Home Blog Page 68

Top Cybersecurity Rule: Don’t Put Your Business at Risk

CISO, Cybersecurity

No company wants to put its business at risk. Indeed, we all strive for success, while continually trying to mitigate risk. The key to enabling this lies in protecting and preventing cyberattacks on networks, devices, applications, and data.

By Mucteba Celik, Chief Technology Officer, RevBits

Driving forces, like multi-cloud, SaaS, mobility, and IoT, are causing enterprises to transition away from inefficient and complex legacy security architectures. Traditional solutions add high operational overhead and management complexity. Modern business networks are enabled by diverse security capabilities that can be delivered on-premises or as cloud services, that centrally manage and control the network edge. Today’s extended perimeter requires multi-layered security and a Zero Trust model to protect data, applications, endpoints, and networks – regardless of location.

Secure digital transformation is a business imperative

There is nothing conventional about today’s digital business transformation. The longer an enterprise holds on to strict traditional network perimeter confines, the greater their security risk, and their inability to compete with more technically agile companies. While enterprises can’t control the unsecured nature of the Internet, they can control and secure access to applications and systems that collect and store customer data and corporate secrets. A perimeter-less network means organizations can no longer rely upon a trust model. The identity of every user, device, and location must be verified and given authorization before allowing access.

Conflating multi-layered security capabilities

As digital infrastructure margins expand and edge intelligence increases, we must encrypt data and authenticate and authorize all users and devices. Secure access to network-connected assets is a requirement for true digital business transformation. A secure foundation for digital transformation requires a cohesive, unified, and user-friendly platform that supports security and privacy integrated throughout.

To accomplish this requires an integrated multi-layered security platform. This enables IT and security teams to support efficient, reliable, and secure on-premises and cloud services. All platform security functions can be viewed, automated, and managed through a single dashboard, enabling the flexibility to secure applications and services at scale.

Having a single view into everything, including identity, applications, and endpoints enable the governance needed through an integrated digital infrastructure with controlled access. A Zero Trust security model is key to enabling this, with advanced access controls across clouds, on-premises, hybrid, and mobile environments. Leveraging identity, by automatically authenticating and authorizing access based upon business policies, gives enterprises the control they need to protect their digital assets.

Don’t lose sight of your expanding business perimeter

Business success is no longer judged by the size of the walls that contain it. Software is breaking down walls, eliminating restrictive perimeters, and providing a secure and more risk-averse foundation of flexible, low-cost, simplified, and consolidated infrastructure. Today’s successful businesses are running faster than ever before and being driven by software that makes them fleet of foot and agile in execution.

An integrated software-based architectural approach, with capabilities like email security, endpoint security, identity management, deception technology, and ZTNA (zero trust network access), significantly increases an organization’s security posture. It closes security gaps, improves performance, and eliminates the need for multiple physical appliances.

These capabilities enable enterprises to extend their network perimeter, without gaps between siloed security functions. This simplifies and automates the creation, delivery, management, and operations of diverse security services, including configurations, policy, certificates, etc.

This software model requires a security platform that can abstract business advantages from the underlying infrastructure. One that can cross-pollinate security policies, unifying them with visibility across multiple domains, business units, locations, users, and devices. These are the requirements for securing today’s digital enterprise.


About the author

Mucteba Celik Mucteba Celik is RevBits‘ Chief Technology Officer. With over 15 years of experience in cybersecurity and development, he designed, architected, and led the development efforts of RevBits products, which utilize five of his patents. Mucteba is a hands-on and highly experienced cybersecurity leader with numerous advanced certificates, including GXPN, GREM, GCFA, OSCP, OSCE, etc. For many years Mucteba analyzed malware, cyberattacks, state-sponsored attackers, and cybercriminal behavior, and in parallel, he analyzed cybersecurity products, and their vulnerabilities and shortcomings. Overseeing more than 60 developers at RevBits, he has created a suite of innovative and effective security products that make cyberspace safer for enterprises.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Implementing Digital Forensics in Emerging Technologies

digital forensics

Technology is progressing at an astounding rate, and while at it, it is also connecting the digital world in a way never seen before. Implementation of technologies such as the Internet of Things (IoT), cloud computing, etc. has changed the way data is being processed and stored. But it is well-known that the advancement in technology is always followed by associated cybersecurity risks as their interactions with existing technologies, platforms, and people is not very well understood during its inception. Hence, it is has become essential for cybersecurity professionals to look into every aspect of security and also consider the impact of emerging technologies on business operations.

