Home Blog Page 72

Alert! Researchers Find New Ransomware Variant “Diavol”

Ransomware attacks, ransomware, Sinclair Broadcast group

Ransomware operators at times announce shutdown of their operations but continue with a new ransomware variant. Some attackers create new ransomware infusing capabilities from the old one. Recently security researchers from Fortinet discovered a new ransomware dubbed Diavol targeting organizations globally from June 2021.   While Diavol is a new ransomware threat, the researchers claimed that it has a connection with Wizard Spider – a Russia-based cybercriminal group that operates Trickbot botnet.

How Diavol Spreads

Researchers stated that Diavol leveraged Asynchronous Procedure Calls (APCs) with a unique encryption procedure. The Diavol ransomware drops a ransom note in every folder it encrypts. While Diavol does not use any tactics to evade security detections, researchers found an anti-analysis technique used by the group to disguise its code.

Diavol Attack Flow

  • Create ID on the targeted system
  • Initialize configuration
  • Initiate C&C communication
  • Kill system processes
  • Initialize encryption key
  • Find drives
  • Find files
  • Prevent recovery
  • Encrypt files
  • Change desktop wallpaper

Similarities to Conti and Egregor Ransomware

The researchers also analyzed Diavol ransomware to find any similarities with Conti and Egregor ransomware. The command lines used by Diavol are somewhat similar to those of Conti ransomware. Besides, Conti and Diavol ransomware operate with synchronous I/O operations while encrypting the files. Researchers also suspected links with Egregor ransomware. However, attackers could have used these similarities on purpose to confuse the security experts.

“Currently, the source of the intrusion is unknown. The parameters used by the attackers, along with the errors in the hardcoded configuration, hint to the fact that Diavol is a new tool in the arsenal of its operators, which they are not yet fully accustomed to. As the attack progressed, we found more Conti payloads named locker.exe in the network, strengthening the possibility the threat actor is indeed Wizard Spider. Despite a few similarities between Diavol, Conti, and other related ransomware, it’s still unclear, however, whether there’s a direct link between them. And there are a couple of major differences from attacks previously attributed to Wizard Spider,” Fortinet said.

Thwarting Threats with a Zero Trust Security Posture

Zero Trust, cybersecurity

Hackers are breaching our nation’s critical infrastructure and with security threats lurking in the enterprise, Zero Trust adoption continues to rise. According to Cybersecurity Insider’s Zero Trust Adoption Report, 78% of IT security teams plan to implement a Zero Trust model. So, thwarting threats with a zero-trust security posture seems to be a viable option for businesses.

By Dr. Bob Baxley, CTO at Bastille Networks

But without true visibility, Zero Trust has zero chance of fully protecting an organization. Integrating and deploying Zero Trust enforces location-aware network access control policies for devices in secure environments.

The premise of the Zero Trust security model is simple enough: Organizations should not automatically trust any devices inside or outside a company’s perimeters. Instead of trusting a device’s authenticity, CISOs and IT security pros must continuously verify anything and everything that is on their network.

But as we’ve said before, “you can’t protect what you can’t see,” and unfortunately, without the right tools, radio frequency (RF) network traffic and devices are invisible.

Many organizations have overlooked RF devices in their Zero Trust security posture, resulting in a sense of misplaced trust. Today, there are new “Insider Threats” – compromised systems and user devices that have RF interfaces within an enterprise.

This includes Bluetooth and IoT devices, vendor and third-party equipment, shadow IT equipment, and industrial control systems such as HVAC. These RF devices all offer bad actors a vector to sensitive information, as it is possible to exfiltrate data over RF.

Current solutions on the market can passively observe rich RF data to discover threats and define policy for the authorized and unauthorized devices operating in or close to an organization’s environment. When integrated with an NAC such as Aruba ClearPass, this enables a complete Zero Trust policy to be maintained over all devices, whether they are already known to be using facility Wi-Fi, or radio systems beyond existing Zero Trust policies, such as Bluetooth, Cellular, and IoT devices.

