Home Blog Page 69

Is Digital Forensics Possible in a COVID-19 scenario?

Digital Forensics

The COVID-19 pandemic has created havoc not just in the lives of people but also rocked the business world globally. With countries going into lockdown, businesses are today forced to adapt to the situation and operate remotely. With this, businesses are confronted with new challenges and threats. Although organizations around the globe have adopted the work-from-home operating model, this has opened doors to malicious cyberattacks. With the new working norms and companies accelerating their digital transformation, cybersecurity is now a major concern.

By Narendra Sahoo, Founder, and Director, VISTA InfoSec

While the entire world is focusing on health, the economy, and restoring normalcy, criminals are constantly capitalizing on the situation to stage a well-planned cyberattack. Not only does the incident of cyberattack have severe reputational, legal, operational, and compliance implications, it also severely impacts the forensic investigation. Speaking more on this, we have explained in the article the challenges of remote working, prerequisites to prevent incidents of the breach, the protocols to be followed in case of a data breach, and all the nitty-gritty of cyber forensics. The article provides insight on the impact of remote working on cybersecurity, and the process of cyber forensics in case of a breach.

What happens in Cyber Forensics?

Handling a data breach incident in a normal scenario is very different from the current situation for both the organization and the cyber forensic team. Before the pandemic, when businesses were running in a controlled environment, even in case of a data breach, immediate response, measures to contain, and investigations helped lower the impact. However, now in the pandemic situation, with the remote working model, the situation is completely different. Not only has this increased the risk of a cyberattack, but it has also hampered the process of investigation and containing the situation in case of a data breach. But, before we get into the details of the challenges faced in cyber forensics during the pandemic, let us first understand the process of a cyber forensics investigation.

Cyber Forensics Investigation

Before the pandemic, when a data breach incident occurred, organizations had to follow a specific protocol to respond and contain the incident. With that, a cyber forensic team investigates the situation at the location and helps the organization respond, recover and resolve the incident. The process of handling the incident involves two primary steps which include:

  •  Responding and Containing Incidents
  • Investigating the Incident and Collecting Evidence

While the approach taken by the organization may vary based on their priorities, severity of the incident, and impact of the incident, there are certain basic protocols organizations must follow. Given below is a list of protocols that organizations should follow in case of a data breach. Once there is a breach, the organization should follow a few essential steps immediately to limit the impact of the breach.

Protocol to be followed in a Data Breach Incident

Step 1: Survey the damage

Once the organization discovers the data breach incident, the Information Security Officer along with the designated information security team should conduct an internal investigation. This is to first determine whether an incident has happened and to access the impact of the incident on critical business functions. They further need to conduct an in-depth investigation to identify the attacker/source of the attack, discover the exploited security vulnerabilities, identify immediate steps that can be taken to limit the loss, and determine steps for resolution and improvements. If an attack is confirmed, it is well advised to hire external professionals to investigate and take steps…To read the full story, subscribe to CISO MAG.

This story first appeared in the June 2021 issue of CISO MAG.


About the Author

Narendra SahooNarendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the U.S., Singapore and India. Mr. Sahoo holds more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, and Compliance services. VISTA InfoSec specializes in Information Security audit, consulting, and certification services which include GDPR, HIPAA, CCPA, NESA, MAS-TRM, PCI DSS Compliance and Audit, PCI PIN, SOC2 Compliance and Audit, PDPA, PDPB to name a few. The company has for years (since 2004) worked with organizations across the globe to address the Regulatory and Information Security challenges in their industry. VISTA InfoSec has been instrumental in helping top multinational companies achieve compliance and secure their IT infrastructure.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Schneider Electric Patches 13 Vulnerabilities Affecting its EVlink Charging Stations

Schneider Electric

Schneider Electric, an energy management and automation company, has reportedly patched 13 critical vulnerabilities in its EVlink range of products. The EV product range is associated with electric vehicles and offers charging points/stations for private properties, semi-public car parks, and on-street charging. Talking about the criticality of the discovered vulnerabilities,  Schneider Electric said that the exploitation of these vulnerabilities “could lead to things like denial of service attacks, which could (further) result in unauthorized use of the charging station, service interruptions, failure to send charging data records to the supervision system and the modification and disclosure of the charging station’s configuration.”

