Home Blog Page 89

Password Day 2021: Tips for Your First Line of Defense

world password day

The last year has seen most of us adopt new ways of working, collaborating, communicating, and shopping, as well as changing our entertainment habits.

By Jeffrey Kok, VP, Solution Engineers, Asia Pacific and Japan, CyberArk

Consumer

We have more accounts with more websites, applications, and services than ever before. This has created exponential growth in the number of digital identities each one of us possess. Many of these identities, unfortunately, will be secured by weak passwords, putting not only our data at risk but our whole digital ecosystem, including our employers.

Cybercriminals are well-aware of this, routinely taking advantage of the opportunities to exploit weak passwords and compromise data. Here are three tips to reduce the password-related risk this World Password Day:

  1. Use a strong password – Strong passwords contain several different types of characters and, consequently, require more effort and time for an attacker to hack. Passwords should contain at least 10 characters and include a combination of character types, such as commas, percent signs, and parentheses, as well as uppercase and lowercase letters and numbers.
  2. Don’t Re-use Passwords – If you re-use passwords on multiple sites or accounts, even if your password is complex enough and long, all it will take is for one of your accounts to be compromised to make all of your other accounts vulnerable.
  3. Use multi-factor authentication (MFA) – Many services we use online require that multiple types of authentication – not just a password – are required to unlock the account. But many only give you the option. If MFA is an option, use it. Yes, it’s a little more time-consuming, but it keeps you and your data much safer.

Trade

The last year has seen the forced acceleration of digital transformation, with many organizations adopting a new way of working, collaborating, and communicating.

Whilst this may have boosted innovation within an enterprise, it’s also created challenges for security and IT professionals. Every new corporate application or tool becomes a new identity silo, with unique password management requirements, such as complexity or how often they should be rotated.

And because we are pretty bad at using and remembering strong passwords, we often use weak ones or re-use them. In fact, 84% of remote workers admitted to re-using passwords in our survey. Added to this, passwords are still often the only verification method in use. Because of this, IT professionals consider passwords to be amongst the weakest links in their company’s defenses.

World Password Day 2021 provides a timely opportunity for IT admins and security teams to reinforce best practices. Here are four top tips to reducing password-related risk:

  1. Mandate the use of a strong password – Strong passwords contain several different types of characters and, consequently, require more effort and time for an attacker to hack. Passwords should contain at least 10 characters and include a combination of character types, such as commas, percent signs, and parentheses, as well as uppercase and lowercase letters and numbers.
  2. Enforce the use of one unique password for each service and account – If employees re-use passwords on multiple sites or accounts, even if the password is complex enough and long, all it will take is for one of their accounts to be compromised to make all of their other accounts vulnerable.
  3. Use multi-factor authentication – This means that multiple types of authentication – not just a password – are required to unlock the account. The first part of the authentication process requires something the user already knows, like a password. The other part of the authentication process involves something the user doesn’t already know, such as a code sent to the mobile phone by authentication software or created by a designated application on the phone.

This code becomes the other half of a user’s login authentication. Now, even if attackers manage to get a password, they still don’t have access to the account without the other part of the authentication.

  1. Address the risk of local admin accounts on workstations – Weak passwords and end-users with local admin rights on their workstations represent a significant security risk for organizations. Many attacks start on endpoints where attackers initially gain access through a phishing attack or when an employee inadvertently downloads and executes a malicious application. In many cases, an attacker’s aim is to compromise the privileged credentials that reside on workstations.

Privileged credentials – such as admin rights – can allow attackers to move laterally until they can secure credentials to the system with sensitive PII (personally identifiable information) or intellectual property. To reduce this risk, organizations should rotate local admin credentials (including the OS build-in local account) on a periodic basis as an important security measure. Over time, organizations should consider removing local admin rights from end-user workstations altogether to further reduce the risk of attacks from the endpoint.


About the Author

Jeffrey Kok is Vice President of Solution Engineers, Asia Pacific and Japan at CyberArk. Kok is responsible for working with various internal teams at CyberArk to qualify leads, identify business issues and drivers in any particular sales opportunity, and managing the entire presales and solution process of the business cycle.