Safeguarding Organizations With Zero Trust Security Posture

Here are some essential steps on how implementing a Zero Trust approach can safeguard organizations from similar attacks:

  • Determining Where RF Exists: Traditional security technology is incapable of detecting devices operating within the RF spectrum. Knowing which devices are communicating and attached to your organization’s infrastructure is critical in protecting against a cyber pitfall.
  • Evaluating RF Solutions: When assessing RF technology, CISOs and IT teams must examine solutions that will counteract radio-borne attacks to their facilities, intellectual property, trade secrets and sensitive data. Adopting RF technology is all the more necessary for the government sector. Their data and devices are very critical from a national security viewpoint. Thus, detecting devices in real-time from the realms of known and unknown threat landscapes is crucial.
  • Embracing Zero Trust: As with endpoints and network traffic, in order to have a Zero Trust posture, you must have tools in place to continuously monitor and evaluate whether RF devices are conforming to your security policies. Policy examples include preventing RF devices from operating in restricted areas, ensuring that RF devices only connect with intended and approved devices, detecting the existence of unauthorized or rogue devices in your enterprise.

Establishing a Zero Trust security posture equips organizations and critical infrastructures to mitigate cyber attackers looking to compromise vulnerable RF devices. In today’s remote-focused world, it’s critical for organizations to embrace a Zero Trust security approach to secure operations and improve safety and accessibility from rogue access.

The bottom line: To maintain a Zero Trust posture, organizations MUST have RF network and device visibility.


About the Author

zero trust security posture, Dr. Bob Baxley, CTO at Bastille NetworksFor more than a decade, Dr. Bob Baxley has been a technology leader in implementing machine learning algorithms for software-defined and cognitive radios. At Bastille, Bob serves as Chief Technology Officer where he leads the development of systems to sift through massive amounts of radio frequency data to protect enterprises from radio threats. Prior to joining Bastille, Bob was the Director of the Software Defined Radio Lab at Georgia Tech, where he led basic and applied research projects for organizations including NSF, ONR, Army, DoD, Air Force, and DARPA. He has published more than 100 peer-reviewed papers and patents is the recipient of various research awards and is a Senior Member of the IEEE. He also led the GTRI team that competed in the DARPA Spectrum Challenge and placed second out of 90 teams.

Disclaimer

This article has been researched and written by the said author and CISO MAG does not take any responsibility of the facts, figures, and content. The views expressed are purely the Author’s and CISO MAG does not endorse or take responsibility for it.

If You’re Connected, You’re Vulnerable Too!

IoT attacks

Though IoT devices continue to assist with smart connectivity and communication, there are high potential risks involved. For instance, a new investigation from the consumer advocacy organization Which? revealed that smart homes could suffer over 12,000 IoT attacks in a week. Common home appliances like air-conditioning units, TVs, refrigerators, washing machines, lights, doorbells and even ceiling fans are increasingly being IoT enabled.

Fake Smart Home Setup

In order to find the frequency of IoT attacks, Which? created a fake smart home setup with real IoT devices like smart TV, webcams, routers, thermostat, printers, doorbells, and smart lights, etc., The company conducted the test in May 2021 in collaboration with cybersecurity firm NCC Group and IoT malware specialists the Global Cyber Alliance (GCA).

What the Investigation Found

  • Over 1,017 hacking attempts detected were from across the world, in the first week of the test.
  • Nearly 66% of the intrusions are malicious.
  • More than 12,807 unique scans/attacks were observed against IoT devices in a week in June.
  • Over 2,435 specific attacks to authorized intrusions were observed, accounting to 14 attacks per hour.
  • While attackers often hide their locations during attacks, most hacking attempts originated from the U.S., Russia, India, China, and the Netherlands.

Weak Passwords – The Main Culprit!

Most IoT devices have default or weak passwords that can easily be guessed. And their owners never bother to change the passwords from factory defaults. The investigation found over 2,684 hacking attempts that are intended to guess weak and default passwords. As soon as the device connects to the Internet, it’ll be under hackers’ radar. Cybercriminals often focus on vulnerable IoT devices to find credentials, deploy ransomware, or data theft. It is estimated that 97% of all IoT attacks are performed to add them into Mirai, a botnet that searches for insecure connected devices. Mirai botnet leverages brute-force attacks to guess passwords and install Trojan on the targeted devices.

