Home Blog Page 77

Use iPhone 6 Plus? Apple has an Urgent Security Update for You

Apple App Store, Apple vulnerabilities

Cybercriminals have started exploiting vulnerabilities at will and to make it worse, they are now penetrating deeper by finding zero-day vulnerabilities. Owing to this, Apple is keeping no stone unturned to fix the zero-day bugs at the earliest and has released a new security update in iOS 12.5.4 for addressing three zero-day vulnerabilities affecting the ASN.1 decoder and the WebKit in Apple’s widely used products – iPhones, iPads, and the 6th generation iPod touch.

Patch Management for Apple’s Zero-day Vulnerabilities

The vulnerability patch from Apple mainly consists of three security fixes that are listed below with their respective CVEs:

  1. CVE-2021-30737 (ASN.1 Decoder Issue)

This vulnerability allowed processing a maliciously crafted certificate, which eventually would have allowed an attacker to carry out arbitrary code execution. It was found to be a memory corruption issue in the ASN.1 decoder and the vulnerable code has now been removed to fix the issue.

  1. CVE-2021-30761 and CVE-2021-30762 (Webkit Issue)

This vulnerability allowed processing maliciously crafted web content which could lead to arbitrary code execution. Apple says that it “is aware of a report that this issue may have been actively exploited.”

The CVE-2021-30761 was found to be a memory corruption issue that has been addressed with improved state management. Similarly, the CVE-2021-30762 is said to be used after the free issue, which has been addressed with improved memory management.

All these zero-day vulnerabilities were reported by anonymous researchers and were mainly targeted at Apple’s older devices listed below:

Devices impacted: iPhone 5s, iPhone 6, iPhone 6 Plus, iPad Air, iPad mini 2, iPad mini 3, and iPod touch (6th generation).

Besides releasing the patches for these zero-day vulnerabilities, Apple has also issued multiple security updates since the beginning of the year for its various operating systems, including the macOS, watchOS, and tvOS. Users are recommended to update their respective devices to the latest versions available.

Related News:

BlastDoor: New Security Feature in Apple iOS 14 to Counter Zero-click Exploits

How Attackers Are Using SEO Poisoning to Deliver ‘SolarMarker’ Remote Access Trojan

SEO poisoning

From malicious email attachments to weaponized PDFs, cybercriminals leverage various traps to target unwitting victims. At times, threat actors rely on old hacking techniques like backdoor payloads to compromise targeted systems and pilfer sensitive data.

Recently, security experts from Microsoft unveiled a series of attacks that used SEO Poisoning to infect systems with a remote access trojan (RAT) and steal sensitive data. The threat actors distributed SolarMarker malware (also known as Jupyter, Polazert, and Yellow Cockatoo) in this campaign. SolarMarker is a .NET RAT that runs in a system’s memory and is used by hackers to deploy additional payloads on infected devices. It’s a backdoor malware that steals user data and credentials from web browsers and exfiltrates the stolen data to C2 servers.

What is SEO Poisoning? 

Also known as search poisoning, SEO poisoning is an old attacking strategy in which threat actors create malicious websites and use different SEO techniques to make them appear on top in search results. In SEO poisoning,  attackers use tactics like keyword stuffing, PDF documents, hidden text, and cloaking to manipulate the search rankings and redirect the victims to unwanted applications, phishing sites, malware links, and adware.

How Does a SolarMarker Attack Work?

Threat actors used thousands of PDF documents stuffed as SEO keywords and links that redirected users to a malicious site. “The attack works by using PDF documents designed to rank on search results. To achieve this, attackers padded these documents with ten pages of keywords on a wide range of topics. As intended, these PDF files or pages referencing them turn up in search results. When opened, the PDFs prompt users to download a .doc file or a .pdf version of their desired info. Users who click the links are redirected through 5 to 7 sites with TLDs like .site, .tk, and .ga,” Microsoft said.

Attackers used catchy business terms like insurance form, acceptance of contract, how to join in SQL, and math answers to lure professionals.

Over 100K Malicious Webpages Found

Attackers commonly hide RAT into these forms to redirect the users to the fraudulent websites that host the malware. They leverage the malicious document templates to infiltrate into victims’ devices.

Earlier, cybersecurity solutions provider eSentire reported that threat actors leveraged Google Sites to host malicious documents. Attackers targeted business professionals to lure them into hacker-controlled websites, hosted on Google Sites, inadvertently installing RATs. eSentire discovered over 100,000 unique web pages that contained popular business terms as keywords such as template, invoice, receipt, questionnaire, and resume.