Cyber/digital forensics, without a doubt, has become an integral part of the cybersecurity domain, and the increasing cyberattacks have made everyone take the security of their digital assets more seriously. The role of Digital Forensics (DF) in the security architecture is to examine the incidents and detect the digital footprint left by the attacker. The DF aims at identifying vulnerabilities that were missed by multiple layers of deployed security. Like any other domain of cybersecurity, digital forensic is also susceptible to the impact of emerging technologies. It could be said that cyber forensics is continuously evolving in the digital landscape due to developing technologies and their implementation into cybercrime by threat actors.

digital forensics whitepaperIt has become imperative for the DF community to look at these issues and develop its assets, scope, and policies to overcome these challenges, and we believe that the best possible place to start the development of DF is the corresponding education programs. From the perspective of cybersecurity education in digital forensics, this survey attempts to gauge the upcoming challenges that will arise upon the deeper integration of digital forensics with these technologies. By understanding the challenges faced by the forensic community during the investigations involving trending technologies and developmental features, a curriculum could be constructed around it to further the understanding of the students/aspirants and make them forensic-ready for all existing and potential challenges.

The CISO MAG study not only highlights the challenges of incorporating digital forensics in emerging technologies such as IoT, could, etc., but also shed light upon the existing branches of digital forensics such as malware forensics, databases forensics, browser forensics, dark web forensics, etc., which are either seeing development in some of their aspects or the overall change brought due to their implementation into an evolving digital landscape.

digital forensics surveyTo better understand the challenges and state of readiness in implementing Digital Forensics in emerging technologies,

French Organizations on APT31 Group’s Radar

Patchwork BADNEWS, APT31 threat group

Like ransomware attacks, cyber espionage campaigns are fatal and can cause irreparable damage to enterprise IT security perimeter. Government and organizations must enforce robust security measures to identify cybercriminal operations before they exploit a company’s security architecture.

Recently, the French National Agency for the Security of Information Systems (ANSSI) warned organizations about a China-linked threat actor group APT31. In a security advisory, the ANSSI stated that the APT31 group is leveraging compromised home routers to break into targeted organizations’ networks. The ANSSI shared the list of Indicators of Compromise (IoCs) and IP addresses of the ongoing campaign and urged the affected organizations to report any evidence of the campaign.

“ANSSI is currently handling a large intrusion campaign impacting numerous French entities. Attacks are still ongoing and are led by an intrusion set publicly referred to as APT31. It appears from our investigations that the threat actor uses a network of compromised home routers as operational relay boxes to perform stealth reconnaissance as well as attacks. As such, indicators of compromises (IOCs) are shared to help assess possible compromises (searches should start at the beginning of 2021) and used in detection services,” said the ANSSI.

Is APT31 Unstoppable?

Also tracked as Zirconium, Red Keres, and Judgment Panda, the APT31 group has been reportedly involved in various cyberespionage campaigns linked to the Chinese government. Ben Koehl, a threat analyst at Microsoft’s Threat Intelligence Center, stated that the IP addresses shared by the ANSSI are mostly located in Africa, Asia, Russia, and Latin America.

“ZIRCONIUM appears to operate numerous router networks to facilitate these actions. They are layered together and strategically used. If investigating these IP addresses they should be used mostly as source IP’s but on occasion, they are pointing implant traffic into the network,” Koehl added.

Cybersecurity in France

The French government is making constant efforts to boost the country’s cybersecurity standards and defend against evolving threats. From enhancing the security practices to penalizing the violators, the French data privacy regulators have always prioritized user data security. Recently, the French Competition Authority (FCA) fined Google €220 million (approximately $268 million) for abusing its dominant position in the advertising market and favoring its services at the expense of its competitors. Read More Here

This Flaw in HP, Xerox and Samsung Printer Drivers Went Unnoticed for 16 Years

HP multi-function printers, Unpatched vulnerabilities

Unpatched vulnerabilities are no less than potential cyberattacks. They might blow up the company’s security defense at any time. While some unpatched flaws get identified and addressed during regular security audits, some are left behind until hackers find and exploit them. One such unpatched vulnerability, which went unnoticed for 16 years, was identified by cybersecurity researchers from SentinelOne.