Schneider Electric Vulnerabilities and Affected Products

In all, Schneider Electric addressed 13 flaws, which include threecritical”, eighthigh” and twomedium” severity vulnerabilities. Schneider Electric further added that these vulnerabilities could be exploited by threat actors in only two ways:

  1. Physical access to the charging station’s internal communication ports which can be gained only by removing the entire housing, or,
  2. If the charging stations are directly connected to the internet or the network of the charging station’s supervision system (for remote exploitation)

The three most critical vulnerabilities and their respective CVE and CVSS scores are:

  1. Use of Hard-coded Credentials

CVE ID: CVE-2021-22707

CVSS v3.1 Base Score 9.4 | Critical

CWE-798: This vulnerability could potentially allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.

  1. Use of Hard-coded Password

CVE ID: CVE-2021-22729

CVSS v3.1 Base Score 9.4 | Critical

CWE-259: This vulnerability could potentially allow an attacker to gain unauthorized administrative privileges when accessing the charging station web server.

  1. Use of Hard-coded Credentials

CVE ID: CVE-2021-22730

CVSS v3.1 Base Score 9.4 | Critical

CWE-798: This vulnerability could potentially allow an attacker to gain unauthorized administrative privileges when accessing the charging station web server.

The other “high” and “medium” vulnerabilities are:

  • CVE-2021-22706 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’
  • CVE-2021-22708 – Improper Verification of Cryptographic Signature
  • CVE-2021-22721 – Improper Neutralization of Input During Web Page Generation (‘Stored Cross-site Scripting’)
  • CVE-2021-22723 – Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) through Cross-Site Request Forgery (CSRF)
  • CVE-2021-22726 – Server-Side Request Forgery (SSRF)
  • CVE-2021-22727 – Insufficient Entropy
  • CVE-2021-22728 – Information Exposure
  • CVE-2021-22773 – Unverified Password Change
  • CVE-2021-22774 – Use of a One-Way Hash without a Salt

Products Affected and the Fixes Available

EVlink City EVC1S22P4 / EVC1S7P4 All versions prior to R8 V3.4.0.1 https://www.se.com/fr/fr/product-range-download/63015-evlink-city/#/software-firmware-tab
EVlink Parking EVW2 / EVF2 / EV.2 All versions prior to R8 V3.4.0.1 https://www.se.com/ww/en/product-range/60850-evlink-parking/#software-and-firmware
EVlink Smart Wallbox EVB1A All versions prior to R8 V3.4.0.1 https://www.se.com/ww/en/product-range/63506-evlink-smart-wallbox/#software-and-firmware

Related News:

Schneider Electric and Claroty form cybersecurity partnership

Facebook Suspends Accounts of Iranian Hackers Targeting U.S. Defense

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

Social media handles are the primary target for cybercriminals to impersonate high-rated profiles for malicious activities. Recently, Facebook disrupted several fake accounts operated by an Iranian threat actors group targeting military personnel.

As per Facebook’s threat intelligence analysts, the cybercriminal group, dubbed Tortoiseshell, created bogus online identities to connect with individuals working in the defense and aerospace organizations across the U.S., the U.K., and Europe. After building the trust, the attackers distributed malicious URLs and tricked users into clicking them and infecting their devices with information-stealing spyware.

As per reports, Tortoiseshell’s malware was developed by Mahak Rayan Afraz (MRA), an IT firm in Tehran with ties to the Islamic Revolutionary Guard Corps (IRGC).

