Home Blog Page 80

Diversity is Our Prime Asset for Cybersecure Digitalization

diversity

We live in a complex globalized world that’s in the midst of a digital revolution, and that means massive changes for humanity. Digitally networked societies bring technological, economic, and human challenges – and at the same time, they’re faster and more powerful. On the one hand, there’s isolationism, nationalism, and the risk of complex cyberattacks, and on the other hand, there are vast opportunities for people, institutions, and companies. The energy business is also currently undergoing a technological revolution. And the more diverse the challenges in this dynamic environment, the more varied our responses to them need to be. And those responses should come from an entire network that crosses company and industry boundaries. It’s only by joining forces globally that we can make the most of the opportunities offered by digitalization and protect our critical infrastructures.

By Dr. Judith Wunschik, Chief Cyber Security Officer and Global Head of Cybersecurity, Siemens Energy

Diversity is a factor for success. In a team, the more diverse the members’ backgrounds are, the more varied their ideas, thinking, and solutions will be – and the greater their prospects for success and achievement. That finding has been reconfirmed in a study by the Boston Consulting Group that’s in the midst of a digital revolution, and that means massive changes for humanity. Digitally networked societies bring technological, economic, and human challenges – and at the same time, they’re faster and more powerful. On the one hand, there’s isolationism, nationalism, and the risk of complex cyberattacks, and on the other hand, there are vast opportunities for people, institutions, and companies. The energy business is also currently undergoing a technological revolution. And the more diverse the challenges in this dynamic environment, the more varied our responses to them need to be. And those responses should come from an entire network that crosses company and industry boundaries. It’s only by joining forces globally that we can make the most of the opportunities offered by digitalization and protect our critical infrastructures.

Diversity is a factor for success. In a team, the more diverse the members’ backgrounds are, the more varied their ideas, thinking, and solutions will be – and the greater their prospects for success and achievement. That finding has been reconfirmed in a study by the Boston Consulting Group (BCG). The BCG team found “a strong and statistically significant correlation between the diversity of management teams and overall innovation. (Surveyed) companies that reported above-average diversity on their management teams also reported innovation revenue that was 19 percentage points higher than that of companies with below-average leadership diversity – 45% of total revenue versus just 26%.”[1]

I also think that greater diversity has a very positive influence on our collaboration. The way we deal with others is friendlier, more empathetic, and less biased than in less diverse teams. But even though it’s a recipe for success, people don’t practice diversity everywhere, even though it’s a major strength in our globalized world. Companies can, and should make the most of that strength, especially if they have to ensure secure critical infrastructures – like the reliable, resilient generation and distribution of energy.

In the cyber world, many roads lead to Rome

But from a manager’s viewpoint, it’s not always easy to put diversity into practice. It means more than just achieving a good balance between genders, although that’s tricky enough in itself. A diverse team reflects our complex world and is open to everyone, no matter their religion, ethnicity, culture, or social group. Today diversity in business also includes employees of different ages and different educational backgrounds, sexual orientations, and disabilities. So, diversity naturally also entails inclusion. But in practice, this means that to fill openings from a pool of diverse candidates, you first need an appropriate selection of people to choose from…To read the full story, subscribe to CISO MAG.

This story first appeared in the March 2021 issue of CISO MAG.


About the Author

Judith Wunschik_CCSO_Siemens Energy (3)Dr. Judith Wunschik is the Chief Cyber Security Officer and Global Head of Cybersecurity for Siemens Energy since October 2019. She is accountable for securing Siemens Energy’s business operations, products, data, and assets as well as for ensuring compliance with cybersecurity regulations. She is serving as a thought leader for cybersecurity as well as an advisor to Siemens Energy’s senior leadership on cyber risks related to products, services, and operations. In her current professional role, she is building the future global cybersecurity capabilities for Siemens Energy, including Information Security Operations, Supply Chain Security Management, and Product & Solutions Security Services.

Previously, Dr. Wunschik held senior management roles in the European banking sector, most recently as Chief Information Security Officer for ING Germany and ING Groep N.V. in Amsterdam. She is highly experienced in working with deeply skilled expert groups and is a renowned public speaker and valued member of prestigious international security committees. Dr. Wunschik holds a Ph.D. in Solid State Physics and Computational Theoretical Physics from the University of Erlangen-Nuremberg.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Step Up Cybersecurity! White House Warns About Rising Ransomware Attacks

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

Though government security policies may motivate organizations to boost their cybersecurity standards, ultimately it is a company’s proactive measures that prevent cyberattacks. Irrespective of size, it is about time that organizations take cyberattacks seriously and enhance their security defenses.