 

Prior to joining CyberArk, Kok was Technical Consultant Director, Asia Pacific and Japan for RSA, managing a team of senior pre-sales engineers and technicians. While in this role he built a strong and high-performing cross-regional pre-sales practice.

Kok has more than 17 years of experience in the cybersecurity industry, serving in companies and institutions including RSA, Cisco Systems, Nera Telecommunications, and the National University of Singapore (NUS).

Kok holds a Bachelor of Applied Science in Computer Engineering from the Nanyang Technological University and CISSP certification.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Telstra Service Provider Hit with a Cyberattack; Tens of Thousands of Sim Cards Breached

Remote Access Scams

Keeping a close eye on the rising number of phishing attacks on Australians amidst the COVID-19 pandemic, in September 2020, Telstra launched a pilot project to block phishing texts in association with the Australian Cyber Security Centre (ACSC) and Services Australia. The initiative was lauded by its customers and other federal agencies as a step forward in securing its citizens from notorious cybercriminals. However, it seems like Telstra had forgotten to consider its third parties. Because Telstra has reportedly confirmed that one of its service providers was affected in a security breach.  Threat actors are claiming that they have exfiltrated “tens of thousands” of Telstra’s customers’ financial and SIM card(s) data and are now demanding a ransom in exchange for it.

The Compromised Service Provider

The third-party service provider, whose compromise led to the hack, is  Melbourne-based telecom service provider Schepisi Communications. According to their official website, they are “trusted” and a platinum partner” of Telstra supplying phone numbers and cloud storage services. Since the alleged cyberattack, a cybercriminal group claimed it had infiltrated the company’s data systems and posted a ransom note on the dark web saying,

We have a large amount of data on mobile devices, tens of thousands of SIM cards … financial information, contracts, banking information and much more.

The cybercriminals further warned Schepisi Communications that they had only 240 hours to agree to their terms or the data will be leaked on their name-and-shame website. The warning also additionally stated that decrypting the data would be of no use and in retaliation, their site would then be attacked by a wave of DDoS attacks.

A Telstra spokesperson confirmed the security breach to a national daily and accepted that it had affected one of its “dealers.” He added, We’ve been in contact with the dealer and been told some ‘high level’ Telstra business customer information, such as mobile phone numbers, may have been accessed from its order fulfillment system.

More information on the type of ransomware and the operators behind it is awaited.

Related News:

Telstra Forms Alliance with ACSC and Services Australia to Eradicate Phishing Texts Spoofing

NSA Releases Advisory on Securing IT-OT Connectivity

NSA security advisory

The U.S. National Security Agency (NSA) released a security advisory addressing the National Security System (NSS), the Department of Defense (DoD), and the Defense Industrial Base (DIB), detailing ways to evaluate risks and improve the security of connections between operational technology (OT) and enterprise IT networks. The advisory “Stop Malicious Cyber Activity Against Connected Operational Technology,” stated that the exploitation of IT networks often leads to abusing enterprise OT networks, as IT systems serve as an entry point into industrial networks.

Though the recommendations are specifically addressed to the government agencies, they can be used by any industrial company to strengthen the security of IT and OT systems connectivity.

Evaluating the Value vs. Risk vs. Cost for enterprise IT and OT Connectivity
  • Acknowledge that a standalone, unconnected OT system is safer from outside threats than one connected to an enterprise IT system with external connectivity.
  • Determine the value to the enterprise of connecting the IT system to the OT network and/or control system environments.
  • Determine the risk to the enterprise of connecting the IT system to the OT environment.
  • Quantify the increased costs associated with mitigating the additional risks from connecting the existing OT networks and devices to the enterprise IT system.
  • Present leadership with findings so they can effectively evaluate the value, risks, and expenses/resources.
Improving Security for Connected Enterprise IT-OT Networks
  • Fully manage, cryptographically protect (encrypt and authenticate), and apply an allow list or a dial-back approach1 to all access vectors.
  • Wherever remote access is permitted, add sensors, and monitor all cross-domain connections. It is recommended that all remote access connections be disconnected until such time that active monitoring is in place.
  • Create a known OT network map and device settings baseline and validate all equipment on the network.
  • Create a known OT network communication baseline.
  • Assess and prioritize OT network cybersecurity needs to identify required mitigations and define short-, medium-, and long-term cyber-hardening outcomes.
  • Create an exemplar Gold copy baseline to enable all OT networks and devices to be repaired and/or instantiated.
  • Gold copy restoration files and capabilities should be stored in locked, unconnected locations. Do not store gold copy restoration data online or on-network.
  • Practice OT network re-instantiation to ensure success and shorten OT network downtime if an issue or malicious activity occurs.

