the attack as possible.”

Importance of Intrusion Detection System in Cybersecurity

Intrusion detection system (ids)

As businesses shift to distributed environments, the threat landscape gets broader, and hackers are now shifting their focus to attacking the systems of remote workers. In this context, the importance of an intrusion detection system or IDS becomes more important than ever, in protecting endpoint devices and enterprise networks from sophisticated attacks. This article will shed light on the different types of intrusion detection systems and why it is beneficial for ethical hackers to use IDS to detect anomalies and minimize cyberattacks.

An Intrusion Detection System (IDS) is an application to detect suspicious activity on network traffic. Also known as an Intrusion Prevention System, it is widely used to identify suspicious or unknown malware activities on a protected asset. It is not impossible for hackers to penetrate networks; therefore, intrusion detection system importance is paramount here. Traditional enterprise systems and organizations can benefit from IDS to improve their security controls and protect their network environment.

IDS gathers and analyzes malicious actions before reporting them to the system administrator and other users. It can also be stored in a Security Information and Event Management System (SIEM).

Let’s understand a bit about the functions and types of intrusion detection systems below.

Functions of an Intrusion Detection System

IDS serves three main functions: detecting anomalies, reporting potential threats, and blocking traffic using two methods – Signature-based detection and Anomaly-based detection.

1. Signature-based IDS

With the rise in cyberattacks, it is wise to safeguard your personal or business network from malware, viruses, Trojans, etc. Signature-based detection is a popular technique to detect and identify suspicious software or malware attacks in your system. It analyzes inbound network activity and looks for known fingerprints (signatures) or vulnerable patterns in the signature database, also known as attack signatures. Antivirus developers use Signature-based IDS to detect suspicious activity in the system files or database. However, it cannot detect unknown suspicious activity.

2. Anomaly or Behavior-based IDS

Anomaly-based IDS is more effective than signature-based detection systems. Unlike signature-based, the anomaly-based detection system can monitor and analyze significant network traffic and data to detect anomalies. It does not rely on known signature attacks to identify potential threats but looks for behaviors that could be a threat or attack. Therefore, there are higher chances of identifying and lowering the risks of malicious attacks. Anomaly-based IDS monitors network traffic with the help of AI (Artificial Intelligence), statistical models, and machine learning to safeguard your network.

Types of Intrusion Detection Systems

IDS is a great way to protect your businesses’ network environment from cyberattacks. Network-based and host-based intrusion detection systems are the two major classifications of an Intrusion Detection System.

Let us unravel these two types in detail.

1. Network-based Intrusion Detection System (NIDS)

Network intrusion detection systems keep track of all traffic coming in and out of the network. The tool can look for threats and identify potential intrusions from within the network. It can also warn the administrator of the potential risks and block the source from accessing the network.

The NIDS analyzes the traffic to spot trends and strange actions, after which a warning is given. When a port scanner is used on a network that is protected by an IDS, it is highlighted and further investigated in ethical hacking.

A few advantages of NIDS include:

  • Relatively safe from direct attacks as hackers may be unable to trace it.
  • Faster than a host-based detection system.
  • Helpful in detecting internal and external threats or attacks.

A few disadvantages of NIDS include:

  • Cannot read or identify encrypted data.
  • Chances of false positives are high.
  • Time-consuming as it monitors a large volume of data.

2. Host-based Intrusion Detection System (HIDS)

A host-based intrusion detection system (HIDS) analyzes entire system activity, including application logs and system calls. It differs from NIDS in this regard – while NIDS monitors network behavior, HIDS monitors all system activity. HIDS looks for both internal and external threats in your system. They can locate or identify known signatures or malicious patterns that are a threat to your network security, either generated by people or software. If someone tries to log into another’s computer or tamper with someone’s files or data, HIDS can be helpful to detect anomalies. It can capture snapshots of the machine’s data and in running processes and can generate an alert if they are altered over time; HIDS examines change management in operating system files, logs, software, and other areas.