Tracked as CVE-2021-3438, the buffer overflow vulnerability has existed in a common printer driver SSPORT.SYS file. used by popular printer manufacturers like Xerox, HP, and Samsung.

The Impact

The researchers found that the vulnerable driver gets installed when running the printer software, enabling an attacker to target the computer without a printer. The vulnerable driver accepts data via IOCTL (Input/Output Control) without validating, allowing hackers to evade the buffer used by the driver.

“An interesting thing we noticed while investigating this driver is this peculiar, hardcoded string: ‘This String is from Device Driver@@@@’. It seems that HP didn’t develop this driver but copied it from a project in Windows Driver Samples by Microsoft that has almost identical functionality; fortunately, the MS sample project does not contain the vulnerability,” SentinelOne said.

If exploited successfully, the vulnerability could allow threat actors to perform various malicious activities such as install malicious programs, access, alter, encrypt, delete data, or create new accounts. It could also allow the attacker to obtain elevated privileges on the targeted system, affecting millions of printers and users across the globe.

Mitigation

SentinelOne claimed that the vulnerability affects over 380 different HP and Samsung printer models and 12 Xerox products. The flaw was identified and reported to HP in February 2021. Immediately, HP released a security update in May 2021 to address the vulnerability.

The researchers urged both enterprise and individual users of HP/Samsung/Xerox to apply the patch mentioned in HP Security Advisory HPSBPI03724 and Xerox Advisory Mini Bulletin XRX21K as early as possible to avoid potential risks.

Abuse of Unpatched Bugs is Inevitable

While there is no evidence that CVE-2021-3438 flaw has been exploited in the wild, researchers warned that attackers could still abuse the unpatched and vulnerable devices. Recently, Microsoft warned about a zero-day vulnerability in Windows Print Spooler code. Dubbed as PrintNightmare, the remote code execution (RCE) flaw (CVE-2021-34527) could allow a remote hacker to disrupt the Windows Print Spooler operations. The tech giant stated that all versions of Windows are vulnerable to exploitation. Read More Here

Saudi Aramco Hit by Cyberattack; Adversaries Demand $50Mn in Cryptocurrency

Superior Plus, Saudi Aramco data breach

Businesses shy away from disclosing security incidents. And some companies only reveal after sustaining the damages.  Recently, Saudi Arabia’s state oil giant Saudi Aramco confirmed that it has suffered a data breach that exposed some of the company’s files via third-party contractors.

Saudi Aramco stated that it “recently became aware of the indirect release of a limited amount of company data which was held by third-party contractors. We confirm that the release of data was not due to a breach of our systems, has no impact on our operations and the company continues to maintain a robust cybersecurity posture.”

Aramco did not reveal the name of the contractor that was affected, nor did it provide details about the information that was impacted in the security incident. The Associated Press reported that the attackers obtained over one terabyte (1,000 gigabytes) of Aramco data and exposed it on the dark web. While the operators behind this cyber extortion scam are currently unknown, they are allegedly demanding a ransom of $50 million in cryptocurrency to delete the data from the dark web.

Third-party Security is a Must

Speaking with CISO MAG, Dirk Schrader, Global VP of Marketing at Netwrix, said that the security of third-party contractors can’t be ignored when they are holding the company’s confidential data and networks.

“While keeping in mind that most of the details about this breach are unconfirmed, only its mere existence is confirmed yet, the list of data points in the trove provided by the threat actor is worrying. Information about employees, with full details of about one-fourth of all of Aramco’s workforce, is a collection that can’t be ignored by cybercriminals using spear-phishing tactics or attempting some type of business email compromise, which in itself is supported by additional pieces of information in the trove like invoices and contracts. Overall, the potential risk related to this breach cannot be ignored by Saudi Aramco,” Schrader added. “Aramco might be correct to state that its cybersecurity is robust and that it has not experienced an impact to its operations – so far. The trove seems to hold enough information to change that verdict.”

This is not the first time Aramco suffered a cyberattack. The oil giant was hit by the infamous Shamoon malware in 2012, which deleted data from the company’s hard drives and forced it to shut down its operations by affecting over 30,000 systems.