“Once the target lands on a site controlled by the hacker, the page shows download buttons for the document template they were searching. When clicked, the business professional is redirected (unknowingly) to a malicious website which serves up an executable disguised as a PDF document or a Word document,” eSentire said.

Also Read: Not Just Hands, Your PDFs Also Need to be Sanitized

The Vulnerabilities that Open the Door to Ransomware

Ransomware attacks, ransomware, Sinclair Broadcast group

The Darkside ransomware group brought the Colonial Pipeline to its knees in May 2021. In another incident that soon followed, REvil (Ransomware Evil), a private Ransomware as a Service (RaaS) caused meat prices to rise when it attacked JBS — a meat processing giant. And in Ireland, Conti attacked the Irish Health systems and the FBI published a warning that they would be targeting the health care sector more.

By Ram Movva, the President and Co-founder of Cyber Security Works

Could these attacks have been avoided? Can we prevent future attacks?

Yes.

If these organizations had remediated vulnerabilities that are associated with ransomware, they could have shrunk their attack surface and avoided the attack.

The catalyst behind the rise in ransomware attacks is the ease with which they can exploit organizations due to technical debt and patch management lags. We’re seeing industries such as critical oil pipelines, global meat processing plants, and even regional ferry transportation get hit with disruptive ransomware. Each attack provides additional proof that digital infrastructure is weak and needs maintenance so it will be strong enough to defend against these threat actors.

CSW’s analysts have been conducting in-depth research on ransomware and attack trends for the past year. We have delved deep into ransomware attacks, exploits, Advanced Persistent Threat (APT) groups, exploit kits and attack patterns that occurred in the last two years and we recently published our findings in a Ransomware Spotlight Report. The report covers the latest attacks and ransomware trends, and provides actionable insights for organizations to prioritize vulnerabilities for patches.

Rapid Rise in Ransomware

Remote working has resulted in weaker controls and more public-facing RDP servers, thus creating the ideal environment for ransomware to thrive. Predictably, this led to an increase in ransomware attacks since 2020.

We have been tracking ransomware associations with vulnerabilities since 2019, when RiskSense published its first Ransomware Spotlight Report. CSW’s analysts have noted that the number of vulnerabilities associated with ransomware rose from 57 in August 2019 to 223 in December 2020. By the first quarter of 2021, we found that the number of vulnerabilities had increased to 260, clocking a 17% increase!

Currently, ransomware attackers are spoiled for choice with 260 vulnerabilities to compromise and can easily launch crippling ransomware attacks.

So, what should organizations fix first to avoid becoming the next ransomware victim?

Our researchers had highlighted 132 vulnerabilities trending as ransomware targets in Q1 of 2021. These key vulnerabilities are weaponized and have active exploits; they should be at the top of every organization’s remediation list.

Although every vulnerability tied to ransomware should be considered a high exposure risk to an organization, we recommend that these 132 issues be prioritized for patches because they have been exploited actively by attackers from 2018 to 2021 (Quarter 1).

If organizations were to rely solely on CVSS scores to prioritize and patch vulnerabilities, they would still be exposed to ransomware. We say this because of the following reasons:

  • Only 65% of vulnerabilities tied to ransomware have a CVSS v3 score. Approximately 25% of these vulnerabilities are rated as critical and 10% as high. Therefore, if organizations were to patch critical and high vulnerabilities, they would get only 35% coverage against ransomware and still be vulnerable to attacks.
  • While 99% of the vulnerabilities have a CVSS v2 score, only 70% are rated as high, and if only these are prioritized for patching, the 25% of vulnerabilities rated as medium and 3% rated as low will remain unaddressed, enabling attackers to launch ransomware attacks.

Note: 2% of vulnerabilities do not have CVSS v2 score.

To keep it simple, organizations need continuous threat contexts and proactive alerts to patch vulnerabilities, which are fast becoming cannon fodder for ransomware.

Ransomware is not particularly clever, but ransomware families share and leverage 260 vulnerabilities.

Exploit Kits, Ransomware Families, and APT Groups

Our research also focused on the exploit kits commonly used by attackers. Exploit kits are automated tools used by hackers to exploit a vulnerability and then deliver malware or ransomware payloads. They target common software products from vendors such as Adobe, Flash, Java, Microsoft, and Silverlight.