Recently, the White House asked corporate executives and business leaders to step up their security measures amid rising ransomware attacks in the country. In an open letter,  Anne Neuberger, the National Security Council’s Chief Cybersecurity Advisor, said that strengthening the nation’s resilience from cyberattacks is a priority for the government as ransomware incidents have increased significantly in recent times.

“The threats are serious, and they are increasing. We urge you to take these critical steps to protect your organizations and the American public. The U.S. Government is working with countries around the world to hold ransomware actors and the countries who harbor them accountable, but we cannot fight the threat posed by ransomware alone. The private sector has a distinct and key responsibility. The federal government stands ready to help you implement these best practices,” Neuberger said.

Neuberger stressed that the Federal government is working with global industry leaders to deter ransomware operators and disrupt their networks. It is also working with international partners to hold countries that harbor ransomware actors accountable, developing cohesive and consistent policies towards ransom payments, and enabling rapid tracing and interdiction of virtual currency proceeds.

“All organizations must recognize that no company is safe from being targeted by ransomware, regardless of size or location. But there are immediate steps you can take to protect yourself, as well as your customers and the broader economy. To understand your risk, business executives should immediately convene their leadership teams to discuss the ransomware threat and review corporate security posture and business continuity plans to ensure you can continue or quickly restore operations,” Neuberger added.

Best Security Practices

The U.S. government also recommended certain best security practices to help organizations focus and make rapid progress on mitigating cyber risks. These include:

  • Implement the five best practices from the President Biden’s Improving the Nation’s Cybersecurity Executive Order, which include: Implementing multifactor authentication, endpoint detection, incident response, encryption, and an empowered security team.
  • Backup your data, system images, and configurations, regularly test them, and keep the backups offline
  • Update and patch systems promptly
  • Test your incident response plan
  • Check Your Security Team’s Work
  • Segment your networks

The directive from the White House comes after ransomware operators recently disrupted operations of the world’s largest meat processing giant JBS and the biggest U.S. fuel supplier Colonial Pipeline.

Lack of User Verification Policy for Password Reset Could Lead to Social Engineering Attacks

User Verification Policy, zero trust approach

Despite the rise in identity theft across various sectors globally, some organizations are still not maintaining a robust verification process to secure their employee data. According to a survey from Specops Software, nearly 48% of organizations don’t have a user verification policy in place for incoming calls to IT service desks. The survey, based on the responses from more than 200 security leaders from the private and public sectors in North America and Europe, found that 28% of the companies that are having user verification policies are not satisfied with their current policy due to security and usability issues.

It was also found that most organizations rely on knowledge-based questions like what is employee ID, manager’s name, or HR-based information like what an employee’s date of birth or address is. This data can be easily obtained by cybercriminals.

Despite several self-service password-reset options, most organizations go to the IT help/service desk for resetting passwords. Threat actors often target an unwitting remote workforce with various social engineering attacks by impersonating an IT service desk. Besides, the National Institute of Standards and Technology (NIST) urged organizations to avoid using knowledge-based questions, for which the answers are based on static information pulled from Active Directory or HR systems.

What is a user verification policy?

A user verification or authentication policy is a process to verify a user who is attempting to access services and applications. The verification can be performed via a variety of authentication methods like entering a password, using two-factor authentication (2FA), or multi-factor authentication (MFA) methods. Verifying users helps determine the appropriate access privileges to the users and also minimizes the risk from hacker intrusions. With the spike in digitalization, organizations must ensure that the right users are given access to the critical digital infrastructure.

“Based on our recent findings, password resets at the service desk are a serious vulnerability for organizations of all sizes. In the absence of a self-service password reset solution, it is up to the service desk agent to verify that the caller is the legitimate owner of the account before issuing a new password. Unfortunately, without a secure verification policy in place, service desk agents can provide account access to unauthorized users without even knowing it – exposing businesses to an increased risk of costly cybersecurity breaches,” said Marcus Kaber, CEO of Specops Software.

Related Story: How to Leverage a Contact-free Authentication Solution for the Workforce

The Curious Case of WhatsApp and Government of India Highlights the Broader Traceability Concerns

WhatsApp and Indian governmentWhatsapp Hack

Facebook-owned WhatsApp and the Indian government have been at loggerheads since January this year. However, with no party ready to back down, the WhatsApp and the Indian government battle reached the next level in the Delhi High Court, earlier last week. The E2E encryption, which most social media apps use helps protect its users’ data (in motion) from being intercepted or adulterated. Based on this, WhatsApp has argued to the court that the Indian government’s new IT Rules are difficult to implement and can undermine users’ privacy.