The social media giant claimed that the group created several fictitious profiles on multiple social media platforms, impersonating employees or recruiters from aerospace and defense enterprises. They even spoofed the legitimate U.S. Department of Labor job portal to lure the victims.

The attackers used persistent security measures to hide their cyberespionage campaign. In addition to leveraging email, messaging, and websites, they also used various tactics, techniques, and procedures (TTPs) including social engineering, phishing, and credential theft attacks to deploy malware.

“This group created a set of tailored domains designed to attract particular targets within the aerospace and defense industries. Among them were fake recruiting websites for particular defense companies. These domains appeared to have been used for stealing login credentials to the victims’ online accounts. They also appeared to be used to profile their targets’ digital systems to obtain information about people’s devices, networks they connected to and the software they installed to ultimately deliver target-tailored malware,” Facebook said. 

Attackers leveraged advanced malware tools and even continued to update their malware Syskit, distributed the malicious links via Microsoft Excel spreadsheets.

The suspension of fake Facebook accounts comes days after cybercriminals recently targeted Facebook users using malicious URLs and spamming them with copyright complaint notifications. Claiming to be from the Facebook security team, the attackers sent warning notices to users citing policy violations and re-verification requirements.

U.S. Govt. Introduces Two Initiatives to Curb State-sponsored Attacks

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

Organizations and governments across the globe are working towards curbing the rising cyberattacks. From joint cyber operations to awareness programs, several federal agencies are severely focused on disrupting cybercriminal cartels. Recently, the U.S. government launched two initiatives to prevent threat actors and their malicious activities targeting the country’s critical infrastructure.

One-Stop Ransomware Resource

The U.S. Department of Homeland Security (DHS) and the U.S. Department of Justice (DOJ) jointly introduced a website StopRansomware.gov, intending to help public and private enterprises against evolving ransomware attacks.

The website provides consolidated information on ransomware threats sourced from all federal government agencies. Individuals and organizations can visit the website for security alerts and guidance that is helpful or instrumental in fighting these attacks. The new integrated platform offers direction to victims on how to report cyberattacks to the authorities.

StopRansomware.gov also contains critical information and other resources from the Cybersecurity and Infrastructure Security Agency (CISA), the  Federal Bureau of Investigation (FBI), the Department of Commerce’s National Institute of Standards and Technology (NIST), and the Departments of the Treasury and Health and Human Services.

“The Department of Justice is committed to protecting Americans from the rise in ransomware attacks that we have seen in recent years. Along with our partners in and outside of government, and through our Ransomware and Digital Extortion Task Force, the Department is working to bring all our tools to bear against these threats. But we cannot do it alone. It is critical for business leaders across industries to recognize the threat, prioritize efforts to harden their systems, and work with law enforcement by reporting these attacks promptly,” said Attorney General Garland. 

Reward for Information

The second initiative from the U.S. government is the Rewards for Justice (RFJ) program. Launched by the U.S. Department of State (DoS), the RFJ program offers a reward of up to $10 million to individuals or organizations for giving information about foreign state-sponsored actors involved in malicious activities against the country’s critical infrastructure, under violation of the Computer Fraud and Abuse Act (CFAA).

The violations of the CFAA include extortion threats like ransomware attacks,  unauthorized access to systems, illicitly obtaining sensitive data, and intentionally causing damage to critical resources. Individuals can report potential suspects or attacks via a dark web-based reporting channel established by the authorities to protect the identity of the informers.

“The RFJ program also is working with interagency partners to enable the rapid processing of information as well as the possible relocation of and payment of rewards to sources. Reward payments may include payments in cryptocurrency,” the DoS said.

Alert, Facebook Users! That Copyright Complaint Could be Malicious

Facebook copyright complaint

It’s a common practice for threat actors to exploit users’ social media handles for their illicit activities. From malware payloads to hacking tools, attackers often drop malware payloads by spoofing websites that look legitimate. According to independent security researcher Rajshekhar Rajaharia, cybercriminals are currently targeting Facebook users using malicious URLs and spamming them with copyright complaint notifications. Claiming to be from the Facebook security team, the attackers are sending warning notices to users citing policy violations and re-verification requirements. They are also tricking users to click on malware-infused links to compromise devices and pilfer personal data.