Essentially, these are packaged executables, built as layered vulnerability attacks providing all the tools needed to attack an organization.

We identified 32 commonly used exploit kits and three new kits used by attackers in Q1 of 2021.

Top 5 Commonly Used Exploit Kits New Exploit Kits Identified in Q1 of 2021
  1. RIG Exploit Kit
  2. Nuclear Exploit Kit
  3. Angler Exploit Kit
  4. Neutrino Exploit Kit
  5. Fallout Exploit Kit
  1. EternalRomance Exploit Kit
  2. LCG Kit Exploit Kit
  3. Sibhost Exploit Kit

 

In December 2020, we identified 125 ransomware families that were using 223 vulnerabilities to attack their targets. In 2021, this number rose to 140, clocking a 12% increase! The infamous DarkSide ransomware that recently stalled Colonial Pipeline and disrupted gasoline supply in the US is one among the 140.

Our researchers have also been closely monitoring the mushrooming of APT groups and their affiliations to hostile nation-states for more than a year. APT and ransomware associations increase the power of this threat by several notches. These threats are called “persistent” for a reason. APT groups are seemingly well-funded, often, by nation-states who hire them to conduct deep targeted attacks. Therefore, they are not solely motivated by monetary incentives. Their focus is on government entities, critical infrastructure, and Fortune 500 companies to spy and steal sensitive information within Pharma, Energy, and other sectors.

Our Spotlight Report listed 33 APT groups, the ransomware families they are associated with, and the CVEs they exploit. In the first quarter of this year, we spotted a new association to the APT group Viking Spider, which used CVE-2017-0213 to launch attacks in Microsoft Windows Servers. (Download Q1 report for more information.)

CWEs Enabling Ransomware

Lastly, we also analyzed how and why ransomware attackers can exploit weaknesses in applications and operating systems and uncovered many insights that would be useful for software developers.

Our report identified the top five vulnerabilities in the Common Weakness Enumeration (CWE) that the attackers are abusing are CWE-119, CWE-20, CWE-264, CWE-94, and CWE-200.

In the past quarter, two new CWE IDs were introduced: CWE-295 and CWE-611. CWE-295 falls under the A3 category of the Open Web Application Security Project’s (OWASP) top ten vulnerabilities in 2017, indicating sensitive data exposure risk.

Ransomware-as-a-Service (RaaS)

Ransomware-as-a-Service (RaaS) is another reason for the spate of attacks. Today, any malicious attacker with just a little technical knowledge can get an entire ransomware kit from a RaaS website and launch an attack. Each kit comes with detailed instructions on how to deploy the payload, making it extremely easy to launch an attack. The recent DarkSide Ransomware attack on Colonial Pipeline is a classic example of how mature RaaS has become. It is also an indicator of how sophisticated and customer-friendly RaaS is soon to become.

The Way Forward

When we noticed a marked spike in key index numbers, such as vulnerabilities, active exploits, APT groups, and ransomware families, we decided to release quarterly updates on ransomware to help organizations remediate and patch targeted vulnerabilities.

Ransomware is exponentially growing, and the 17% increase in vulnerabilities in Q1 of 2021 is not an encouraging sign. Today, our dynamic database of ransomware research remains the only single source for organizations to quickly understand their attack surface exposure and learn what contributes to ransomware growth. The only way to defend against this threat is to elevate cyber hygiene and adopt continuous risk-based vulnerability management that provides active threat contexts about ransomware.

Watch out for our next quarterly update to get the latest statistics, exploits, and trends on ransomware.

A longer version of this article will appear in the next issue of CISO MAG. Subscribe here.


About the Author

Ram Movva, the President and Co-founder of Cyber Security Works (CSW), is an industry expert in offensive security and intrusion detection. With a master’s degree from Georgia Tech, Ram was with TIBCO for over a decade. He was also part of the founding team at RiskSense, a risk-based vulnerability management company.

After spending 15 years in the US, Ram co-founded Cyber Security Works (CSW) in 2008. Under his strategic leadership, CSW has enabled companies worldwide to improve their security posture.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

New Cyber Espionage Group ‘BackdoorDiplomacy’ Found Targeting Diplomats and Telcos in Africa and ME

Cyber Espionage Campaign Naikon APT

Cybercriminals often leverage sophisticated deceptive techniques to evade detection from federal agencies. Many international cyberespionage campaigns were uncovered after they exploited the target or went undetected. Recently, security researchers from ESET discovered a cybercriminal operation targeting charitable groups, diplomatic organizations, Ministries of Foreign Affairs, telcos, and other companies in Africa, Europe, and the Middle East since 2017.