Energy Sector Become a Frequent Target

Ransomware attacks on organizations in the energy sector have become more prevalent in recent times. From power-grid to fuel pipeline operators, hackers often target critical sectors to cause massive disruption to services and threaten them to expose the data if the ransom is not paid. Recently, the Colonial Pipeline in the U.S. reportedly paid over $4.4 million in ransom after ransomware operators encrypted its systems.

Over 80 U.S. Municipalities Suffer Data Breach via Misconfigured Amazon S3 buckets

Data breach in 100 U.S. cities

Whether it’s accidental or hacker intrusion, data breach incidents affect an organization in multiple ways. It could lead to severe security risks if the leaked data is misused or abused by threat actors. Cybersecurity researchers from WizCase, a web security platform, recently uncovered a massive data breach affecting 80 U.S. municipalities.

One Target, Multiple Victims

As per the investigation, the data breach affected users in over 100 U.S. cities that used “mapsonline.net” from the web service provider, PeopleGIS, to manage user information. PeopleGIS had reportedly stored the data of users in several misconfigured Amazon S3 buckets without proper encryption, exposing it to open access. The exposed information includes citizens’ addresses, contact details, IDs, photographs of individuals, photographs of properties, building and city plans, driver license numbers, tax documents, and other sensitive data.

Out of 114 buckets, 28 appeared to be properly configured, and 86 were accessible without any authentication, accounting for 1000 GB of data and over 1.6 million files.

“Some of the vulnerable documents were redacted, but they were digitally redacted using transparent tools like a marker. This means whoever found them could change the contrast level of the document in a photo editor and see the redacted information. This means even documents that were redacted were potentially vulnerable in this breach,” WizCase said.

While the number of users impacted in the incident is unknown, PeopleGIS stated it secured the vulnerable buckets immediately after WizCase reported the issue.

Reason Behind Misconfiguration

WizCase’s investigation revealed multiple reasons due to which the buckets could have become vulnerable online. PeopleGIS handed over the buckets to all municipalities, without proper configuration. As a result, the buckets were configured by different employees with no clear guidelines on the configuration and some were configured by municipalities themselves with PeopleGIS guidelines.

Data Breach Impact

Most of the exposed data is supposed to be accessed only by government authorities; however, this data leak could affect the residents of the municipalities in different ways. The personally identifiable information (PII) exposed in the breach could allow cybercriminals to launch various cyberattacks, including phishing, financial frauds, identity thefts, and file manipulation attacks. They may encrypt files in the bucket storage and demand ransom.

“Cloud-based backup is revolutionizing data protection”

Milind Borate, Druva, CISO MAG exclusive interview, cloud backup

In the current scheme of things, saying, “ransomware attacks are on the rise” is an understatement. Ransomware attacks exploded eight months ago, targeting U.S. hospitals, followed by attacks on critical supply chains of Colonial Pipeline, JBS, and Kaseya. These surgical attacks have crippled businesses and have even forced some to pay up for restoring operations at the earliest. Governmental organizations, however, are not in favor of this for two reasons: Firstly, it does not guarantee the victim any delivery of a decryption key for unlocking data, and secondly, paying ransom boosts the morale of cybercriminals’ to carry out even more malicious operations in the future.

Ransom money is not the only loss that victims of ransomware attacks face. Operational downtime is what hurts businesses most in the aftermath. As per reports, the average downtime experienced by businesses due to a ransomware attack in the year gone by is 23 days, costing them an average of $60,000 daily. To reduce these costs and get moving at the earliest, experts say having a comprehensive and continuous air-gapped backup is one of the best solutions available. To discuss this in detail, Mihir Bagwe, Senior Technical Writer at CISO MAG, interviewed Milind Borate, Co-founder and Chief Development Officer at Druva, to understand the nuances and intricacies of ransomware incident response and the critical role of cloud backups.

Borate has more than 20 years of experience in enterprise product development and delivery. Prior to co-founding Druva, he worked at Veritas Software as Technical Director for SAN-FS and served on the board of the Veritas patent committee. Borate holds several patents in storage technology and co-authored the book “Undocumented Windows NT” in 1998. His current areas of interest are cloud storage and machine learning for unstructured data. Borate is passionate about building engineering teams that deliver end-to-end solutions, and his favorite past-times is philosophizing on software development.

Edited excerpts of the interview follow:

Ransomware attacks have been around for a while now. What factors do you think have contributed to its sharp rise in the recent past?