Malicious FB Pages

Threat actors are distributing specially crafted fraudulent pages named “Copyright Constraints Page 2021” and tagging parliamentarians, ministers, and other government representatives.

Rajshekar Rajaharia Speaking about the incident with CISO MAG, Rajaharia said, “These Facebook pages have been activated recently, starting July 13. Hackers are tagging verified Facebook accounts continuously. They are using phishing/malicious links to target verified pages. This is an old trick to hack pages, but now hackers are targeting pages with huge followers and very high reach. Later they may use these pages for spamming. Hackers are targeting almost all politicians, celebrities, media, and famous Facebook accounts globally. You may receive a fake Copyright Complaint notification on FB. Don’t click on the link. It’s Malware/Ransomware.”

Cyberattacks on Social Media Continue

A recent investigation from ProofPoint revealed that a new malware is making rounds online via fake software sites, targeting popular service providers like Facebook, Google, Instagram, Amazon, and Apple. The undocumented malware, dubbed CopperStealer, is a specially crafted credentials and cookies stealer with a downloader that installs additional malicious payloads on targeted browsers. Read More Here…

While Employees Work Remotely, Attackers Target Their IoT Devices Left in Office

IoT devices

While the pandemic forced employees to work from home, most of their IoT devices were left behind connected to the corporate networks. Unpatched flaws in these connected devices provided a gateway for intruders to break into corporate systems. A recent survey by cloud security provider Zscaler analyzed the state of IoT devices that are still in the offices, while the employees are working remotely.

The survey “IoT in the Enterprise: Empty Office Edition” examined over 575 million device operations and 300,000 malware attacks on IoT devices, which Zscaler had blocked in December 2020. Nearly 76% of these IoT devices are still connected and maintaining communication with the company’s network on unencrypted plain text channels, posing severe security risks to businesses.

As per the survey findings, cyberattacks on connected devices surged by 700%, compared to the pre-pandemic period. Unauthorized IoT intrusions targeted over 553 different device types, including smart printers, smart TVs, cameras, and other connected devices linked to corporate IT networks.

Most Targeted Devices

The majority of the IoT attacks focused on set-top boxes (29%), smart TVs (20%), and smartwatches (15%). The home entertainment and automation sector reported the least number of attacks when compared to the health care, manufacturing, and enterprise sectors. Most attack traffic was reported on IoT devices in manufacturing and retail sectors (59%), including GPS trackers, 3D printers, automotive multimedia systems, barcode readers, PoS terminals, and other data collection devices.

The most targeted countries in the IoT attacks campaign were Ireland (48%), the U.S. (32%), and China (14%). Also, 90% of the affected IoT devices were found transferring information to servers located in China (56%), the U.S. (19%), or India (14%).

Unique Malware Attacks 

Zscaler’s ThreatLabz team uncovered over 18,000 distinctive hosts and 900 unique IoT malware variants in just a 15-day timeframe. The research team found new malware families — Gafgyt and Mirai — which are known for hijacking IoT devices to create botnets and spread malware.

“For more than a year, most corporate offices have stood mostly abandoned as employees continued to work remotely during the COVID-19 pandemic. However, our service teams noted that despite a lack of employees, enterprise networks were still buzzing with IoT activity. The volume and variety of IoT devices connected to corporate networks are vast and include everything from musical lamps to IP cameras,” said Deepen Desai, CISO of Zscaler.