How to secure your IoT devices

Basic security measures can boost your smart home security. These include:

  • Use strong passwords
  • Enable all the security features offered by the particular IoT device
  • Update the IoT devices regularly
  • Most importantly, update your Wi-Fi router and password regularly, as it’s the gateway for all your smart devices

The IoT Risk is Inevitable!

In an interview with CISO MAG, Chukwudum Chukwudebelu, Chief Strategic Officer and Co-Founder at Simius Technologies Inc., discussed the major cybersecurity concerns associated with IoT devices. “The IoT technology will always improve but it will never be 100% secure. As long as it is connected to the internet, there is always a risk. The best chance at cybersecurity is to reduce that risk. Since the internet was not built to be secure, rather, it was designed to be shared.  Industries are increasing the use of IoTs, and consumers are doing the same,” Chukwudebelu said.

To read the full interview, subscribe to and download CISO MAG’s July 2021 issue, which includes interviews with a diverse and rich mix of topics and conversations that include 5G security, encryption and cryptography, incident response, vulnerability disclosure, API security, IoT device security, backup strategies, insider threats, and the latest cyberthreats.

Get Your Copy Here!

Microsoft Raises Red Flag About Windows Print Spooler Vulnerability ‘PrintNightmare’

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

Despite regular security audits, several enterprises continue to suffer zero-day attacks more often. Unpatched vulnerabilities can give nightmares to organizations and allow a remote attacker to execute account takeover attacks. While companies are trying to boost their security perimeters, threat actors are always on the hunt to exploit potential security loopholes. Recently, Microsoft warned about a zero-day vulnerability in Windows Print Spooler code. Dubbed as PrintNightmare, the remote code execution (RCE) flaw CVE-2021-34527 could allow a remote hacker to disrupt the Windows Print Spooler operations. The tech giant stated that all versions of Windows are vulnerable to exploitation. The vulnerability came to light after security researchers from cybersecurity firm Sangfor Technologies disclosed it.

A zero-day vulnerability is a security flaw in an application or IT process that is yet to be addressed by the developer/company responsible for it. Threat actors often exploit unfixed vulnerabilities to break into corporate networks, posing a severe risk to organizations’ critical data.

How Serious is the Flaw?

The PrintNightmare vulnerability exists when the Windows Print Spooler is performing privileged file operations. If exploited successfully, any remote attacker could run arbitrary code on the targeted systems and obtain system privileges. Threat actors could install malicious files, view, alter, delete data, or create new accounts. They could also obtain authorized access to the targeted system or install ransomware without the user’s knowledge.

“Microsoft is aware of and investigating a remote code execution vulnerability that affects Windows Print Spooler and has assigned CVE-2021-34527 to this vulnerability. This is an evolving situation, and we will update the CVE as more information is available,” Microsoft said.

Mitigation

While no patch has been released yet, Microsoft urged users and businesses to apply security updates released on June 8, 2021, to defend the systems from the flaw. “Please ensure that you have applied the security updates released recently and see the FAQ and Workaround sections in this CVE for information on how to help protect your system from this vulnerability,” Microsoft added.

Here’s what CISA has to say…

Knowing the severity of the flaw, the Cybersecurity and Infrastructure Security Agency (CISA) recommended all security admins to disable the Windows Print spooler service in their domain controllers and systems. “Due to the possibility for exposure, domain controllers and Active Directory admin systems need to have the Print spooler service disabled. The recommended way to do this is using a Group Policy Object,” CISA said.

“I am looking for people who are multipliers and who help everyone else get better”

Jason Lee

Hiring security professionals has taken a new turn today, compared to the pre-pandemic era. The IT organization is reassessing its workforce and making certain internal structuring changes.

Studies show that there is a global requirement for 3.5 million security professionals. And with the growing number and sophistication of threats, organizations are hiring aggressively once again. Yet CISOs face multiple challenges as there are many candidates applying for open positions. Finding the right person with the right skills takes much effort and some time. It is also harder to train people on soft skills and core competencies. But what are the skills and qualities that CISOs look for?