“Each IT-OT connection increases the potential attack surface. To prevent dangerous results from OT exploitation, OT operators and IT system administrators should ensure only the most imperative IT-OT connections are allowed, and that these are hardened to the greatest extent possible. These mitigations include fully managing all IT-OT connections, limiting access, actively monitoring and logging all access attempts, and cryptographically protecting remote access vectors,” the NSA said.

Initial Access Brokers Are Breaking Into Corporate Networks and Selling Access to Bad Actors

initial access brokers

Recent research “Digital Shadows” lifts the cover on Initial Access Brokers (IABs), a fast-growing new class of cybercriminals who breach organizations, and then sell that access to other threat actors, enabling them to do their dirty work (exfiltrations, RATs, ransomware, etc.).

By Matias Katz, Founder and CEO, Byos

The report “Rise of Initial Access Brokers” examines the new role that Initial Access Brokers are playing at the top of the cyberattack kill-chain funnel.

IABs are de facto ‘middlemen’ whose business model is exactly what the name implies: they breach as many companies’ networks as they can. They then sell to the highest bidders that access victims. The buyers are often ransomware groups.

IABs have been proliferating lately largely because of the pandemic and the ensuing Work-From-Home migration. Workers who are logging into systems remotely and connecting from untrustworthy Wi-Fi networks create an exploitable vector of attack. Cybercriminals are exploiting this by scanning at scale for vulnerabilities which allow remote access, such as in virtual private networks (VPNs), and selling this access.

The $7,100 average selling price for access takes into consideration a victimized organization’s revenue, the type of access sold, the number of employees, and the number of devices accessible. RDP (remote desktop protocol) access, the most frequently listed access type for sale, let a threat actor take over a victim’s computer. RDP access typically goes for around $9,800.

The FBI notes that ‘RDP is still 70-80% of the initial foothold that ransomware actors use.’ RDP is believed tied to the Oldham Florida Water Treatment Facility attack, in which attackers attempted to alter the chemicals added to the public water supply.

Beyond the Remote User – As IoT Continues to Grow, So Do System Vulnerabilities

IABs are seeking to expand their offerings by also targeting a new threatscape: IoT devices. They see them as “low-hanging fruit” points of entry to corporate networks.

IoT devices are used as an entry point into the larger corporate networks, where the most valuable data resides because they aren’t built with security in mind. Legacy IoT devices such as servers, modems, PLCs, controllers, and networked medical devices are especially vulnerable as they are incompatible with modern security software agents.

Understanding the traffic at the edge of the corporate network is something that network administrators have long desired since they know their devices are exposed when connecting to any network.

A lot of remote access tools/protocols require local network and device configuration changes, which creates additional risk by exposing internal endpoints directly to the internet – a simple Shodan search confirms this. Once the attacker gains initial access to these exposed endpoints, it is difficult to remove this foothold from the network, let alone prevent it from spreading laterally, highlighting why IABs have become so prevalent.

Because of this, some organizations have even gone so far as to ban remote access to their systems altogether, forcing administrators and technicians to service endpoints physically on site. In a remote-friendly world, a better solution is necessary.

Securing Endpoints: Blocking Access to the Corporate Network

One strategy for mitigating risks of initial access at the edge is micro-segmentation using a secure endpoint edge device.  The main premise behind micro-segmentation asserts that the endpoint is never directly exposed to the network – it is isolated onto its own “micro-segment of one.” It enables organizations to own control of their edge by ensuring the traffic that flows to and from the endpoint flows to it on its own micro-segment.

Micro-segmentation also allows for Zero Trust Remote Access through what is called the “Secure Lobby”; Instead of an administrator configuring the perimeter to allow traffic to the endpoint directly, the secure endpoint edge acts as the gatekeeper to the endpoint, while maintaining full isolation from the rest of the network.