A few pros of a Host-based IDS include:

  • Encrypted data is also accessible.
  • Detects anomalies by focusing on systems/devices.
  • Can identify both internal and external activities.

 A few cons of Host-based IDS include:

  • Substantial risk of false positives.
  • Tedious and time-consuming process.
  • Chances of network traffic congestion.

Based on your network size, you can choose to use NIDS or HIDS for your organization.

Conclusion

These days, intrusions are quite common, owing to the growing cyberattacks and increasing vulnerabilities in network security. Therefore, companies are using several techniques to monitor IT security lapses and intrusion to mitigate cyberattacks. If you are interested in building a career in this domain, you need to get certified in ethical hacking training programs.

EC-Council’s Certified Ethical Hacker (CEH) program is beneficial for cybersecurity professionals and aspiring participants to learn ethical hacking concepts and deploy IDS techniques to prevent cyberattacks. While IDSs can recognize internal and external risks, hacking intrusion prevention systems are also relatively easy with the various hacking tools available. An ethical hacker must have the knowledge to prevent malicious hackers from hacking intrusion systems and bring down potential threats. There is also substantial risk of false positives and false negatives arising out of network IDS. The CEH course aims to help aspirants and professionals understand and detect intrusions in a network, system, or application and equip them with the skills needed to eliminate false positives.

The ethical hacking training and course module is designed to prepare you to be a successful ethical hacker. By the time you finish your training in ethical hacking, you will be a trained, ethical hacker and have learned to scan, test, hack and secure your networks and system from intrusion.

20+ Job Roles | 10,000+ Job Openings | Avg. Salary of $93,000

Become a Certified Ethical Hacker


FAQs (Frequently Asked Questions)

1. Name the different types of intrusion detection systems?

While there are several types of IDS, there are four main ones, namely:

  • Network intrusion detection system (NIDS)
  • VM based Intrusion Detection System (VIDS)
  • Perimeter Intrusion Detection System (PIDS)
  • A host-based intrusion detection system (HIDS)

2. Why is an Intrusion Detection System needed?  

Your device or your network’s environment is prone to external or internal intrusions more than ever. Therefore, companies can install IDS to detect hackers or prevent malicious malware. It is a crucial element of a network’s security and understanding of ethical hacking. Moreover, it identifies the known signatures or attack signatures and can notify the administrator of unknown threats.

3. Is a firewall an IPS (Intrusion Prevention System)?  

While both firewall and IDS/IPS are core elements of a Network, both have primary purposes. The primary function of a firewall is that it blocks traffic or filters traffic based on network information. In comparison, IDS/IPS identifies or detects anomalies and prevents unforeseen attacks.


References:

  1. https://www.makeuseof.com/how-host-and-network-based-intrusion-detection-systems-work/
  2. https://www.sciencedirect.com/topics/computer-science/network-intrusion-detection-system
  3. https://www.techopedia.com/definition/12941/network-based-intrusion-detection-system-nids

7 in 10 Organizations in India Likely to Suffer a Data Breach Next Year: Report

Credential Abuse Attack, credential harvesting campaign

Enhancing security defenses with a robust incident response plan is the only way to become immune to data breaches. From trading in darknet forums to misuse for extortion activities, threat actors leverage stolen/compromised sensitive information in multiple ways. According to a recent analysis from Trend Micro, nearly 73% of organizations in India are likely to suffer a data breach in the next 12 months. In its latest Cyber Risk Index (CRI) report, Trend Micro revealed that lost IP, critical infrastructure damage, and cost of outside experts are the major consequences faced by Indian organizations after a data breach.

Key Findings:

  • 57% of businesses admitted that they are very likely to suffer serious cyberattacks next year
  • 34% of organizations stated they suffered more than seven cyberattacks that infiltrated their network systems
  • 20% had more than seven breaches of information assets
  • 30% of respondents said they’d suffered more than seven breaches of customer data over the past year

The findings are based on the responses of 3,600 businesses of all sizes and industries across Asia-Pacific, North America, Europe, and Latin America.