The One Where It All Began

The tussle between the two Goliaths began with the unveiling of WhatsApp’s latest privacy policy changes for Indian users. The Indian government termed the privacy updates “Discriminatory” and wrote a letter to WhatsApp CEO, Will Cathcart for its immediate withdrawal. Since then, the two heavyweights have thrown punches at each other in the form of multiple affidavits and counter-affidavits filed with the Delhi High Court addressing different issues relative to users’ “Right to Privacy.”

In the latest round of allegations, the instant messaging giant challenged the government in court alleging that its new IT rules (Intermediary Guidelines and Digital Media Ethics Code Rules 2021) could become weapons of “mass surveillance” and undermine the users’ “right to privacy.” The government was not amused because the affidavit was filed on  May 25, a day before the new rules came into force. To clear the air, the government issued a statement saying,

Right to Privacy is a fundamental right and the government respects it. It has no intention to violate it.

But are these justifications enough? What are the new rules? What’s the opposition for? Will these rules help us in maintaining digital hygiene? Or are they simply what WhatsApp suggests – means of surveillance by the government? Questions are many, but answers are few. Here are some key points that may help you decide:

WhatsApp’s Latest Accusation Against GoI

The first accusation made by WhatsApp towards the government is based on a four-year-old verdict on Justice K S Puttaswamy vs Union of India. WhatsApp alleged that the new rules are unconstitutional and undermine an individual’s “Right to Privacy,” which the constitution itself has bestowed upon its citizens as per the 2017 verdict.

Impact: If the new rules come into force, they will make WhatsApp employees liable to criminal proceedings for non-compliance, which again bypasses a few other constitutional rights of its employees since they are citizens of India. Thus, WhatsApp wants the court to ensure that this clause in the amended rules does not come into force to safeguard both employee and its user interests.

The Trouble with Traceability and E2E

The biggest issue that WhatsApp has with the new rules is “Traceability.” In a blog post, WhatsApp explained how the concept of traceability breaks end-to-end encryption (E2E) that was implemented throughout the app’s ecosystem back in 2016. The E2E helps protect its users’ calls, messages, photos, videos, and voice data from being intercepted or adulterated. Data is encrypted the moment it leaves the sender’s device and decrypted only on the intended receiver’s device. Even WhatsApp is unaware of the data that is transmitted between two people and/or groups.

Moreover, WhatsApp also argues that the traceability clause is currently a flawed concept. For example, if a user forwards a message received from another source, that source can be tracked. However, if a user copy-pastes a message from another source and sends it to a recipient, the person who copied and sent the data becomes the originator of the message. This is technically wrong as the message could have been sent for fact-checking or simply out of concern towards the recipient.

Impact:  WhatsApp says that breaking E2E would mean the end of privacy and indirectly mandate mass surveillance. It will have to add a “fingerprint” to not just one or two but all user messages, which will not only keep their data vulnerable to interception and exploitation from potential threat actors but also undermine their users’ privacy round the clock.

Additionally, if traceability requirements are to be enforced, WhatsApp will have to create an India-only app as the E2E is a default feature and a long-standing benefit of its worldwide messaging platform. Records suggest that WhatsApp currently has 503 million users in India and thus it could be a cumbersome yet mandatory process.

Government’s Stance

In response to WhatsApp’s allegations, which were specifically aimed at Rule 4(2) of the Intermediary Guidelines, the government said, “The(se) rules have been framed after consultation with various stakeholders and social media intermediaries, including but not limited to WhatsApp. After October 2018, no specific objection has been made by WhatsApp to the Government of India in writing relating to the requirement to trace the first originator in relation to serious offenses. WhatsApp’s refusal to comply with the guidelines is a clear act of defiance.”

Shri Ravi Shankar Prasad, Minister of Electronics and Information Technology and Communications, and Law and Justice of India, said,

The entire debate on whether encryption would be maintained or not is misplaced. Whether “Right to Privacy” is ensured through using encryption technology or some other technology is entirely the purview of the social media intermediary. It is WhatsApp’s responsibility to find a technical solution, whether through encryption or otherwise, that both happen.