Over the past year, enterprises have experienced an unprecedented number of ransomware attacks. More sophisticated cybercriminals are emerging every day, seizing networks and infrastructure across vulnerable remote workforces and infrastructures. As a result, many businesses are suffering the dire consequences of its effects, resulting in a loss of time, money, and data that can never be recovered. The frequency of these attacks has made it crystal clear that we are facing an entirely new threat landscape that is far more sophisticated and destructive.

Our team at Druva has observed that the increased vulnerability of businesses to ransomware during the pandemic is a result of:

  •  SaaS applications  With the emergency of WFH, more people are using SaaS applications now than ever, from messaging to documents, etc. Thus, it is imperative that sensitive communication complies with all regulations and is retailed as business-critical information.
  •  Cloud-native applications  Cloud platforms allocate new infrastructure quickly and easily. Without experience with the platform, however, users can also quickly expose private data, overrun budgets, and lose data. Cloud environments need oversight.
  •  Endpoints With the blurred lines between personal and professional environments, people can download ransomware on their laptops and infect their organizations. They can also download and unintentionally expose private data. Endpoint devices must be secured and protected.
Reports suggest that the average downtime following a ransomware attack is 23 days. If the average downtime is so high, do you think businesses are still not indulging in taking basic measures like data backup? Is there a more comprehensive approach to it?

As we reflect on the last 12 months, the IT landscape has changed significantly; be it from changes to the way we work and accelerated digital transformation journeys to an onslaught of ransomware attacks and rising cyberthreats. While these changes have tested the resilience of businesses worldwide, it has placed the spotlight on cloud-based solutions, especially services like data protection and management.

As operations and everyday enterprise applications move online, the cloud’s ability to deliver air-gapped data protection whilst improving business resiliency with on-demand scalability makes it the ideal choice. With the threat of ransomware on the rise, the rapid expansion of endpoints and cloud-based collaboration tools like Microsoft 365, Salesforce, and Google Workspace must be met with the right level of protection to safeguard against increasing risks. And now companies are beginning to explore next-generation workloads like Kubernetes. As businesses seek to support a digital workforce and move their business forward, the key to success will be in recognizing how the industry has evolved and the gaps which may have been overlooked in the rush to complete projects.

As we have surged the deployment of SaaS applications, data protection is often an afterthought, which increasingly has come back to haunt organizations. Data is being saved in more places than ever and businesses need a holistic approach that offers visibility across all these environments. A robust approach to data resiliency that includes detection, remediation, and recovery is critical to maintaining business operations. This includes utilizing a backup architecture that enables rapid recovery with agility and confidence.

According to CISO MAG’s Data Security report, the majority of businesses still prefer a hybrid backup strategy. Do you think this will remain prominent, or with a wider acceptance and integration of the cloud, cloud-based backup will gain momentum?

Cloud-based backup is revolutionizing data protection. It has become a compelling value proposition for every company looking to prevent potentially catastrophic data loss, from SMBs to corporate enterprises and everything in-between. Cloud-based backup and recovery is the obvious solution to expensive conventional enterprise data protection schemes, and it is also very useful for typically unprotected smaller firms with limited budgets.

The outbreak of the COVID-19 pandemic has led to a surge in businesses adopting the cloud as it is a bridge to the digitization and getting workforce, distribution, supply chain, etc., online. In the last several months, we have seen years’ worth of digitization take place. A natural affinity to cloud-based data protection is developing in the process as businesses look for technology that can help them scale efficiently, minimally impact employees, improve business resilience, and can be deployed easily within today’s restrictive work environment.

Fair enough, but hybrid and on-premises backup strategies are costlier because of logistical issues. And with ransomware gangs now targeting even SMBs through supply chain attacks, do you think cloud-based backup solutions are still a viable option for the smaller counterparts?

Small and medium companies struggle with the challenges of effective backup and recovery because they often lack the IT resources that are required to manage a comprehensive data protection platform. Despite the affordable cost of protecting data in the cloud, most SMBs have ignored the benefits of backing up their data in the cloud and risk losing valuable data to ransomware attacks and other bad actors.

The cloud provides SMBs with significant business value. Although it can be difficult to know where to start or what to prioritize, SMBs must invest in cloud solutions that allow them to extract more value out of their data. When SMBs extract more value from their data, they uncover new business opportunities, generate more revenue, and achieve their goals. Data-driven SMBs can get ahead of the curve by optimizing operations and predicting future trends.