With Secure Lobby, both the remote user and secure endpoint edge “meet” in the lobby through an encrypted connection. The administrator can now remotely access the micro-segmented endpoint securely and perform any type of monitoring, updating, or patching necessary, without exposing the endpoint to the internet.

This is game-changing for secure remote management because attackers will no longer have direct access into endpoints, thus helping to eliminate the business of Initial Access Brokers all together.


About the Author

Matias KatzMatias Katz is the founder and CEO of Byos. Matias has 15+ years of experience in information security. He founded Mkit in 2008, which provided defensive and offensive security solutions, and is an official CISSP instructor. He has presented his research at cybersecurity conferences around the world and has a popular TEDx talk. He is the author of “Redes y Seguridad” (Networking and Security) and founded the Andsec international hacking conference.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Experian API Flaw Exposed Credit Scores of Thousands of Americans

Log4Shell

Credit scores of millions of Americans were exposed online after a third-party vendor misconfigured the Application Programming Interface (API) keys belonging to the credit reporting agency, Experian. As reported by Krebs on Security, independent security researcher Bill Demirkapi discovered a vulnerability in Experian’s vendor site that allowed anyone to find out credit scores of anyone just by entering their name and mailing address.

Demirkapi stated that the Experian API could be accessed by anyone without any sort of authentication to pull a person’s credit score.

“No one should be able to perform an Experian credit check with only publicly available information. Experian should mandate non-public information for promotional inquiries, otherwise, an attacker who found a single vulnerability in a vendor could easily abuse Experian’s system,” said Demirkapi.

While Experian addressed the vulnerability, Demirkapi stated that it might exist in various other third-party vendor sites that are associated with Experian.

“We have been able to confirm a single instance of where this situation has occurred and have taken steps to alert our partner and resolve the matter. While this did not compromise any of Experian’s systems, we take this matter very seriously. In fact, we continually work with our clients to review their processes and ensure data security best practices,” Experian said.

Security Experts Say…

The Experian data leak incident reminds us of the importance of API security. Talking to CISO MAG, Inon Shkedy, a security researcher at security firm Traceable, said, “In the era of cloud transformation, we are finding more and more companies that unfortunately prioritize fast delivery over security. Developers are under pressure to create features and improve user experience as quickly as possible, and security is often an afterthought. APIs that expose sensitive information, such as credit score and financial insights, should be always tested for access control issues before deployment – not after it’s already being used by customers.”

“Making authorization tests as part of the CI/CD pipeline is becoming more important than ever, especially with APIs that are exposed to everyday consumers or partners, because even one breach can damage trust, have a massive financial impact and legal repercussions,” Shkedy added.

Tesla’s Zero-click Vulnerabilities Allowed its Car to be Hacked Remotely Using Drones

Tesla avoids cyberattack, tesla zero-click vulnerabilities

If you own a Tesla car and see a drone hovering around your parking lot, be super aware! Someone might be trying to gain access to your car by hacking into it. Security researchers Ralf-Philipp Weinmann and Benedikt Schmotzle claim so. The duo has discovered zero-click security vulnerabilities in Tesla’s open-source software component called, ConnMan. On successfully exploiting the vulnerabilities, attackers could take control of the infotainment systems through Wi-Fi.

Tesla’s Zero-click Vulnerabilities

The zero-click vulnerabilities, which the researchers named “TBONE,” were to be demonstrated at the hacking contest “Pwn2Own,” which was scheduled to be held in Vancouver in March 2020. However, it had to close its doors due to the pandemic. Tesla takes pride in identifying itself as a technology firm than an automobile giant because of its pioneering technology of self-driven cars. Thus, it supports such hacking contests and bug bounty programs to furthermore secure its tech front.

Weinmann and Schmotzle said that exploiting the vulnerabilities would allow the attacker to lock/unlock the doors and trunk, change seat positions, both steering and acceleration modes – in short, pretty much everything that a driver can do by pressing various buttons on the console. However, one thing to be noted here was the fact that even after gaining control over these features, the attacker could not fidget with the drive control of the car. (So, no, your Tesla won’t just roll out of the parking lot and reach the attackers’ destination… at least for now.)