Impact: According to the government, Under Rule 4(2) of the guidelines, tracing the first originator of the message, tweet, or post will only be done under select circumstances. It condemns WhatsApp’s accusations on GoI’s 24/7 vigilance on its users. The government said, “We do not wish to track all messages.” It added that the “special” circumstances for tracking can be invoked “only for prevention, investigation, punishment, etc. of inter alia an offence relating to sovereignty, integrity and security of India, public order incitement to an offence relating to rape, sexually explicit material or child sexual abuse material punishable with imprisonment for not less than five years.”

However, WhatsApp argues that this can lead to imprisonment of innocent people who might not have perpetrated or originated the message, but only propagated it – maybe mistakenly. This can cause chaos and is harmful to the democratic rights of people in the broader view.

What Other Social Media Intermediaries Think

The law applies not just to WhatsApp but all “significant social media intermediaries” – that is, the ones with more than 5 million users. This includes the likes of Google, Twitter, and even WhatsApp’s parent company Facebook.

The first to offer a statement about the new intermediary laws was Google’s CEO, Sundar Pichai, who hails from India. Although he retracted from choosing which side he was on, Pichai, however, did say, “Google is committed to complying with local laws and engages constructively with governments as they scrutinize and adapt regulatory frameworks to keep pace with the fast-evolving technology landscape.” He added, “Be it Europe with the copyright directive or India with information regulation, etc., we see it as a natural part of societies figuring out how to govern and adapt themselves in this technology-intensive world.”

On the other hand, Twitter has asked for a three-month extension to comply with the new rules which the government claimed was “rhetorical” to say the least. The Indian government had introduced these rules in February this year and had already given a three-month timeframe to comply with the changes. Thus, asking for additional time does not make any sense. Moreover, Twitter said it had concerns over two things: the possible impact of these curbs on its users’ “freedom of expression” and the criminal liability of their compliance officer for content posted on their platform.

Impact: Although there is little choice for intermediaries for compliance, this can lead to intimidation from the law enforcement authorities as was seen in the incident where the Special Cell of the Delhi Police visited offices of Twitter India in Delhi and Gurgaon with regards to its probe into the Congress toolkit conspiracy.

Expert Opinion

The Internet Society, a non-profit organization, has reiterated its concerns shared by cybersecurity experts, that to comply with these traceability requirements, platforms may be forced to undermine end-to-end encryption. In an open letter to the MeitY, cryptographic and security experts warned that pursuing message traceability would undermine digital security.

In a statement given to CISO MAG, the Internet Society said, “WhatsApp’s lawsuit is the first by a major social media company against India’s revised Information Technology (Guidelines for Intermediaries and Digital Media Ethics Code), Rules 2021 which were announced in February this year. The revised Guidelines include a traceability requirement, or the ability to track down the first originator of a particular piece of content or message.

While the Ministry of Electronics and Information Technology (MeitY) has emphasized that encryption is not a target in these new Guidelines, cybersecurity experts both in India and abroad have pointed out that it is simply not possible for companies such as WhatsApp to try to comply with the new guidelines without suppressing at least some features that are integral for strong encryption to work properly.

In fact, a 2020 report from these experts warned that “to comply with traceability requirements, platforms may be forced to enable access to the contents of their users’ communications, breaking end-to-end encryption and considerably weakening the security and privacy of their product.

With the traceability requirement, the government appears to be compelling popular online platforms to weaken encryption without explicitly telling them to do so. The likely outcome will be for those platforms to stop offering end-to-end encrypted services altogether. End-to-end encryption is the gold standard for keeping Internet users and systems secure and an essential aspect of digital privacy which is imperative to the hundreds of millions of people in India who use Whatsapp.”

Conclusion

This is not the first time that WhatsApp has faced governmental pressure for tracing requirements. Earlier, Brazil had also asked the messaging giant to do the same, to which it replied, “It erodes privacy.” Whether the intermediaries relent to the pressure of compliance or the GoI eases down on them is something that only time can tell. However, users across India are curious about the “suggested” ban on WhatsApp and other social media giants. The government has not mentioned whether it will completely ban these platforms but has hinted about taking away the safe harbor given to them under the IT Act.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 

Ransomware: A Pandemic Plaguing the Digital World

Hive Ransomware

It seems the bad guys in cyberspace decided to forego their holidays and work harder at the end of 2020. While the world was winding down work and preparing to spend time with family, it suddenly faced a wave of ransomware attacks. Yes, these attacks occurred throughout the year, grabbing headlines week after week. But no one expected this during the holiday season. For the opportunists, this was seen as the best time to attack, when the IT staff were going on vacation. Indeed, ransomware attacks have become a booming business in the underground market. The boost in digitization has further catapulted ransomware to be used as-a-Service (RaaS) and has now become the hot favorite for being deployed during a cyberattack.