Brian Pereira, Editor-in-Chief, CISO MAG, spoke to Jason Lee, Chief Information Security Officer at Zoom, to understand his hiring challenges. Lee informed us that he expects continual hiring at his company this year and revealed the type of skills and the people he is looking for.

So, what would it take to ace the interview and get into Zoom? Lee tells us in this interview story.

Zoom as a company has benefitted hugely in the past year, with remote workers depending heavily on this video collaboration tool.

Lee has 20 years of experience in technology, with a specialization in information security and operating mission-critical services. He was recently the Senior Vice President of Security Operations at Salesforce, where he was accountable for the global organization delivering critical end-to-end security operations to customers and employees including company-wide network and system security, incident response, threat intel, data protection, vulnerability management, intrusion detection, identity and access management, and the offensive security team.

Prior to Salesforce, he held the position of Principal Director of Security Engineering for the Windows and Devices division at Microsoft with the charter of protecting the online services of Windows Update, XBOX Live, and the Microsoft online store. He was also the Senior Director of Developer Services, where he was responsible for the design and management of the missioncritical PKI for all products across Microsoft. This included cryptographic services in products such as Windows and SQL Server and cloud services such as Azure and Office 365. Additionally, Lee was responsible for the codesigning and anti-malware services supporting Microsoft in that role.

Edited excerpts of the interview follow:

What are the current hiring trends in the industry and within your own organization?

SolarWinds is in the news now, especially in the U.S. So, I think there is a lot of investment going into hiring. I’ve spoken with a lot of CISOs and there is a considerable amount of hiring going on. We are absolutely expanding our security program here at Zoom.

During the pandemic, it has been much more difficult to hire. There is a lot of competition for cybersecurity experience. But one of the things that have made it easier for a lot of companies, including us, is the opportunity to offer remote positions, where you can work from anywhere in the world. You have to sell somebody on the ability to work remotely, and the ability to work on high-impact work.

It is important to note how companies are going after the same resources as you are, and what you would do to give yourself an edge, in terms of hiring.

What are your approaches to hiring talent? What channels do you use?

We leverage LinkedIn quite a bit and we do look for folks that are already working at other companies, and look for top talent anywhere in the world, at any company.

According to an industry survey, there are 3.5 million security positions open. There is definitely a shortage of cybersecurity professionals.

Absolutely. It is about how do we prepare people out of college and universities for these types of jobs, and this is critical; building stronger information assurance and information security degrees helps considerably. We are just adding more open positions to that 3.5 million. It is difficult to find and recruit the right people when there are so many positions open out there.

In other words, to get more people interested in cybersecurity, the training should go down to K-12 and secondary school?

I believe so because it is such a strong career path. The sooner you can expose people to that and get them excited about that career path, the better.

As a security leader in your organization, what are the top three qualities you look for when hiring for cybersecurity roles?

I focus on soft skills and I look for somebody who has good problem-solving abilities. Somebody who is a team player, with good communication skills, and who can handle the technical side of it. It is harder to train somebody on those core competencies of working well in teams and problem-solving — than it is to teach someone how to manage a firewall or intrusion detection. There is great technical training out there for that…To read the full interview, subscribe to CISO MAG.

This interview first appeared in the May 2021 issue of CISO MAG.


Brian Pereira

About the Interviewer

Brian Pereirais the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Fighting Back Against Ransomware (We’ve Had Enough)

fight

The Colonial Pipeline attack on May 7 was a watershed moment in the universal fight against ransomware attacks. It was the first incident in which the ransom paid to attackers was recovered. The attack on Colonial impacted the fuel supply chain, leading to a temporary fuel shortage along the Northeast coast of the U.S. The pressure was building for Colonial Pipeline and their CEO, Joseph Blount, had to make a difficult decision – paying up. In an interview with the Wall Street Journal, Blount acknowledged he authorized the ransom payment of 75 Bitcoin, which is approximately $4.4 million. A few weeks later, the Department of Justice and the FBI announced that they recovered most of the ransomware amount.