Mitigation

Organizations should develop an IoT threat mitigation plan and practice basic security measures to mitigate the risks from vulnerable IoT devices. These include:

  • Monitor and get complete visibility into all the IoT devices in the network.
  • Always use strong passwords rather than keeping default ones.
  • Fix the unpatched vulnerabilities before the hackers exploit them.
  • Implement a zero-trust policy. Monitor and enforce a strict authentication policy to avoid shadow IoT devices into the company’s network.
  • Implement a strong device verification process before allowing Bring Your Own Devices (BYOD) policy.

Related Stories:

Mastercard’s New Digital Infrastructure Group Drives Digital Identity Service for Open Banking

digital identity service, Identity and Access Management

You may be revealing more information than needed whenever you disclose your personal identity, such as a driver’s license. And that information may be misused by the party from which you buy a product or service. Consumers are not in control of their data today, and there is a need for evolved standards and technology like homomorphic encryption to protect digital identities. These were some of the concerns expressed by Digital Identity ServiceRobert Schukai, Executive Vice President, New Digital Infrastructure and Fintech at Mastercard, when he delivered the keynote address at the Secure and Private Compute Summit (Virtual) on July 6. Schukai also outlined some of the initiatives undertaken by the New Digital Infrastructure Group at Mastercard – backed by Mastercard’s data principles. It’s digital identity service aims to counter consumer data privacy challenges for financial transactions.

By Brian Pereira, Editor-in-Chief, CISO MAG

The New Digital Infrastructure Group at Mastercard is focused on developer outreach, engaging with the Fintech community and with its cryptocurrency work. It is also regarded as Mastercard’s open banking organization. The Group wants to bring about change in how digital identities are exchanged during financial transactions. And it has achieved some success with its digital identity service called “ID” in markets like the U.S., Europe, and Australia. This has also opened up new opportunities and exciting applications that were not possible earlier due to concerns about consumer data privacy.

“Today, we are at a critical juncture at how data is used. We see a real need for consumers to be in control of their data — for consumers to feel like they had a say in how it was used,” said Schukai. “At Mastercard, we took this seriously, and we established our data principles in 2019… these were principles that every single employee at Mastercard buys into today.”

Mastercard Data Principles

According to Schukai, Mastercard believes that four things should take place when it comes to treating personal data with “decency.”

  1. You own the data. You produce data every day, so it belongs to you.
  2. You control your data. You have the right to understand and control how your data is shared and used.
  3. You as a consumer should benefit from the use of data.
  4. Mastercard will protect that data. Your data will be kept secure and used responsibly.

“It is important to set up those data principles today because digital identity and open banking are highly complementary businesses,” said Schukai. “We believe users should only have to share the data that is absolutely necessary at the time of the transaction, and this is our focus for any company that we work with or any use case that is out there.”

Enabling Open Banking

Open Banking, which was introduced in January 2018, has been a topic of many conversations as it gives consumers and third-party financial institutions flexibility for financial transactions. According to Investopedia, open banking is a banking practice that provides third-party financial service providers open access to consumer banking, transaction, and other financial data from banks and non-bank financial institutions, through the use of application programming interfaces (APIs).

Mastercard already operates an open banking solution in Europe, and in 2019, it acquired Finicity, a leader in the open banking space in North America.

Open banking got a major boost after regulatory rules were established for it in the U.S., EU, and Australia. For instance, in Europe, it is known as PSD2 (Second Payment Services Directive), and it is forcing the biggest banks to open up and share their data. The is enabled by standardized API access to information in bank accounts. While open banking has been around since 2018, there are still some major creases to be ironed out before it really takes off. However, the opportunities and benefits have been a big draw for both consumers and financial services organizations.

“This gives you tremendous leverage and opportunity — to create services and offerings for new account opening, for lending or credit decisioning. That was one of the things we found most compelling from a Mastercard perspective,” said Schukai.

He alluded to certain applications like controlling credit scores, which are possible due to open banking.