By Mihir Bagwe, Sr. Technical Writer, CISO MAG

Ransomware attacks are happening daily around the globe. According to a recent report,  more than 500 successful ransomware attacks were officially reported in over 45 countries in the past year (H2 2019 to H1 2020). The financial damages accounted for over $1 billion ($1,005,186,000) and a future forecast predicts this number to rise 20 times to $20 billion by 2021. Experts believe this number could double-up or even rise fivefold if all attacks are reported.

Ransomware in the Year Gone By

While the COVID-19 pandemic took a toll on small and big businesses alike, cyberspace had to deal with a digital pandemic. Ransomware operators targeted health care institutes, banks, government agencies, and universities. Unsettled employees — many of whom were working from home — and a distributed and depleted workforce, meant an increased likelihood of an incident happening, and it did.

Here is a list of the top ransomware attacks and related incidents that sent aftershocks through the business world in 2020:

January 2020
  • Travelex, a major foreign currency exchange company, was hit by a cyberattack (which was later reported as a ransomware attack).
  • Hackers demanded $10,000 in Bitcoin from Richmond Community Schools because a hacking incident happened on their server.
February 2020
  • The University of Maastricht paid 30 Bitcoin ransom amounting to $220,000 (€200,000) for unlocking the systems and servers compromised during the ransomware attack.
  • Ryuk ransomware campaign targeted Port Lavaca City Hall, incurring a bill of $50,000 to the City.
  • Mailto ransomware hit Toll Group, affecting deliveries across Australia.
March 2020
  • Finastra shut down its servers after reportedly being hit by a ransomware attack.
  • Simon Fraser University of Canada hit by a ransomware attack, resulting in a data breach.
April 2020
  • Zaha Hadid Architects suffered a ransomware attack that disrupted the remote operations of its 348 London-based employees working remotely amid the pandemic.
  • Danish Agro’s computer systems were targeted by ransomware.
May 2020
  • Unacademy suffered a data breach, which saw 22 million of its user records being sold on the dark web.
  • French flooring company Tarkett has confirmed being hit by a cyberattack.
June 2020
  • Operations of the Japanese automobile giant, Honda, were reportedly disrupted in parts across Europe, Japan, and the U.S., due to Snake ransomware (also known as EKANS).
  • Cybercriminals targeted Life Healthcare in South Africa.
July 2020
August 2020
  • Jack Daniel’s and Carnival Cruise hit with ransomware attacks.
  • The University of Utah paid $457K to restore data post a ransomware attack.
  • Ransomware attack reported on Indian e-Payments and e-Commerce app Paytm Mall.
September 2020
October 2020
  • Ransomware gang feasted on popular Indian sweets and snacks brand Haldiram.
  • A tsunami of Ryuk ransomware attacks hit U.S. hospitals.
November 2020
  • The Maze ransomware gang announced retirement.
  • Israeli firms targeted with a new strain of ransomware named “Pay2Key.”
  • Web hosting provider Managed.com suffered a ransomware attack.
December 2020
  • Egregor ransomware targeted HR agency Randstad.
  • Conti ransomware gang took down Sangoma Technologies.
  • The Institute for Security and Technology (IST) constituted a Ransomware Task Force (RTF).

So, how do you tame this raging bull? The only way is to take the bull by its horns…To read the full story, subscribe to CISO MAG.

This story first appeared in the February 2021 issue of CISO MAG.


About the Author
CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

Battle of Galaxy Data Breach Affects 5.9 Mn Gamers

battle of galaxy game

While cybercriminals are constantly trying to find security loopholes in organizational networks, accidental data leaks and database misconfigurations are an easy option for them to pilfer sensitive data. Cybersecurity experts from WizCase recently uncovered a leaky database belonging to the popular mobile game Battle for the Galaxy.

Battle for the Galaxy, created by China-based game developer AMT Games, is a free-to-play mobile game with millions of downloads and users across 103 countries.

Misconfigured Database

According to WizCase, an unsecured ElasticSearch server owned by AMT Games was left online without password protection, allowing anyone to access the data. The breach exposed over 1.47 TB of gamer data, including email addresses, IP addresses, and Facebook data.