In his blog post dated June 16, Brian Krebs, Editor of KrebsOnSecurity, reported that the Ukraine Cyber Police arrested six people from the CLOP ransomware group. The gang reportedly extorted more than half a billion dollars from victims.

Ransomware attacks are now an everyday occurrence. A report from Cybersecurity Ventures estimated a ransomware attack on businesses every 11 seconds in 2021.

While there are numerous debates about whether impacted companies should be paying the ransom, we could soon have legislation for this. Last year, the Department of the Treasury’s Office of Foreign Assets Control (OFAC) published an advisory informing the public that the payment of ransom demanded by cybercriminals may be a violation of U.S. law.

For sure, there will be more ransomware attacks in the coming months. The adversaries see this as a lucrative opportunity, more so now, when the pandemic has office workers at home, with weak security on their home networks. Ransomware gangs are getting more organized with affiliate programs. They now offer Ransomware-as-a-Service — case in point, the DarkSide ransomware group that brought Colonial Pipeline to its knees. Read more about this in an article in the Insight section: “The Vulnerabilities that Open the Door to Ransomware.” 

We’re happy to announce that the July 2021 issue is CISO MAG’s fourth-anniversary issue, which includes interviews with a diverse and rich mix of topics and conversations that include 5G security, encryption and cryptography, incident response, vulnerability disclosure, API security, IoT device security, backup strategies, insider threats, and the latest cyberthreats.

We hope you enjoy reading all the interviews and stories in this issue.

To get a copy Subscribe Now!

Rags to Riches! The Evolution of Ransomware Operators

BlackMatter ransomware

Detecting and preventing ransomware attacks have become the primary goal for most organizations. The cybersecurity community across the globe is severely concerned about the rising sophistication of ransomware attacks. Ransomware operators have become a serious threat to organizations and individuals, creating havoc, encrypting sensitive corporate data, and demanding hefty ransoms.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Threat actors leverage double-extortion techniques by threatening to post victims’ data online if they refuse to pay the ransom. If this isn’t menacing enough, threat actors are now leveraging the triple extortion technique to make their ransomware business more lucrative. In triple extortion, attackers send their ransom demands to the customers and third-party agencies associated with the victim.

Several industries saw a growth in their cybersecurity budget to thwart ransomware threats, and governments even declared ransomware as a national threat, implementing robust security measures to protect their critical infrastructure from both state and non-state adversaries.

The Rising Costs of Ransomware 

Despite multiple joint cyber operations that busted several ransomware groups, new kinds of ransomware strains are still being reported regularly. A survey from Cybersecurity Ventures predicted that ransomware attacks would cost organizations across the world $20 billion in 2021, which is a 57% increase when compared to 2015 ($325 million). It also forecast that ransomware attacks will cost the victims over $265 billion annually by 2031, reporting an attack every 2 seconds.

Rise in Attackers’ Revenue

The pandemic and the newly adopted remote working environment gave more opportunities to ransomware operators in creating new malware and extortion techniques. DarkSide ransomware group, which is behind the infamous Colonial Pipeline hack, extracted over $90 million ransom in Bitcoin from 47 victims. The group reportedly infected nearly 99 organizations with the DarkSide malware, with an average ransom payment of $1.9 million.

Why do companies rush to paying ransom?

Threat actors purposely target high-profile organizations with a larger employee and customer base. Their brand image and the massive amount of sensitive customer data make large enterprises accept ransom demands. Research from the Neustar International Security Council (NISC) revealed that over 60% of organizations admitted that paying the ransom would be their primary solution in the event of a ransomware attack. One in five organizations said they would consider paying 20% or more of their company’s annual revenue.

Most organizations prefer paying ransom to avoid data loss or misuse by attackers. For instance, meat-processing giant JBS confirmed that it had paid $11 million to the REvil ransomware gang to restore its systems. The U.S. Colonial Pipeline reportedly paid $4.4 million ransom after attackers disrupted its services. However, there is no assurance that victims will be able to recover their data after paying the ransom. There is a chance that attackers may demand more ransom; they may release only a small amount of data on the dark web, or they can get hold of a copy of the encrypted data to threaten the victim in the future.  It’s imperative to think about the effects and consequences of ransom payments before paying them.