“People could upload their data in a product like the Experian Boost to raise their credit score, so that they can then turn around and secure a mortgage to a company like Rocket Mortgage. This is powered by the Finicity open banking solution, and it lets you get a mortgage very quickly. That ability to move data and use your data for lending and credit decisioning all require a combination of knowing who the person is, to be able to ….to successfully unlock that data. To secure and use it responsibly.”

Enabling Technologies and Techniques

To enable these open banking applications, organizations need to adopt certain privacy-enhancing technologies. There are techniques such as differential privacy, trusted execution environment, secure multi-party computing, and homomorphic encryption. And each of these has its range of complexity, capability, and security requirements. Companies must do their due diligence when choosing a technology.

Schukai informed that Mastercard is invested in homomorphic encryption. It also introduced a program to engage with tech companies that specialize in payments and security.

“Personally, I think homomorphic encryption is a phenomenally exciting technology. We see great value in querying data where it lives. It’s about performing computation in the ciphertext space and returning results of those queries, all this without decrypting. For us at Mastercard homomorphic encryption is an ideal technology when you are dealing with sensitive data that you do not want to sling around but would prefer to leave in its location.”

Data is encrypted at rest and in transit. But it has to be decrypted for processing, and that presents security and privacy challenges. This is now solved by homomorphic encryption, which enables ciphertext data to be processed without the need to decrypt it.

Homomorphic encryption is already coming into the mainstream, though it makes huge demands on computing resources.


Read our stories on Homomorphic encryption

How Intel’s Homomorphic Encryption Can Process Ciphertext

“Until now, technology gave you no protection and confidentiality when you shared your data”

Episode #8: Intel Labs’ Breakthrough Research on Data Privacy and Encryption Technologies


Legislative Compliance Challenges

Schukai said Mastercard is also working to help companies cope with legislation challenges at the local, regional, and international level.

“When you layer data principles with legislative compliance, you see the problems that we face in using data and using data safely. We need to think about multiple layers of security including tokenization and encryption that protect information. We need to think about regulations like GDPR — and Mastercard has launched a My Data portal so that individuals everywhere can see and manage their personal information that Mastercard holds. It gives you the opportunity to remove that data if you do not want it to be stored there any longer,” he said.

Schukai also feels the need for world-class anonymization solutions that protect data while enabling analytics under the GDPR. This will be exceptionally critical for data usage for consumers.

“As a company, we are embedding data responsibility principles into our product development process. We even provide controls over the use of data, including opt-outs for marketing data. We want to be able to unlock the power of data, but we need to unlock that data sensibly and responsibly. And for us at the highest level of security, when we are combining assets like user identity and banking information, we are very proud to be using technologies like homomorphic encryption as a way of leaving data where it sits, complying with national regulation, performing queries against data sets without moving the data and overturning the results of those queries in a safe, effective, and proper way, to unlock the types of solutions that consumers want.”

While Mastercard is doing its bit to secure consumer data, the Government of India thinks it should be more transparent by storing a copy of consumer transactional data on servers on Indian soil. On Wednesday, the  Reserve Bank of India banned Mastercard from issuing new credit and debit cards to consumers, and this is a major setback to the U.S. company.

In a notification, the RBI said Mastercard had not complied with data storage rules from 2018 that require foreign card networks to store Indian payments data “only in India” so the regulator can have “unfettered supervisory access”.

Digital Identity Service

Mastercard is taking its digital identity service (called “ID”) to other markets such as Australia. In November 2020, it did a beta launch for its reusable digital identity solution with Optus, a major Australian telecom company. This will provide Optus’ customers a simpler and more secure way to prove their identity online and in-store. To quote from a press release: In using ID, Optus will strengthen its identity verification and authentication process while retaining its “best-in-class, digital-first customer experience.”


Brian PereiraAbout the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Illicit Cryptomining Surges Amid Soaring Crypto Value

Sardonic, BitMart

Most cybercriminals are financially motivated, performing various malicious cyber activities to generate revenue. Several threat actor groups leverage cryptocurrencies, demanding ransom payments in Bitcoin or Monero. According to an analysis from Cisco Talos, adversaries are deploying malicious cryptomining techniques to infect targeted systems and mine crypto coins.