What data was exposed?

  • The unprotected server leaked approximately 5.9 million gamer profiles which included gamer ID, username, country, total money spent on the game, and even Facebook, Apple, and Google account data if the user linked either account with their game account.
  • Over two million transactional data like encompassed price, item purchased, time of purchase, payment provider, and in some cases, IP address of the buyer. Payment providers included Google, Apple, Steam, Amazon, Samsung, and Facebook.
  • Around 587,000 feedback message data contained account ID, feedback rating given, and users’ email addresses.

“In a sampling of the player profile data, the WizCase security team found that users could spend as much as $907 on the game via in-app microtransactions in the 10,000-player sample from 2019-2020 our team observed. This sample revealed concerning patterns in the mobile game. Of the 10,000 players sampled, 8,552 users made in-app purchases; 764 spent less than $1 on in-app purchases; 651 spent between $1 and $100 on in-app purchases, and 33 spent more than $100. That means 33% of users in the sample produced about 90% of the income in these transactions,” WizCase said.

Risks Associated with the Data Leak

Cybercriminals can misuse the leaked data to target users with various email scams, frauds, phishing, and malware attacks. “It is common for unethical hackers and criminals on the Internet to use personal data to create trustworthy phishing emails. The more information they possess, the more believable these emails look. For example, with the email addresses and specific details of user issues with the service such as in transactions and developer messages could allow bad actors to pose as game support and direct users to malicious websites where their credit card details can be stolen,” WizCase added.

Security Measures

WizCase recommended certain security measures to prevent any potential security risks, such as:

  • Always provide minimum information when making a purchase or setting up an account online.
  • When receiving an unexpected email from a seemingly trustworthy source, do not open any attachments.
  • If you are ever unsure about an email from a trustworthy company, give them a call.
  • A good antivirus program can also aid in protection from malware, Trojans, and other dangers.
  • Delete your credit card information from your phone after purchasing something from a game’s store.

Misconfigurations Increase Data Leaks

The State of Cloud Security 2020 survey revealed that inadvertent database exposure continues to be a major risk for organizations, with misconfigurations exploited in 66% of reported attacks. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern.

What Is Amazon Sidewalk? And How to Opt-in and Out of It?

Amazon Sidewalk

A lot of security concerns are being raised by individuals using Amazon-connected devices after the e-commerce giant announced the launch of its new service Sidewalk, a shared network that will connect Amazon smart devices. In an official notice, Amazon stated that Alexa, Ring Doorbell, Echo, and other connected devices will now have a new feature, from June 8, 2021, which share internet network with neighbors for better connectivity.

What is Amazon Sidewalk?

Amazon Sidewalk is a shared network intended to help connected devices work better, both at home and beyond the home network by sharing internet bandwidth with other Wi-Fi networks in the neighborhood. Amazon claims that Sidewalk extends the range of low-bandwidth devices and helps them connect online and even provides offline functionality outside the range of the users’ home network.

“Customers with a Sidewalk gateway can contribute a small portion of their internet bandwidth, which is pooled together to create a network that benefits all Sidewalk-enabled devices in a community. This can include experiences ranging from finding pets or valuables that may be lost and improving reliability for devices like leak sensors or smart lighting, to diagnostics for appliances and power tools,” Amazon said.

Privacy Issues with Amazon Sidewalk

While several smart home device users are concerned about this new feature, Amazon clarified that Sidewalk has three layers of encryption to secure data traveling on its platform. It has all the necessary security features to safeguard user data and prevent unauthorized intrusions. (Read: Researchers find a vulnerability in Amazon’s Ring Video Doorbells)

“Amazon has carefully designed privacy protections into how Sidewalk collects, stores, and uses metadata. Sidewalk protects customer privacy by limiting the amount and type of metadata that Amazon needs to receive from Sidewalk endpoints to manage the network. For example, Sidewalk needs to know an endpoint’s Sidewalk-ID to authenticate the endpoint before allowing the gateway to route the endpoint’s packets on the network. Sidewalk also tracks a gateway’s usage to ensure bandwidth caps are not exceeded and latency is minimized on a customer’s private network,” Amazon added. 

How to Opt-in or out of Amazon Sidewalk?

While the Sidewalk feature automatically updates on Amazon-supported devices, users can opt-out or turn off the service in the account settings.

Steps to turn off Amazon Sidewalk:

On Alexa:  

Open More > Select Settings > Account Settings > Select Amazon Sidewalk> Enable or Disable (as per preference)

This option will not be visible if you’re not connected to any Echo or Ring devices.