When you talk about cloud-based backup solutions, how does this help in ransomware protection and/or recovery?

Ransomware has become more sophisticated, evolving from encrypting data to deleting backups to now extracting copies of data, which increases the potential damage to your organization. This is where cloud-based backups and protection come in.

As the number of threats targeting data and applications continues to grow, reliance on prevention measures alone is insufficient. Customers need to have new and improved ways to prepare for and respond to incidents, including better visibility, automation, and orchestration.  For this, customers should be able to leverage multi-layered ransomware protection and recovery to defend against data loss, accelerate incident response, and simplify recovery, so they can reduce downtime.

Cloud-based backup and recovery is a crucial line of defense against ransomware. Having secure backup images of critical business data and applications allows companies to roll back in time to recover applications and data before the point of ransomware infection. When integrated with existing security information and event management (SIEM) and security orchestration, automation, and response (SOAR) tools, air-gapped backups become the foundation for rapidly and securely recovering from ransomware attacks with enhanced capabilities.

What are the top three suggestions that you would like to give businesses in terms of resilience against ransomware attacks?

The top three suggestions that I would give businesses for improving their resilience against ransomware attacks are:

  1. Security must be embedded into the business’ culture. This means prioritizing security and ensuring that security experts are involved in critical business decision-making from an early stage. It also means taking the time to train employees on security best practices to ensure a more cyber-aware workforce.
  2. To ensure cyber resiliency, a business must implement a holistic security strategy that incorporates both protection and recovery. This includes deploying protective measures that can keep threats out and empowering resilience to minimize downtime when (not if) a ransomware attack happens.
  3. Security awareness should be a constant process. It must be more fluid and continuous throughout the entire year. Organizations should aim to promote security awareness throughout the year, after all, malicious actors are always trying to find ways to harm your business. In information security, we often say it is the weakest link that can have the biggest impact; it is important to focus on cybersecurity throughout the year to help your teams align their security priorities.
About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Sr.Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity news, tech, and trends.

 

Risk-based Vulnerability Management – Time to Move Away From the Whack-a-Mole Model

actively exploited vulnerabilities, Vulnerabilities, risk-based vulnerability management

Technologies like AI, ML, and IoT are experiencing explosive growth in the digital world. But do you know what is the source of inspiration for these disruptive technologies? Sci-fi books and movies. An  example of IoT’s influence can be found in the 1977 classic film “Demon Seed.” The movie plot revolves around the AI-based computer ‘Proteus IV,’ which was developed by the male protagonist, Dr. Alex Harris. The AI-based computer initially works exceedingly well, but soon things get out of hand as it falls for its creator’s wife, Susan. Proteus IV downloads itself on the home computer and virtually controls all devices, from lights and locks to bells and alarm systems. Sounds like today’s smart home, right?

The movie might have inspired people to design futuristic smart homes nearly five decades later, but the creators of the modern tech seem to have forgotten essential learnings from it – implementing a risk-based approach. Dr. Harris only concentrated on innovation without considering the possibility that things might get out of control. Only after he learned about Proteus’ intentions, Dr. Harris realized his mistake. By then, it was too late.

By Doug Drew – Client Solutions Advisor, Americas, Optiv

 SPONSORED CONTENT 

Modern cybersecurity is treading in a similar space. Patching after something has happened or simply going after threats that are designated as high severity by a CVE Numbering Authority (CNA) is a whack-a-mole game.

The Vulnerability Management Whack-a-Mole

This seismic shift in recent times towards digital transformation due to factors like e-commerce, cryptocurrency, and COVID-19 has only increased the attack surface and, subsequently, the number of vulnerabilities that businesses are exposed to. Threat actors are feasting on these gaps by exploiting them to the fullest.

Everyone knows that an unpatched vulnerability is one of the most common causes of data breaches and security compromise. In fact, industry research has highlighted that 60% of breaches are linked to vulnerabilities left unpatched even after a patch was available. Who should we hold accountable for this challenge?

We need to understand that new vulnerabilities are found every day. Legacy scanning tools return hundreds or thousands of vulnerabilities in every scan. These numbers are overwhelming and stretch the capacity of already-stressed security teams to the limit, forcing them to simply prioritize their vulnerability management based on traditional CVSS severity levels.