Closing Comments

Bob DiachenkoSpeaking to CISO MAG about the rise of ransomware attacks, cybersecurity researcher Bob Diachenko said, “Ransomware evolves similarly to any software proposition on the market – there are large groups operating as marketplaces with ransom-as-a-service solutions, state-sponsored APTs, and many independent actors most of which are simply trying to reach a low-hanging fruit in the form of misconfigured databases.”

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

 

Why Automotive Cybersecurity is Crucial for the Future

cybersecurity practices, Automotive Cybersecurity

Connected technologies are helping transform vehicles from a mode of transportation to mobile living spaces. Technologies like navigation, GPS, connected infotainment, among others., have become a standard feature in a modern car. To put this in perspective, as per Deloitte’s 2020 report on connected cars, the Indian connected car market is projected to grow at a CAGR of 22.2% and reach $32.5 by 2025 from an estimated $9.8 billion in 2019. Connectivity has been opening doors for new technologies and information sharing across industries.

By Alexander Klotz, Head of Technical Center India (TCI), Continental Automotive India

However, as the connectivity quotient increases in the car, cybersecurity becomes a key priority for all those involved in the automotive industry as we move closer to autonomous vehicles.

Automotive Cybersecurity: The Need

A vehicle today has several million lines of code. These vehicles rely on Over-The-Network (OTN) communication interfaces to function, increasing the risk factor for privacy and security. The various Electronic Control Units (ECUs) in a vehicle are linked through an internal network,

and a lack of cybersecurity measures makes them vulnerable. For instance, we need to secure the ECUs of a vehicle’s brakes and transmission from a possible hack. Earlier, our concern was to protect the environment from faulty components. Today, it is equally essential to protect the components from hostile environments.

Further, a connected vehicle has a network of functions, such as cameras that screen passengers, GPS, seat belt warnings, working together to share the necessary information. If even one of these functions were compromised, the whole system could be affected.

The vehicles in the future would be collecting vast amounts of data through the internet, and it will leave the user open to other data threats, including the consumer’s personal information. The result of compromised data would make the car more vulnerable to security threats.

The Need for Cybersecurity for the Automotive Ecosystem

As we move towards connected and electric mobility, and vehicles becoming IoT devices, we could be looking at a future where a faulty ecosystem can expose the vehicles to threats and vulnerabilities. For instance, many charging stations use outdated open charge point protocol based on HTTP, which does not encrypt data/information, allowing attackers to break into the WIFI signal and rewire the charging gateway.

There is a crucial need to develop means based on artificial intelligence and machine learning to fight cyberattacks and minimize their impact on the Internet-of-Vehicles framework. Automotive cloud security could help stakeholders by giving them an entire picture of the data flows in their surroundings. It makes it easy for users to identify threats to one’s network and identify deviation beforehand.

However, automotive cybersecurity does not limit just to securing the vehicle. It has to start way earlier. For instance, during the manufacturing process itself. The manufacturing setup requires a robust security system to prevent intrusion of the hackers, who could modify the codes of the components, leading to faulty behavior.

Automotive Cybersecurity: Beyond Mobility

As we move towards connected plants and advanced technologies, it opens us to new threats and vulnerabilities. Any information that travels through the internet is susceptible to a cyberattack. For example, when manufacturing data migrates from Operational Technology (OT) systems on the factory floor to interconnected Information Technology (IT) systems in the corporate network, new risks evolve. This data is now more vulnerable at this stage. Cybercriminals could potentially gain access to intellectual property, shut down systems, disrupt production timetables, and affect product quality.

The manufacturing setting needs to be considered a fully integrated setting, even if some processes are not integrated into the Internet. Although many breaches start in IT networks, the hackers or attackers may jump into other parts of the setting through connected devices. Furthermore, some connected devices may include information about the non-connected process.

A secure supply chain ecosystem also requires diligence toward proper vendor management. Any third parties that have authorized access to the company’s network can become unwitting avenues of attack. A bad actor who steals any login credentials of the third party could potentially gain access to the company’s network by pretending to be an authorized user.