What the Researchers Say…

Weinmann, who is the CEO of Kunnamon, said,

Looking at the fact that TBONE required no user interaction, and the ease of delivery of the payload to parked cars, we felt this attack was ‘wormable’ and could have been weaponized.”

“Adding a privilege escalation exploit such as CVE-2021-3347 to TBONE would allow us to load new Wi-Fi firmware in the Tesla car, turning it into an access point which could be used to exploit other Tesla cars that come into the victim car’s proximity. However, we did not want to weaponize this exploit into a worm.

The researchers did not have an actual Tesla car to test their exploit, so, they used an in-house emulator – “KunnaEmu” – to devise these attacks. However, they were confident about its accuracy and thus disclosed their analysis at Tesla’s bug bounty program in October 2020. Tesla was quick to work around it and released a patch update v2020.44 in late October. Additionally, Tesla has also reportedly moved to an alternative of ConnMan – dnsmasq.

ConnMan is used in several German automobiles and thus the duo shared their findings with the CERT-Bund (German CERT) to help automobile companies fix these vulnerabilities at the earliest.

Related News:

Tesla Offers US$1 Million and a Car as Bug Bounty Reward

40 Mobile Apps with Over 100 Mn Downloads Found Leaking AWS API Keys

Mobile Apps Security, mobile apps

Security threats from mobile applications continue to be a major risk for developers and users. Cybercriminals often try to exploit vulnerabilities or misconfigurations in the cloud infrastructure of iOS and Android mobile applications, exposing users’ personal information and taking control over other apps on the device.

Despite robust security scans, several malicious apps are still making their way to official app stores. To find any potential vulnerabilities and security loopholes in several mobile applications, cybersecurity firm CloudSEK recently launched BeVigil, a security search engine that helps determine an app’s security posture before installing.

BeVigil’s Analysis

BeVigil found that 0.5% of mobile apps expose Amazon Web Services (AWS) Application Programming Interface (API) keys, leaving users’ sensitive information at high risk. Out of 10,000 apps that were analyzed using BeVigil, the company found more than 40 apps exposing private AWS keys. All 40 apps are popular with over 100 million downloads.

“Given that there are over 8 million apps available across app stores, we estimate that there are thousands of mobile apps exposing AWS keys. With many of these apps catering to millions of users, there needs to be widespread awareness about the risks involved. more than 100 million downloads. CloudSEK has responsibly disclosed these security concerns to AWS and the affected companies independently,” CloudSEK said.

Some of the popular apps that were leaking private AWS keys include: Clubfactory, Adobe Photoshopfix, Adobe Comp, Weather Forecast & Snow Radar, Wholee – Online Shopping Store, Oven Story Pizza, and Hootsuite.

Also Read: How to Secure Your Mobile Apps

Risks Associated with Leaked AWS Keys

Exposed AWS keys offer a pool of possibilities to threat actors to misuse the keys and illicitly obtain access to the app’s cloud infrastructure. “CloudSEK has observed that a wide range of companies — both large and small — that cater to millions of users have mobile apps with API keys that are hardcoded in the app packages. These keys could be easily discovered by malicious hackers or competitors who could use them to compromise their data and networks. While this is not a flaw in AWS, it is evidence of how sloppily AWS keys are handled. So, it is up to individual companies to address the security concerns associated with using AWS services,” CloudSEK added.

Also Read: How to Spot Malicious or Fake Apps

Mobile Side of Technology Adoption Still Continues to Present a Challenge

Ritesh Chopra

India has transformed into a mobile-first economy. The ease of accessibility and cheaper data make these a primary source of entertainment. Given the transition to remote working, people are well accustomed to new technologies and are discovering different ways to stay connected. Recent incidents have shown the vulnerabilities individuals and business owners can witness if one is not cautious to protect their data and identity in the digital world.

In an email interaction with Augustin Kurian, Assistant Editor of CISO MAG, Ritesh Chopra, Director Sales and Field Marketing, India & SAARC Countries, NortonLifeLock, discuss the increasing cyberthreats given the current social apps scams making consumers vulnerable.