Dubbed “BackdoorDiplomacy,” the campaign targeted both Windows and Linux operating systems by exploiting vulnerable connected devices like web servers and management interfaces for networking equipment. Upon compromising a system, the attackers leveraged various open-source tools for scanning the environment and lateral movement. The threat actors achieved the interactive access in two ways:

  1. Through a custom backdoor “Turian,” which is derived from the Quarian backdoor.
  2. Through the deployment of certain open-source remote access tools, when more direct and interactive access is required. The attackers were also observed targeting removable media for data collection and exfiltration.

Targeting Unpatched Vulnerabilities

The researchers found that the operators behind BackdoorDiplomacy employed advanced tactics, techniques, and procedures (TTPs) to make their tracking more difficult. The group targeted servers with internet-exposed ports, by likely exploiting unpatched bugs or poorly enforced file-upload security.

BackdoorDiplomacy allegedly shares similarities with several other cyber campaigns, especially when it comes to the Turian and the Quarian backdoor.

“In one specific instance, we observed the operators exploit an F5 BIP-IP vulnerability (CVE-2020-5902) to drop a Linux backdoor. In another, a Microsoft Exchange server was exploited via a PowerShell dropper that installed China Chopper, a well-known web shell in use, by various groups, since 2013. In a third, we observed a Plesk server with poorly configured file-upload security execute another web shells similar to China Chopper,” the researchers said.

Red Team Tools Discovered

The BackdoorDiplomacy attackers employed open-source reconnaissance and red-team tools to evaluate the environment for additional targets of opportunity and lateral movement. The discovered tools include:

  • EarthWorm– A simple network tunnel with SOCKS v5 server and port transfer functionalities
  • Mimikatz– Various versions including SafetyKatz
  • Nbtscan– A command-line NetBIOS scanner for Windows
  • NetCat– A networking utility that reads and writes data across network connections
  • PortQry– A tool to display the status of TCP and UDP ports on remote systems
  • SMBTouch – Used to determine whether a target is vulnerable to EternalBlue

A red-team tool/toolkit is an offensive security platform used by red teamers (which are mostly cybercriminals) to perform advanced network operations and exploit the target.

Explaining about the BackdoorDiplomacy activities, Tony Anscombe, the Chief Security Evangelist at ESET said,

                                                                                            Video Courtesy: ESET

“BackdoorDiplomacy initial attack methodology is focused on exploiting vulnerable internet-exposed applications on web servers, to drop and execute a web shell. Post compromise, via the web shell, BackdoorDiplomacy deploys open-source software for reconnaissance and information gathering and favors the use of DLL search order hijacking to install its backdoor, Turian. Finally, BackdoorDiplomacy employs a separate executable to detect removable media, likely USB flash drives, and copy their contents to the main drive’s recycle bin,” the researchers added.

The Edward Don Ransomware Attack – A Reminder of Disruption Caused by Cyberattacks on Supply Chains

ransomware attack on Edward Don

Ransomware attacks targeted towards supply chains in the U.S. have spiraled indiscriminately in the recent past. The incidents are growing by the day, and now joining this long list is the popular foodservice supplier, Edward Don. The company did not publicly disclose anything about the security incident, but its employees have reportedly claimed that a ransomware attack has locked them out of their systems and forced them to decline orders until the systems are up again.

What’s Affected

Edward Don and Company is a known distributor of foodservice equipment and supplies in the U.S. Its portfolio includes products from kitchen supplies to flatware and bar supplies to dinnerware. Moreover, its clientele includes top U.S. hospitals, restaurants, hotels, and bars. Thus, a cyberattack on its systems meant significant disruption of the entire supply chain and its operations.

The ransomware attack that took place early last week has affected Edward Don’s networks, phone systems, and even the email services. According to the reports, the email service outage not only forced its employees to decline new orders but also compelled the firm to manage all communications for already placed and urgent orders to be carried out via private Gmail accounts.

Qbot Behind the Attack?

As there is no official statement issued by the company until now, the accurate details of the operators or the way in which the compromise took place is not yet clear. However, reports suggest that Qbot malware operators could be behind the attack.