“We’ve found plenty to keep CISOs awake at night, from operational and infrastructure risks to data protection, threat activity and human-shaped challenges. To lower cyber risk, organizations must be better prepared by going back to basics, identifying the critical data most at risk, focusing on the threats that matter most to their business, and delivering multi-layered protection from comprehensive, connected platforms,” said Vijendra Katiyar, Country Manager, India & SAARC, Trend Micro.

Top Cyberthreats

According to the report, the major security risks reported in India include:

  • Ransomware
  • Watering hole attacks
  • Botnets
  • Malicious insiders
  • Advanced persistent threats (APT)

While cloud computing remains the top infrastructure risk, the report revealed that malicious/negligent insiders, cloud computing providers, organizational misalignment, and complexity are the top security risks to organizations’ network systems.

What’s lacking?

Other security challenges faced by organizations include:

  • Lack of sufficient knowledge among security personnel
  • Shortage of skill and expertise to protect data assets and IT infrastructure
  • IT security function complying with data protection and privacy requirements

For years, data breaches have been a severe threat to organizations’ critical infrastructure. Though they are inevitable, organizations must boost their security defenses by identifying loopholes in the systems and deploying multi-layered protection to defend against potential security incidents.

Related Story:

Suffered a Data Breach? Here’s the Immediate Action Plan

NCSC for Startups Initiative will Address U.K.’s Cybersecurity Challenges

NCSC for Startups Initiative

Bringing the technical expertise of both public and private organizations will help mitigate security gaps and boost the overall cybersecurity posture in the country. In an effort to resolve the cybersecurity challenges posed by the nation’s critical infrastructure, the U.K. government has launched the National Cyber Security Centre (NCSC) Startups initiative.

NCSC for Startups

NCSC for Startups is a cyber accelerator program that involves onboarding cybersecurity startup companies for technical collaboration and better outcomes. The new initiative is a cooperation between the NCSC and Plexal, with additional partnerships with CyNam, Deloitte, Hub8, and QA.

NCSC for Startups will aid new firms with established cybersecurity solutions, which are looking to expand their reach into new markets and support the NCSC’s mission to make the U.K.’s digital space secure. The initiative will also:

  • Shape technical challenges to focus on areas of interest
  • Work together and directly with startup companies to influence their products
  • Provide technical leadership and influence to encourage the growing cyber eco-system

The NCSC has selected five cybersecurity innovators to work with the U.K.’s cybersecurity experts to address the most prevalent cyberthreats in the country. The first five startups are:

  1. PORGiESOFT – The EdTech startup offers cyber fraud detection services for enterprise employees
  2. Exalens – Provides inexpensive threat detection services
  3. Enclave – Helps organizations in creating Zero Trust overlay networks
  4. Meterian – Provides a sustainable line of defense for apps that use open-source software
  5. Rebellion Defense – Leverages AI to defend national security systems against threats like ransomware

The selected startups will receive direct support from the NCSC’s experts and Plexal’s cyber innovation team to obtain wider technical and commercial opportunities with the industry partners across the U.K.’s cybersecurity ecosystem.

Commenting on the new initiative, Chris Ensor, NCSC Deputy Director for Cyber Growth, said, “The U.K. has a thriving cybersecurity industry. Finding great ideas that can help protect all areas of society is a key part of our mission and we look forward to collaborating with more startups as the program rolls on.”

“The NCSC understands the U.K.’s cybersecurity challenges better than anyone, and the opportunity for innovative startups to benefit from its world-class insight and expertise is unique. Combined with Plexal’s extensive track record in supporting startups to become market leaders, NCSC For Startups will help companies address some of the most challenging security problems facing the government, businesses, and society now and in the future,” said Saj Huq, Director of Innovation at Plexal.