Chopra is responsible for developing and implementing strategies to drive the adoption of NortonLifelock products among consumers in the sub-continent. He champions NortonLifelock’s partner strategy in India and manages OEM/ISP and online channel relationships. Chopra also held the position of Country Manager until June 2018 before being promoted and has been with the company since 2012.  With over 20 years of extensive experience in the technology sector, he is a sales and marketing strategist in India and Asia-Pacific regions. He has been recognized with Six Sigma qualification and has successfully conceptualized and implemented multi-tier channel loyalty programs in his previous role with Seagate, Singapore.

In the interview, Chopra has also provided insights on the growing usage of the dark web as well as key findings from the NortonLifeLock Digital Wellness Report.

 

Email addresses were the most common piece of PII shared with apps and were shared with 48% of the iOS apps and 44% of the Android apps analyzed. With the rise of the dark web, do you think better nationwide cybersecurity regulation can bring in a lot of difference?  

Personally, Identifiable Information (PII) such as medical records, bank details, passwords, phone numbers, and email IDs are most targeted by cybercriminals. Cybersecurity regulations will certainly help in making a difference in how data is handled on the dark web. But consumers also need to be aware of the kind of data that is shared through apps. Certain apps can enable attackers to mine information from the device in the background, even without the user’s knowledge. Unlike desktop users, smartphone users cannot see the entire URL of the site they are visiting, which makes them vulnerable to phishing attacks. Such threats can be avoided, to an extent, by using strong passwords, avoiding using public WiFi, watching out for phishing emails, regularly backing up important data, and keeping all apps and operating systems up-to-date. Amidst the evolving cybersecurity landscape, it is imperative for individuals to invest in robust anti-theft device security to ensure digital safety.

 

COVID-19 changed the cybersecurity landscape. It is now even more important for companies to support the security of their workforce – regardless of geo-location or platform. With myriad compliance and regulations norms varying from country to country, how should a company ensure that best practices are in place across their offices globally? 

The COVID-19 pandemic has changed the way we work; the concept of “remote working” is gaining popularity. While people seek opportunities that allow remote work, they must also equip themselves with cyber safety and data protection tools. There are some basic measures you can adopt to avoid falling prey to cyberattacks:

  • Speak to your employer to understand the policies that help keep you, your co-workers, and the business safe.
  • Always use the company’s tech toolbox, as it likely includes firewall and antivirus protection and security features like VPN and two-factor authentication.
  • Beware of coronavirus-themed phishing emails used by cybercriminals. Immediately report such phishing attempts to your employer.
  • Keep your VPN turned on, as it provides a secure link between employees and businesses by encrypting data. A VPN helps keep information secure from cybercriminals and competitors.
  • While working remotely, it is important to understand that online safety is a shared responsibility that begins at the individual level.

As far as PCs are concerned, people are increasingly using paid software. They are even adopting security products for ‘Mac’ machines. But the mobile side continues to present a challenge. We are seeing people adopt VPN and mobile security products; however, it still appears to be a bit further away from what we would want it to be.

 

India witnessed several state-sponsored attacks during vaccine development. Even the vaccine makers are being targeted in nation-state attacks. What can the country and its cybersecurity divisions do to combat these threat vectors?

Scammers and cybercriminals have been exploiting the COVID-19 pandemic and, more recently, the ongoing vaccination drive, to create new hooks to lure victims. Although the authorities have been warning people to watch out for scams on such themes, there has been a huge increase in the number of phishing scams since the pandemic began. Cybercriminals are sending emails that appear to be sent by government agencies, employers, and other global health organizations, inviting users to click on what, in reality, are malicious links.

Consumers can adopt some basic measures to falling prey to cyberattacks:

  • Beware of online requests for personal information. A coronavirus-themed email that seeks your personal data is likely to be a phishing scam. Legitimate government agencies will not ask for such information. Do not respond to such emails.
  • Check the email address or link. You can inspect a link by hovering the cursor over the URL to see where it leads. Sometimes, it is obvious the web address is not legitimate. Even otherwise, be careful, because phishers can create malicious links that closely resemble legitimate addresses.
  • Phishing emails are unlikely to address you by your name. Greetings like “Dear Sir or Madam” is an indication that email might not be legitimate.
  • Avoid emails that urge you to take immediate action. Phishing emails often try to create a false sense of urgency. The goal is to get the user to click on a link and divulge personal information. If you receive a suspicious-looking email of this type, delete it.