Qbot malware is a banking trojan that has been active for over a decade and is known to regularly upgrade its malicious capabilities. Its operators steal users’ keystrokes, deploy backdoors, and spread malware payloads on compromised devices. Their primary targets have always been financial institutions across the U.S., however, of late, they seem to have begun working closely with ransomware gangs and their affiliates for increased monetary gains. In this new association, their job is to provide access to ransomware gangs to the compromised networks through which they can spread laterally and inflict severe damage. The combination of the attacks seems to be the exact strategy used in the ransomware campaign against Edward Don.

What the Expert Says

Troy Gill, Threat Hunter and Manager of the Zix I App River Research Team told CISO MAG:

The new attack on Edward Don continues to underline the significant disruption ransomware has had to critical infrastructure and the supply chain of organization in the U.S. This continues to add to the trend of “ransomware as a service”. 

Although it is not clear yet what ransomware operation has conducted the attack, it is said to have been infected by the Qbot malware based on their adversarial visibility. Qbot is known to partner with ransomware operations to supply them remote access to infected networks and we have seen a ramp-up in Qbot activity following the takedown of Emotet early this year. Ransomware operators that are reliant on buying access to compromised systems will surely turn to alternatives such as Qbot.  Organizations need to identify and block these attacks daily which are mostly leveraging malicious macro-enabled XLS files.

Remote work has continued to add to the rise of attacks and thus email still remains the top attack vector for advanced threats. Organizations must mandatorily enforce two-factor authentication (2FA) or a multi-layered protection approach (MFA) that better safeguards the entire network – including the company, employees, and end customers. Additionally, organizations should regularly run security audits to identify suspicious user behavior.

Related News:

Qbot Malware: An Old Banking Trojan Back with New Capabilities

Attackers Target Volkswagen Vendor; 3.3 Mn Audi Customers Impacted

Volkswagen and Audi data breach

Security risks are everywhere, they could be from state actors or insiders (employees) you are working with. As cyber risks are evolving by the day, perimeter security is not enough. Organizations must ensure that their third-party agencies, with whom they share corporate data, follow necessary security precautions and strictly abide by their security compliance. A simple mistake can cost companies a huge fortune.

Recently, Volkswagen revealed that a data breach at its third-party vendor affected more than 3.3 million customers and potential buyers of Audi in the U.S. and Canada. According to the official statement, the exposed information was gathered for sales and marketing from 2014 to 2019. It was found that threat actors accessed the customer data when the vendor left it unsecured at some point between August 2019 and May 2021.

Sensitive Data at Risk

The exposed data included contact and vehicle information relating to Audi customers and interested buyers such as first and last name, personal or business mailing address, email address, phone number, vehicle purchased, leased, inquired about, vehicle identification number (VIN), make, model, year, color, and trim packages.

In some cases, the data also included more sensitive information like eligibility for purchase, loan, or lease, driver’s license numbers, birth dates, social security numbers, insurance details, bank account numbers, and tax identification numbers.

While the attackers behind the data breach are unknown, Volkswagen has commenced an investigation to determine the nature and scope of the incident and reported the issue to the affected customers and the federal law enforcement authorities. “We take the safeguarding of your information very seriously. We have informed the appropriate authorities, including law enforcement and regulators. We are working with external cybersecurity experts to assess and respond to this situation and have taken steps to address the matter with the vendor,” the company said.

What should the affected users do?

Threat actors could exploit the leaked data in many ways, as the sensitive data was unsecured for a long time. Customers need to be vigilant about any suspicious emails or SMSs claiming to be from Audi or Volkswagen, as they could possibly be malicious. Remember to:

  • Look out for spam emails or other communications requesting sensitive personal information.
  • Be cautious when opening links or attachments from unsolicited third parties. Unsolicited emails could contain malware or other types of phishing links.

Data Leaks Cost Companies High-Interest Rates

A recent study from the American Accounting Association revealed that there is a very real cost for companies that can’t protect their customers’ personal information. Reportedly, banks charged higher interest rates to companies that suffered a data breach, compared to companies that had not. Besides, the effect could be high if the breach involved data of a large number of customers and even higher if the breach was a result of a cybercriminal act, rather than a mistake.

How is Automation Helping in Security?

If you are looking at automation in regard to PKI, there are four areas in security where automation can be applied: Efficiency, Security, Crypto-agility, and Compliance.