Higher the value, grave the crime

The price of cryptocurrencies is highly volatile. The rise in crypto values certainly influences the frequency of illicit cryptomining in the wild. As the price skyrockets, crypto hackers perform various crypto hacking campaigns using malware payloads like RATs and banking Trojans. Attackers often target cryptocurrency exchanges and digital wallets to steal virtual currency.

Among all cryptocurrencies, Monero is the most preferred virtual coin for attackers in their illicit mining activities. The standard design of Monero enabled attackers to mine them on unsuspecting systems across the globe.

“It appears that the mining activity does have some dependence on the value of the currency. The most cryptomining activity we’ve ever seen has occurred in the last couple of months when Monero hit its all-time high. Outside of the short price drop that occurred in early 2021, before the massive spike, the graph tracks almost identically the value of the currency. This was honestly a surprising correlation since it’s believed that malicious actors need a significant amount of time to set up their mining operations, so it’s unlikely they could flip a switch overnight and start mining as soon as values rise. This may still be true for some portion of the threat actors deploying miners, but based on the actual data, many others are chasing the money,” Cisco Talos said.

Crypto Threats Surge by 500%

According to Akamai’s report, cybercriminals are using several malware variants to infect both personal and corporate servers for malicious cryptomining activities. The report stated that the access to fake crypto exchange phishing URLs increased over 500% between March 2020 and May 2021. Threat actors are also leveraging malicious crypto apps to trick users and steal crypto coins.

“We believe the increase in malicious traffic is driven by the increase in cybercriminals’ motivation to execute cryptomining activities. As cryptocurrency prices grow, and the potential benefit from malicious mining activities increases, cybercriminals gain momentum as well,” the report added.

Ransomware Alert! SonicWall Asks Users to Fix Flaws in SRA and SMA Products

microsoft, flaws in SonicWall SRA SMA

Ransomware attacks have become sophisticated and continue to affect the cybersecurity community. The constant development of security defenses has become imperative for organizations amidst evolving attack vectors. Addressing unpatched flaws and monitoring security alerts in the systems can help mitigate the risks. Recently, security solutions provider SonicWall issued an emergency notice warning its customers of a ransomware campaign exploiting unpatched vulnerabilities in Secure Mobile Access (SMA) 100 series, Secure Remote Access (SRA) products, and end-of-life 8.x firmware.

SonicWall stated that attackers leveraged stolen credentials to exploit the known vulnerabilities; however, they have been fixed in the newer versions of firmware. The company urged its customers to update the vulnerable SMA and SRA devices as early as possible due to the risk of potential ransomware attacks.

Mitigation

As an immediate security measure, SonicWall asked enterprises using the vulnerable end-of-life SMA and SRA devices running firmware 8.x to either update or disconnect the services. The vulnerable products include:

  • SRA 4600/1600 (EOL 2019)
  • SRA 4200/1200 (EOL 2016)
  • SSL-VPN 200/2000/400 (EOL 2013/2014)
  • SMA 400/200 
  • SMA 210/410/500v

“The affected end-of-life devices with 8.x firmware are past temporary mitigations. Continued use of this firmware or end-of-life devices is an active security risk. Organizations that fail to take appropriate actions to mitigate these vulnerabilities on their SRA and SMA 100 series products are at imminent risk of a targeted ransomware attack,” SonicWall warned.

SonicWall also recommended users reset all passwords linked to SMA and SRA systems and enable multifactor authentication as an additional security measure.

Unpatched Bugs – An Imminent Threat

In a similar emergency directive, the Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies to address a zero-day vulnerability in Windows Print Spooler, which is being exploited in the wild.