 

Millennials top the charts in online transactions as compared to women and Gen X who are most complacent about security, yet trends indicate Gen X to be more susceptible to cyberattacks than millennials. Do you think it is completely around digital literacy, or there is more to this trend?

The lines between the virtual and the real world have blurred today. Individuals, irrespective of their age or generation, are vulnerable to cyberattacks when they use public or private networks if they do not have any cyber safety solutions installed on their systems. Individuals often neglect to log out of their social media accounts and apps. This habit needs to change. We must bring some good practices from the real world into the virtual one. Just like how we lock the main door before going to sleep, we should log out of emails and social media accounts, and online banking sessions, once we are done using them.

We often download free apps and, often, without thinking, permit them to access different features and data on our device. If something like a weather app asks us to grant access to our contact list, it should give us pause for thought. We need to read the terms and conditions a careful read too, rather than accepting them blindly. It is advisable to install an application scanner to check for security vulnerabilities and a VPN to mask our identity.

Data from our Digital Wellness Report reveals some interesting facts:

  • 81% of the respondents in the survey were using parental control mechanisms on their devices, while 70% knew that connecting with strangers while playing online games could lead to problems like cyberbullying.
  • The report found that female respondents (84%) were more aware than men (74%) about security threats and that they had security software installed on their smartphones.
  • 71% of female respondents (versus 63% of male respondents) concerned themselves with app privacy and permissions on their phones.
  • Gen Z users (95%) were found to be more proactive than millennials (94%) and Gen X users (90%) in adjusting the privacy permissions on their phones.

According to our 2019 NortonLifelock Cyber Insight Report:

  • 40% of millennials reported having experienced cybercrime in the past year.
  • Nearly 3 in 10 people said they cannot detect a phishing attack. Another 13% said they have to guess between a real message and a phishing email. Thus, 4 in every 10 people were vulnerable to phishing.
  • 86% of respondents said they may have experienced a phishing incident.
  • 7 in 10 respondents wished they could make their home Wi-Fi network more secure.
  • 27% of respondents believed it was likely their home Wi-Fi network could be compromised.

 

At present, fintech is one of the most regulated industries in the world. But the key challenge is the presence of too many governing bodies but no universal standards – a singular regulatory policy or framework for the industry is lacking. Do you feel there is a need for a standard set of compliance and regulation for fintech and cryptocurrency?  

You’ve probably heard of Bitcoin. But what about Ethereum? Or Tether and Polkadot? What are these? They’re all examples of cryptocurrency – a digital currency that you can buy with real money and then spend in online transactions. It’s true that you probably can’t buy a meal at your favorite restaurant with Bitcoin or rely on Ethereum to fill your car’s gas tank. But cryptocurrency is becoming increasingly more popular and valuable. Coindesk.com, which covers cryptocurrency, reported that, as of January 2021, the total value of all cryptocurrencies topped $1 trillion for the first time.

New cryptocurrencies emerge frequently. Coinmarketcap.com listed more than 4,100 types of them in an early 2021 price index published on its site. But what do these digital currencies mean to you? Do you need to learn how to purchase them and spend them? Probably not. But while digital money isn’t a necessity, it does have its uses. Users of cryptocurrency say that digital transactions closed with cryptocurrency are more secure than those using credit cards.

As cryptocurrencies become more popular, so do the scams associated with them. Some scammers set up fake cryptocurrency exchanges. You might send real money to buy Bitcoins that don’t exist. Once you send your funds, they are gone, and your crypto wallet remains empty. To avoid such scams, only buy cryptocurrency from reputed exchanges. Don’t do business with exchanges that seemingly pop up out of nowhere.

 

What kinds of changes should be made during vendor sourcing and onboarding processes? And how much of the responsibility must fall on the CISO? 

Data beaches have a direct negative impact on at least three very important aspects of a brand: presence, affinity, and trust. In the age of social media, negative news can affect not only people’s perceptions about the company but also the company’s financial prospects. Customers might stop engaging with the brand completely or engage at a significantly lower level than before.