On Ring app:

Tap the “three-lined” icon > Go to Control Center > Select Sidewalk> > Enable or Disable (as per preference)

Also Read: Amazon Alexa “One-Click” Attack Could Jeopardize Personal Data

Brazil Implements Tougher Reforms to Fight Cybercrime

Brazil cybercrime, Brazilian cybercrime

Brazil is the top-most targeted country in Latin America when it comes to phishing attacks. As per official stats, one in every five (19.94%) internet users in Brazil had been targeted at least once in the reporting year 2020. The same year, Brazil also led the Latin America list for “the country with most ransomware attacks.” Owing to this carnage on the cyber front, the Brazilian government, on May 27, approved changes to the legislation adopting stringent penalties for cybercriminals targeting Brazilian businesses and masses.

Reportedly, the Brazilian Penal Code approved law 14.155 to imply severe penalties on cybercriminals who carry out serious offenses including “device invasion, theft, and misconduct in digital media environments, as well as crimes committed with the information provided by someone induced to or erroneously through fraudulent emails, social networks, or contacts via telephone.”

As per the updated legislation, fines and jail terms have been increased for cybercrimes if:

  • The victim suffers economic damage.
  • The cybercriminal illicitly invades electronic devices such as smartphones and computers to obtain, tamper, or destroy information without user consent.
  • The cybercriminal installs malicious software to obtain illegal entry into the device or network of the user.

The new legislation update has increased the jail time for cybercriminals as well. Depending on the severity of the cybercrime, the range has now been set between 1 to 8 years in addition to monetary fines. These penalties, however, become more severe if the cybercriminal is from a different nation-state or the victim is an elderly or vulnerable person/entity.

The introduction of tougher reforms for cybercriminals comes after Brazil’s recent amendment of law 14.132 passed on March 31, which has now criminalized online as well as physical stalking. Anyone guilty of committing this crime will now serve a jail term ranging between 6 months to 2 years and an additional fine as deemed fit.

In a report released earlier this year by tech giant Google, 66% of phishing attacks targeting Brazilian users were done leveraging the Portuguese language. This means the attackers geotargeted Brazil or are regional attackers. To know more about why you are more likely to be targeted with a phishing email, click here.

“Bot attacks can create inconvenience for legitimate users”

Nick Palmer

Apart from cyberattacks on the health care sector and phishing and ransomware campaigns targeting employees working remotely, 2020 also witnessed an increased surge in bot attacks. Bot attacks have also gained popularity due to their success rate compared to other vectors of cyberattacks. To discuss more about bot attacks during 2020 and the best mitigation strategies, we have Nicholas Palmer, Vice President of Global Sales, Group-IB. Since the beginning of his journey with Group-IB, Palmer has progressed through the company from a key account manager to become Head of Group-IB’s Global Business with teams reporting to him spanning Singapore, Malaysia, Vietnam, Spain, South Africa, Italy, UAE, the U.K., and the Netherlands. He is also a regular speaker at industry events such as RSA, INTERPOL World, FS-ISAC summits, CyberCrimeCon, and many others.

In an interview with Augustin Kurian from CISO MAG, Palmer reflects on the bot attacks in 2020 and their success rates. He also talks about API security and the tools that hackers favor for attacks. The latter part of the interview has interesting insights on Group-IB’s fraud hunting platform and “smart” bot protection.

Edited excerpts of the interview follow:

Which were the massive bad bot attacks of 2020 that had your attention? Do you believe those could have been prevented? If yes, how?

In 2020, bad bot attacks were plentiful: threat actors resorted to bots frequently to automate the process of conducting fraud, which offered them greater outreach and, hence, higher capitalization of their crimes. The application range of bot attacks is impressive, with bots generating about 30% of Internet traffic. Cybercriminals often leverage bots to compromise users’ online accounts and steal their payment or personal data. There are also several known cases of bots being used as a means of unfair competition — to generate hundreds of negative comments or paid adsclicking.

In terms of scope, the e-commerce sector was often targeted by bad bots. This was due to the proportion of valuable content available on e-commerce websites, both without authentication, such as pricing and scope, and in users’ accounts; the lack of appropriate protection measures; or their ineffectiveness against bot threats. Group-IB has observed a number of large-scale bot-attacks aimed at getting access to users’ reward points in online stores, their travel miles, or even personal data. Such attacks were characterized by the high intensity of requests, totaling up to 90% of all website traffic at some point. Apart from direct financial losses, bot attacks can create inconvenience for legitimate users who might have problems accessing the website.