Also Read: Risk Based Vulnerability Management – Let’s Begin With the “Why?”

The Delusional CVSS

Though useful, CVSS is essentially risk-unaware. Its theoretical value is based on algorithmic calculations, but it doesn’t consider the degree of threat or how it could be exploited in the wild. Worse, CVSS doesn’t even differentiate between business-critical and legacy, or general vulnerabilities. It simply rates a vulnerability as ‘critical’ or ‘severe’ and then security teams rush to patch them, often without the context of risk or criticality to the business.

With the explosive growth of known vulnerabilities and the growth of attack surfaces (phones, tablets, cameras, and other IoT devices), applying an understanding of the real-world basis for the possibility of exploit and the corresponding attendant risk becomes ever more important. According to Tenable research, attackers have a seven-day head start on remediation teams. This means that true visibility and speed of discovery are crucial to staying ahead of hostile threat actors. To take your game to the next level of vulnerability management, you need to implement a risk-based vulnerability management (RBVM) approach.

Why a Risk-Based Vulnerability Management Approach?

For organizations looking to improve remediation and lower risk exposure, or for organizations who are moving to cloud and/or IoT, new techniques are needed. This could mean agents for data acquisition, or API state retrieval from a cloud provider, or IoT-specific data acquisition tools. Ideally, all the vulnerabilities should be centralized and managed through a single console. This allows true enterprise-wide rationalization of exposure, and risk-based vulnerability management accomplishes just this.

Also, the RBVM approach answers the 4Ws and the H of vulnerability management:

  1. What is my attack surface?
  2. Which are the most critical assets?
  3. Where are the gaps?
  4. When can a vulnerability be possibly threatening?
  5. How will the said vulnerability impact my business?

To begin with, fixing unknown issues is nearly impossible. Thus, RBVM helps you first gauge the operational landscape, including traditional assets, mobile, web apps, cloud, container, IoT, and OT, to give total visibility into the corresponding threat landscape. Doing so, RBVM identifies the critical assets in your system’s periphery that, if exploited, could steamroll the entire business. Unlike legacy vulnerability management tools, RBVM adds asset criticality and, more importantly, probability of exploitation in the wild. Further, based on the impact of these vulnerabilities, RBVM prioritizes patching so that security teams don’t waste time and labor on something that has a low probability of being exploited.

Focus on the Vulnerabilities, Not the Severities

Legacy vulnerability management tools are reactive, focusing on traditional infrastructures, CVSS scores, and system silos. However, risk-based vulnerability management is a dynamic, proactive, and continuously evolving approach. Using forward-looking technologies powered by AI and ML allows your business to optimize, view, detect and automate your traditional vulnerability management processes all under a single roof.

Integrating risk-based vulnerability management into your business reaps significant benefits, and it’s easier than it probably sounds.

Want to learn more? Click here and talk to an Optiv representative today.

 

3 Steps to Boost Your Enterprise Cloud Security

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

Cloud computing has already revolutionized the way businesses operate. Several organizations jumped the bandwagon of deploying multiple cloud environments into their IT infrastructure. Organizations are using various cloud services to store confidential corporate data. According to a survey, nearly 90% of organizations use cloud services like Amazon Web Services (AWS), Microsoft Azure, and Google Cloud. Over 77% of businesses have been using at least one cloud application.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Cloud computing provides organizations flexibility in multiple processing services like server management, storage operations, and networking. However, organizations must keep a check on security implications associated with multiple cloud environments. This is where Cloud Security comes into the picture. Organizations must build robust cloud security policies to defend against evolving risks threatening cloud environments.

With the rise in digitalization and remote working conditions, organizations globally continue to adopt cloud computing services. According to the State of Cloud Security report, nearly 84% of IT professionals are concerned about safeguarding the security of cloud environments due to the distributed work environment.  To protect their cloud environments from sophisticated cyberthreats, many organizations increased their cloud security budget. As per a report, the global cloud security market is expected to grow from $34.5 billion in 2020 to $68.5 billion by 2025. Factors like advanced attacks on cloud computing systems and the need for compliance with data privacy regulations are driving the cloud security market.