Here is an example where automation helps. As we are moving towards digital transformations, the number of certificates being used in any type of enterprise is increasing.  Contradictory to that, the life cycle of certificates and their expiration of those certs are getting smaller. That means you need to deal with more certificates and short life certificates. With automation, you can replace those certificates in no time and prevent outages in case an administrator forgets about expired certificates and is not able to replace those.

Human errors are playing a big role in security. Imagine that you have thousands of certificates, and you need to configure each one of those manually and individually. This will create a surface of error where an individual will inject inaccurate data into a certificate request before the certificate is issued.

Automation enables that IT admin to set policies and rules and then request the certificate and minimize the error.

Another area where automation could help is Compliance. The CA/Browser Forum occasionally comes out with new baseline requirements and policies. So, if the certificates are already in production and new certificates are about to be issued, these will be required to be compliant with the new baseline requirements. This often happens overnight and sometimes, they have more time to plan for it. But regardless, this is where automation can help — with larger scale certificate deployment. It allows those certificates to be automatically renewed and be compliant in case there is a new compliance policy.


About the Author

Avesta Hojjati is the Head of R&D at DigiCert, where he manages the advanced development of cybersecurity products. Before joining DigiCert, Avesta was part of the Symantec and Yahoo security teams, as well as operating his own cybersecurity startup. Avesta focuses on applied cryptography, blockchain, post-quantum crypto, and IoT security. Avesta earned his Masters in computer science with a concentration on security from the University of Illinois at Urbana Champaign, and he’s currently completing his Ph.D. dissertation on applications of blockchain and IoT in manufacturing.

Disclaimer

Views expressed in this article are personal.

DoJ Takes Down Largest Stolen Credentials Marketplace ‘Slilpp’

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

Most cybercriminals and ransomware groups operate from different locations, making it hard for law enforcement agencies to track them down. Several governments are making international cybersecurity operations to deter cyberattacks and nab the threat actors responsible for them.

Recently, the U.S. Department of Justice (DOJ) announced that a multinational operation took down Slillpp, an infamous underground marketplace of stolen login credentials. The cooperation, which involved the law enforcement agencies from the U.S., Germany, the Netherlands, and Romania, seized servers that hosted Slilpp’s online infrastructure and its domain names.

“The Slilpp marketplace allegedly caused hundreds of millions of dollars in losses to victims worldwide, including by enabling buyers to steal the identities of American victims. The department will not tolerate an underground economy for stolen identities, and we will continue to collaborate with our law enforcement partners worldwide to disrupt criminal marketplaces wherever they are located,” said Nicholas L. McQuaid, Acting Assistant Attorney General of the Justice Department’s Criminal Division.

Slillpp’s Cyber Activities 

Slilpp’s online marketplace has been trading stolen login credentials, including usernames and passwords for bank accounts, online payment accounts, mobile phone accounts, retailer accounts, and other online accounts since 2012.

The fraudulent platform also served as a data broker allowing vendors to sell, and customers to buy, stolen/leaked credentials. Most cybercriminals later used those login credentials to conduct unauthorized transactions on targeted users. The U.S. law enforcement charged over a dozen individuals in connection with the Slilpp marketplace.

Huge Number of Credentials for Sale

Most of the threat actor groups have a presence in underground marketplaces where they share details related to stolen data, malicious tools, malware samples, and hacking targets. The DoJ found stolen account login credentials for over 1,400 account providers available for sale. While the full impact of Slilpp is still unknown, the agency stated that the stolen login credentials sold over the Slilpp platform caused over $200 million in losses in the U.S.

“With today’s coordinated disruption of the Slilpp marketplace, the FBI and our international partners sent a clear message to those who, as alleged, would steal and traffic in stolen identities: we will not allow cyber threats to go unchecked. We applaud the efforts of the FBI and our international partners who contributed to the effort to mitigate this global threat,” said Acting U.S. Attorney Channing D. Phillips of the District of Columbia.

Are You Ready for Risk Quantification?

cybersecurity practices, Automotive Cybersecurity

Are you ready for risk quantification? Follow this decision tree to understand if you’re ready for risk quantification today – or if not, what actions you can take to enhance insights today that will support risk quantification in the future. Use this infographic to:

  • Identify how you score risk today
  • Qualify what your immediate goals are
  • Realize tactics that you can leverage now

 SPONSORED CONTENT 

Forrester’s 2021 Predictions outline an uptick in the requirements for businesses and audit professionals to quantify risk. “Risk quantification solutions that provide insights into the criticality of assets and potential impact of an issue in real-time with business context will help security leaders determine what stays, what goes, and where limited increases should go. Examine risk quantification solutions — and their substantial required dependencies — to move beyond the tried-and-true basic business case that was sufficient during the growth years.”