Solution

The solution for automotive cybersecurity needs to be proactive and multilayered. First, individual electronic components/systems must be secured. Following this, the connections between these components/systems need to be made secure. As the next step, the focus should shift towards protecting and securing the external interfaces. Once all external interfacing is secured, as the final step of protection, data processing taking place outside of the car has to be strengthened to prevent data theft and exploitation. Cloud and backend solutions also need to be given importance at the final stage, and they need to be protected from security breaches.

Today, teams are working on securing the systems, memory, communication, and supporting infrastructure. Online trust centers secure the crypto keys, penetration test labs that continuously look for vulnerabilities and threats have become crucial to ensure vehicle safety.

Cybersecurity can be tackled in three broad critical steps:

1. Prevent – The probability of security encroachment rises in tandem with the degree of networking and the number of in-vehicle interfaces that it necessitates. Hackers are driven by various factors, including data theft, financial gain, and prestige. Manufacturers need to strengthen all potential attack points and lay down security solutions across multiple levels and departments. This can be made possible by identifying the various attack points, understanding the behavior, and designing safety measures to secure the systems.

In other words, make it as hard as possible for hackers to attack. This typically involves hardware-enhanced crypto, embedded security software, secure networks, and secure vehicle architecture. In terms of automotive cybersecurity, another example of a preventive approach would be DevSecOps. The practice ensures that developers are using coding practices that are less vulnerable to attacks.

2. Understand – Know that the system is being hacked, identify the point of entry, exposed vulnerabilities, and other critical information in real-time. This involves live monitoring and tracking of connected vehicles. An example of this would be setting up the Security Operation Centres (SOCs). SOCs are needed to ensure real-time detection of any such breach and tackle it in real-time. The SOCs would also help us identify the gaps and do quick patches to avoid long-term exposure to vulnerabilities in on-road vehicles.

3. Respond – Mitigate the damage and immunize the fleet in hours. This involves software updates over-the-air and patch management. Cybercrime is an asymmetric challenge. Although an organization must monitor hundreds of processes, hackers just need to find a single flaw to gain access. It is like a never-ending race between those who want to secure networks and those who want to break them down. This is why, once a loophole is identified, it is vital to act as quickly as possible.

Organizations should implement an Incident Response Management System that provides an extra layer of security that reacts quickly if an attack occurs. Millions of cars will be able to upgrade themselves to new protection standards without needing to visit an auto repair shop. Real-time patch management through over-the-air updates is an essential requirement for “Vision Zero” – a future without fatalities, injuries, and crashes.

The Way-forward

Cybersecurity has always been an industry that has sustained innovation. For instance, earlier, the concern was to protect the environment from faulty components. Today, it is equally essential to protect the components from hostile environments. Today, a considerable section of industry engineers are working on securing the systems, memory, communication, and supporting infrastructure. Today, online trust centers secure crypto-keys, and penetration test labs continuously look for vulnerabilities. As the technology evolves, the industry continuously adapts and responds to the threats, innovating to keep the systems secure.

The challenge today we face, as an industry, is a lack of standardization. Standardization is crucial in shaping cybersecurity practices of the future. As an industry, we also need to move towards an information-sharing ecosystem – share information and best practices with peers. As they say, one person’s detection can become another person’s prevention.

Another step that could be transformative would be the introduction of AI and predictive modeling. It is accelerating instant detection and response, better communication of risks to the business, and gaining a better understanding of cybersecurity’s situational awareness.


About the Author

Alexander KlotzAlexander Klotz is the head of Continental’s Technical Center India (TCI), the in-house R&D center of Continental Corporation. In this role, Klotz is responsible for the growth of the center into a trusted partner augmenting Continental’s global R&D competence. In this regard, he will oversee the growth of competence, innovation potential, and capacity.

Prior to this, Klotz was Director R&D within Continental’s Interior division, responsible for advanced product development and systems engineering. Klotz has more than 15 years of automotive engineering experience, in areas spanning vehicle testing, project management, customer and product strategy, simultaneous engineering, and innovation.