CISA issued the alert after Microsoft raised a red flag about the flaw, dubbed PrintNightmare. The remote code execution (RCE) flaw CVE-2021-34527 could allow a remote hacker to disrupt the Windows Print Spooler operations. Read More Here…

Remote Work Has Accelerated Zero Trust Security

Remote Work

The COVID-19 pandemic has opened a pandora’s box that has directly impacted every individual on this planet. From soaring inflation to economic downturns, the unprecedented crisis has jeopardized the recovery of both low-income households and SMBs.  While organizations are still struggling to get back on their feet and survive the new normal, ever-rising incidents of cyberattacks are making threat vectors deplorable.

New challenges bring new solutions. How often does an organization need to press the refresh button to keep abreast with the dynamic security challenges?

The pandemic has been fueling growth in cybersecurity with an obvious buzz around zero trust implementations.

In its “2021 State of Zero Trust Security Report,” Okta Inc., an identity and access management company, divulged that a zero trust security model is key to securing businesses due to the pandemic and remote working scenario. More than three-quarters (78%) of companies around the world opined that zero trust has increased in priority, and nearly 90% are currently working on a zero trust initiative (up from just 41% a year ago).

The report further imparted that this year, organizations have dramatically accelerated their journey towards identity and access management (IAM) maturity and plan to progress significantly by the end of next year.

According to the report, every single recommended zero trust project across the identity maturity curve will have reached at least 25% adoption by 2023. Interestingly, that number jumps to nearly 40% for Forbes Global 2000 companies.

Till now, organizations had to deal with dispersed networks and now they have “dispersed employees” to extend security implementations.

When respondents were asked to rank core zero trust requirements, the number one priority was “people” for one-third of all organizations, followed by devices and data.

As cybercriminals have a field day, companies are not left with much choice but to adopt stringent authentication across resources for employees, customers, partners, contractors, and suppliers, while moving from network-based to more individualized device-based access decisions.

Sharing data on the IAM maturity curve, the report talks about more than a third of all companies prioritizing SSO and MFA for external users, context-based access policies, and automated account provisioning and deprovisioning.

Emphasizing on industry sectors, nearly a third (30%) of health care organizations indicate that zero trust is now a top priority due to the pandemic, as compared with 17% globally. Among financial services businesses, 94% already have a zero trust plan in place or will have one in the next 12-18 months, compared to less than half in 2020. Surprisingly, the software industry is lagging in its adoption.

Though, according to the survey, almost four in five companies plan to adopt a zero trust security initiative by the end of next year, compared with just 9% that have an initiative in place today; it needs to be a well-informed decision that involves a fundamental shift in strategy and mindset involving all the stakeholders.

Key Highlights

  • The pandemic is fueling zero trust prioritization — In 2020, 41% of organizations said they were working on a Zero Trust initiative or intended to start one shortly. This year, that number spiked to 90%.
  • People are the new corporate perimeter — 33% said people was their top priority, and 26% said devices were their top priority.
  • More than a third of all companies are prioritizing SSO and MFA for external users, context-based access policies, and automated account provisioning and deprovisioning.
  • The APAC region has progressed significantly, with all projects in Stage 1 of the Zero Trust Maturity Curve expected to be adopted by more than half of all companies by 2023.
  • Financial services, health care, and software companies are also prioritizing zero trust.

Zero Trust Security Implementation Climbing the Charts

According to a report published by Research Dive, the global zero trust security market is projected to register a revenue of $66,741.3 million at a CAGR of 17.6% during the forecast period (2020-2027), increasing from $18,500.0 million in 2019.

As the security lines get blurred, organizations are not left with much choice but to get inclusive in their approach to remote work and devices; traditional implementations continue to undergo a rapid change to keep up with the security challenges. Zero trust security implementations are one of the approaches that can address the security challenges thrown at the organizations. Cyberattacks will not cease anytime but are only getting more sophisticated and intelligent with every passing second. The think thanks have to make a fundamental change in their strategy and approach to match up with the criminal minds at play.