Risk quantification can help your organization go beyond traditional risk matrix scoring, applying values to contributing factors of risk – and calculating them across what can be massive data loads to help you gain risk insight on the risk posture of your organization.

But for many organizations, executing a risk quantification exercise can be a resource-intensive exercise, that may or may not scale or provide the insightful ROI expected. Robust statistical models certainly have valid uses – and can help identify a dollar amount to communicate to your board or leadership. They can be a massive initiative to first get off the ground and secondly scale and maintain across various aspects of your business. At the end of the day, the inputs can still be prone to a subjective perspective. But Risk Quantification doesn’t have to be a heavily complicated exercise – you can jump into risk quantification without jumping into the deep waters of complex statistical models.

Review this infographic to understand where you are in evaluating if your organization is ready for risk quantification and what you can action today.

Risk Quantification

Get additional information on using risk metrics, collecting risk insights, and improving risk quantification in our webinar, Risk Clarification: Eliminate Your Fears and Doubts About Risk Quantification.

Cybersecurity Posture of Commonwealth Entities Continues to Improve: Report

Remote Access Scams

Last year, owing to the rapid surge in cybercriminal activities in Australia, Prime Minister Scott Morrison announced that the country had allocated a budget (also known as the CESAR package) of AUD 1.66 billion (approximately $ 1.19 billion)  to bolster the cybersecurity defenses of Australian enterprises and governmental bodies. Thanks to this budget allocation, Australia invested and initiated several campaigns to raise its cyber resilience. To name a few:

  • AustCyber invested $1.22 million in the Aushield Defend cyberthreat intelligence platform. Part of these funds was directed towards a TAFE cybersecurity education project, which is a University of Adelaide initiative to provide schools with cyber resources, and a cybersecurity job platform.
  • The government introduced a basic cybersecurity standard for all IoT devices in the country called the “Code of Practice.”
  • The ACSC allied with the country’s leading telecommunication giant, Telstra, to eradicate phishing texts spoofing.
  • The Australian government entered into a bilateral agreement with the U.S. for jointly developing a cyber training platform.
  • Also, with the help of industry experts, the federal government defined guidelines to thwart ransomware attacks aimed at the country’s businesses and public domain entities.
  • Apart from this, the ACSC undertook other programs like the Cyber Maturity Measurement Program (CMMP), the ACSC Cyber Security Uplift Services for Government (ACSUSG), and the Cyber Security Aftercare Program (CSAP) in 2020, to uplift the cyber defense posture.

All these efforts have led to the growth in the Australian government’s cybersecurity maturity and the overall resilience of all commonwealth entities in the past year, and the Commonwealth Cyber Security Posture Report for 2020,” concurs with this.

Commonwealth Cyber Security Report 2020

The said report, which informed the Australian parliament of the overall cybersecurity posture of all Commonwealth entities, highlighted that there has been a significant improvement in the cybersecurity posture across the board. However, to counter the evolving threats, it suggested that Commonwealth entities should further build resilience and mature faster than the threat actors.

While the report says, “no single mitigation strategy can comprehensively prevent cybersecurity incidents, the implementation of the ‘Essential Eight’ mitigation steps can help the entities protect from a range of cyberattacks”. For example, 12% of the entities who improved application hardening got better, and similarly, 10.5% who did application control, and 9.5% who restricted admin privileges properly, improved their overall cybersecurity stance.

The Plan Ahead

In line with its Cyber Security Strategy 2020, the ACSC said, “In 2021, the Australian government will focus on a range of additional areas of effort to continue to increase the cybersecurity posture of Commonwealth entities. The CESAR package will maintain and enhance the cybersecurity capabilities of the ACSC, and the assistance provided to Australians over the next decade.”

To pave the road for added cyber resilience, the Australian government will additionally focus on the following initiatives:

  • Harden Government IT (HGIT)
  • Cyber Threat Intelligence (CTI) sharing
  • Host-based sensors program
  • Cyber Toolbox pilot program
  • Protection of COVID-19 vaccine
  • Commonwealth Cybersecurity Posture Reporting