Most of these incidents could have been prevented if a proper mechanism for checking all the requests and their source was in place. The thing about AI and machine learning is that it’s used by not only good guys but by bad actors as well. To shield against advanced bot attacks, one should not only analyze the source of requests, the frequency of requests from the same IP address, but also behavioral parameters like whether the request was generated by a browser or some tool like Selenium, to imitate user activity, and if it is the result of the user’s activity in a mobile or web app.

According to your research, three out of 100 user sessions at banking and e-commerce portals worldwide appeared to be fraudulent, with malware attacks, social engineering, and bot activity as the top three threats for users of e-commerce and banking portals. Following the same chronology, among these top three threats, which sees the maximum rate of success?

These three attack vectors compete in effectiveness, and we often see that one attack vector serves as a continuation to another. We have recently seen online fraud with the use of a Trojan utilizing the Android Accessibility Service for the bot-generated money transfers in mobile banking. In addition, sometimes it is difficult to distinguish between these three vectors.

Bots, however, have been gaining popularity lately with the highest success rate. It relies less on the human factor. In addition, tools for bot development are becoming more unified, diversified, and effective, reducing the entry threshold for conducting bot attacks.

While there are automated bots that snatch the best deals and win giveaways, there are also dangerous ones that break into online accounts, steal users’ payment and personal data, and abuse APIs while imitating human behavior. Do you think the cybersecurity industry is giving enough to API security? 

We have seen a number of huge portals that have to deal with bad bots because of outdated and irrelevant security solutions. API abuse is something that is on the rise. While more and more financial institutions and services for banks utilize APIs to fill their apps with data, fraudsters are taking advantage of this. As a result, businesses need to analyze requests to their API…To read the full story, subscribe to CISO MAG.

This story first appeared in the February 2021 issue of CISO MAG.


Augustin KurianAbout the Interviewer

Augustin Kurian is the Assistant Editor of CISO MAG. He writes interviews and features.

Cyberattack on JBS Disrupts Meat Slaughter Operations Across Australia

Cyberattack on JBS

Cybercriminal activities are everywhere. From gas pipelines, health care services to food processing organizations, threat actors have been exploiting every sector to their advantage. The recent victim to join the bandwagon of high-profile cyberattacks is JBS, one of the largest meat processing giants globally. In an official notice, JBS admitted that it recently sustained an organized cyberattack that affected some of its IT systems in North American and Australian units.

Upon discovering the attack, JBS immediately suspended all its operations and suspended the affected systems. While there is no sign of misuse of any customer, supplier, or employee data yet, the company stated that the incident may delay certain transactions with customers and suppliers in Canada and Australia.

JBS also notified the federal authorities and engaged a third-party security firm to investigate the incident. The suspension of meatpacking activities could affect consumers and suppliers in multiple countries including the U.S. and also result in meat price hikes.

Are Russian hackers involved?

Cybersecurity experts opined that threat actors linked to Russia are likely behind this incident. White House spokeswoman Karine Jean-Pierre said they’ve contacted Russia’s government about the matter and the FBI is investigating the same.

“The White House has offered assistance to JBS and our team at the Department of Agriculture have spoken to their leadership several times in the last day. JBS notified the administration that the ransom demand came from a criminal organization likely based in Russia. The White House is engaging directly with the Russian government on this matter and delivering the message that responsible states do not harbor ransomware criminals,” Jean-Pierre said.

What Experts Say…

Commenting on the incident, Rob Cheng, founder and CEO of cybersecurity firm PC Matic, said, “The ransomware attack on meat producer JBS USA, which appears to have originated from Russia according to White House officials, is the latest reminder that companies need to make changes to their cybersecurity strategy if they want to avoid dire setbacks to their business.

It may sound painfully obvious but the key to stopping ransomware attacks is prevention. That doesn’t mean just deploying an antivirus solution and calling it a day. It’s fine to have an AV solution to detect threats but relying only on antiquated blacklisting technologies means playing a never-ending game of catchup that you simply can’t win. Organizations need to add a more preventative layer to their cybersecurity strategy such as whitelisting technology. Because whitelisting only allows safe applications and files to run, it is the only proven preventative measure against polymorphic malware that is running rampant across hospitals, utility companies, government agencies, K-12 institutions, and companies of all sizes.”