Some of the notable cloud security risks are:

  1. Misconfiguration of on-cloud data systems
  2. Lack of adequate security while migrating to cloud
  3. Lack of Identity and Access Management (IAM) practices
  4. Account takeovers, DDoS, or insider threats
  5. Accidental data leaks

Steps to Enhance Cloud Security

Most organizations store enormous volumes of sensitive data on their cloud-based applications and systems. Robust security measures and policies to protect cloud environments must include:

1. Strong Authentication

Any information stored on the cloud ecosystem should be strongly encrypted to prevent unauthorized intrusions. Enable robust authentication/verification procedures like two-factor and multi-factor authentication methods to restrict illicit entries.

2. Limit Access

Not every employee in the organization needs access to the cloud. Limit the number of users accessing data and applications in the cloud to avoid misuse. Closely monitor the end-user activities and their log entries in the cloud applications and services. You can suspect any abuse of the data based on the user access behavior. Organizations can also deploy automated solutions to detect unauthorized entries into the cloud environment.

3. Avoid Misconfigurations

Several organizations have sustained inadvertent data breaches due to cloud misconfigurations. The misconfigured cloud storage services in 93% of cloud deployments led to over 200 breaches in the past two years, exposing more than 30 billion records. Not only manufacturers, but organizations and end-users also need to follow the required security precautions while configuring the servers. And as due diligence, companies should closely observe the life cycle of the server and update it as per the requirements.

In addition to these, organizations need to ensure their employees are aware of the basic cloud security practices. Train your employees on the different cloud environments your business is using, as improper use of cloud services may lead to irreparable security risks.

About the Author:

Rudra Srinivas

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

DevilsTongue – A New Spyware from Israeli Company Candiru

Candiru DevilsTongue

Not all malware variants are available on underground darknet markets. Some criminal syndicates design and supply them, especially for state-sponsored cyberattacks. In a recent investigation, security researchers identified new spyware created by Candiru (also known as SOURGUM), an Israel-based mercenary spyware vendor, to target Windows systems, iPhones, Macs, Android platforms, and cloud networks across the globe. The vendor is reportedly trading various cyberweapons to state-sponsored actors and government agencies in hacking-as-a-service packages.

Candiru’s DevilsTongue

A joint investigation by Citizenlab and Microsoft Threat Intelligence Center (MSTIC) identified the Windows spyware, tracked as DevilsTongue, exploiting two windows zero-day vulnerabilities listed as CVE-2021-31979 and CVE-2021-33771. If exploited, the vulnerabilities could give a remote attacker privilege escalation access by evading browser sandboxes and gain kernel code execution.

Microsoft has fixed the bugs in its July 2021 security update.

The spyware also targeted more than 100 victims, including politicians, journalists, academics, embassy workers, human rights activists, and political dissidents. Adversaries leveraged different browsers and Windows exploits to deploy malware on the targeted systems. They sent malicious single-use URLs to targets via messaging services like WhatsApp. Most of DevilsTongue’s victims are located in Palestine, followed by Israel, Yemen, Iran, Lebanon, Spain, the U.K., Turkey, Armenia, and Singapore.

Citizenlab stated that Candiru’s Windows payload poses a variety of features such as exfiltrating files; stealing cookies and passwords from Chrome, Internet Explorer, Firefox, Safari, and Opera browsers; and exporting all messages saved in messaging apps.

Microsoft claimed that it has implemented necessary security measures to protect its products from this highly sophisticated spyware.

“We have shared these protections with the security community so that we can collectively address and mitigate this threat. We have also issued a software update that will protect Windows customers from the associated exploits that the actor used to help deliver its highly sophisticated malware,” Microsoft said.

Candiru’s Corporate Structure  

According to Citizenlab, Candiru was founded in 2014 and is known to have changed its identity several times. While the company presently operates under the name Saito Tech Ltd., it has been functional under multiple identities, such as DF Associates in  2017, Grindavik Solutions in 2018, and Taveta in 2019. The company provides various criminal services like custom malware distribution and cyber espionage (computers, mobile devices, and cloud accounts) by keeping its operations, infrastructure, and staff identities in stealth mode. Candiru has clients in Europe, the Persian Gulf, the former Soviet Union, Asia, and Latin America.

The researchers found over 750 websites linked to Candiru’s spyware infrastructure, many of which impersonated several legitimate domains of social welfare and advocacy agencies like Amnesty International and Black Lives Matter.