Klotz also launched and led the Silicon Valley office for Continental in 2013. He studied Mechanical Engineering and Business Administration (German Diplom Wirtschaftsingenieur) at the Technical University Carolo Wilhelmina in Braunschweig, Germany.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Facebook Sues Marketing Firm and Vietnamese Group for Abusing its Ads Platform

Surveillance Legislation (Identify and Disrupt) Amendment Bill

Facebook has a history of lawsuits and settlements, from the Cambridge Analytica scandal to the recently settled photo-tagging class-action lawsuit. The social media giant earlier took multiple actions legally with its third-party agencies for policy violations. Recently, Facebook filed two different lawsuits against perpetrators for online scams and abusing its advertising platform.

Lawsuit  Against N&J

According to an official statement, the first lawsuit was filed against a marketing firm N&J USA Inc. for its involvement in bait-and-switch online ad promotions on Facebook. The company allegedly ran fraudulent ads on Facebook that, when clicked, redirected victims to a deceptive e-commerce site. The defendants even blocked users’ negative feedback on their Facebook pages, violating user rights.

Lawsuit  Against Vietnamese Suspects

The second lawsuit is against four Vietnamese suspects – Nguyễn Quốc Bảo, Thêm Hữu Nguyễn, Lê Khang, and Pham Hữu Dung for running unauthorized advertisements by hijacking employee accounts of various marketing firms. The defendants allegedly deceived the victims into installing a fake mobile app, “Ad Manager for Facebook,” which was created to steal users’ login credentials. The perpetrators leveraged compromised Facebook accounts to run fraudulent ads worth $36 million and promote their online scams.

“As part of our ongoing efforts to keep people safe and combat abuse of our ad platform, we filed two separate legal actions today against the perpetrators of online scams who violated our Terms and Advertising Policies. Today’s legal actions demonstrate our ongoing commitment to protecting users, enforcing our policies, and holding people accountable for abusing our services,” Facebook said.

Facebook Settles Class-Action Lawsuit

In one of the largest data violation lawsuit settlements, Facebook recently agreed to pay $650 million to users in Illinois who indicted the social media giant for using photo face-tagging and biometric information without their consent. Nearly 1.6 million users in the Prairie State filed a class-action lawsuit against Facebook in April 2015, for violating the Illinois privacy law. The claimants stated that Facebook used its facial recognition technology to unauthorizedly scan and collect users’ photos from their profiles. Read More Here

Scam Alert! U.K. Police Warn WhatsApp Users Over Account Takeover Attacks

FMWhatsapp

Whether it is about policy violations or unauthorized intrusions by hackers, WhatsApp has been in the news since the beginning of 2021. After a slew of legal battles with the Indian government over privacy policy changes, WhatsApp is now facing concerns in the U.K. over the surge in WhatsApp scams. Police authorities in the U.K. recently warned WhatsApp users about fraudsters targeting WhatsApp accounts to steal sensitive information, according to a report. Scammers are allegedly tricking unwitting users to share their WhatsApp verification codes to compromise accounts.

“We have seen a surge in WhatsApp accounts being hacked, if you are sent a text from WhatsApp with a code on it, don’t share the code with ANYONE no matter who’s asking, or the reason why,” said the Southwark Police in South London.

How does the scam work?

Hackers exploit the six-digit verification code, which is sent to the WhatsApp users at the time of registration. They then call users by imitating WhatsApp customer support and ask them to share the verification code received via SMS to compromise the accounts. Once hackers get your verification code, they take full control of your WhatsApp account, which eventually results in identity theft and information misuse.

The Police authorities urged all WhatsApp users to be vigilant and not share verification codes with anyone. Even WhatsApp advised its users to enable a two-step verification process and maintain necessary privacy measures to prevent any potential intrusions.

This is not the first time WhatsApp users encountered such scams. Recently, a malicious app named WhatsApp Pink made rounds online to gain control over user devices and steal their personal information. According to Indian security researcher Rajshekhar Rajaharia, threat actors are sending malicious links to users, claiming to provide new WhatsApp features in pink color. Read more here…