Data security has, for long, been viewed as a “hygiene” factor by many businesses and consumers. However, in today’s interconnected world, where data is more valuable than ever and a company’s reputation is based on its ability to protect customer data and establish digital trust, cyber safety and data security are no longer a mere hygiene exercise, but a business differentiator.

There are no set rules for building a security framework, and no system can guarantee 100% protection against all threats. However, imbibing a culture of security within the organization and ensuring the independence and empowerment of the CISO indicates that the organization is serious about cyber safety and data security. It also ensures that critical security-related changes within the organization can be effectively taken care of by the CISO.

Augustin KurianAbout the Interviewer

Augustin Kurian the Assistant Editor of CISO MAG. He writes interviews and features.

 

Project Signal: An Iranian State-Sponsored Ransomware Operation Emerges

Log4j, Iranian Ransomware Actors, SpoofedSccholars, second-tier targets, NIOPDC

State-sponsored actors from Iran have often been linked to various cyberespionage campaigns targeting organizations globally. In a recent development, security experts from Flashpoint recently discovered another state-sponsored ransomware operation from Iran active since July 2020.

Flashpoint stated that Iran’s Islamic Revolutionary Guard Corps (IRGC) was operating a ransomware campaign via an Iranian contracting company – Emen Net Pasargard (ENP). The ransomware campaign titled “Project Signal”  likely began its operation between late July 2020 and early September 2020, with ENP’s internal research organization, putting together a list of unspecified target websites.

“Iran has a history of attempting to use cybercriminal TTPs to blend in with non-state-sponsored malicious cyber activity to avoid attribution and maintain plausible deniability. It’s largely assumed that Iran has been behind multiple destructive and disruptive attacks in recent years; most notably the 2012 Shamoon attacks against Saudi Aramco and the 2012 Operational Ababil DDoS attacks against the U.S. financial institutions,” Flashpoint said.

Flashpoint’s researchers validated three documents that were leaked between March 19 and April 1, 2021, which indicated that IRGC was operating a state-sponsored ransomware campaign through ENP (which is also known as Imannet Pasargad, Iliant Gostar Iranian, and Eeleyanet Gostar Iranian).

“A leaked internal ENP spreadsheet showed that during this time, the group was researching three to four websites per day and that at the time the spreadsheet was written around twenty sites had been reviewed and analyzed by the Studies Center. Project Signal was also referenced in another spreadsheet showing that the project had been assigned to ENP’s Cyber Directorate, responsible for carrying out ENP’s offensive cyber operations. The transfer of the Signal project from the Studies Center to the Cyber Directorate demonstrated that the ransomware project had progressed from the research and planning phase to the operational phase,” Flashpoint added.

Link with Pay2Key Ransomware?

Flashpoint opined that the operators behind Project Signal have links with the infamous Iranian ransomware campaign Pay2Key, which targeted multiple Israeli firms across various sectors from November 2020. The researchers found financially motivated attributes in both Project Signal and Pay2Key campaigns. Flashpoint found over six Israeli companies that had leaked internal documents due to Pay2Key ransomware.

UNICC and Group-IB Take Down 134 Fake Websites Impersonating WHO

fake websites impersonating WHO

Group-IB, in coordination with the United Nations International Computing Centre (UNICC), has taken down a massive fake websites campaign in which 134 fraudulent websites were observed to be impersonating the World Health Organization (WHO) with an intent of duping people. The multistage scam campaign was specifically run on and around April 7, 2021, for leveraging the occasion of “World Health Day.”

The Modus Operandi

The scammers had created a distributed network of 134 fraudulent websites impersonating the World Health Organization (WHO) on its health awareness day. The campaign asked users to take a fake survey with the promise of getting a 200-euro prize for completing the survey. Once users answered the questions, they were prompted to share the link with their WhatsApp contacts. This way, the scammers orchestrated a multistage scheme that could be distributed virally. To make it look more authentic, scammers also added fake Facebook comments about receiving the gift prize.

To be more convincing, the victims were additionally shown customized content depending on their geolocation, user agent, and language settings. One such example, which Group-IB’s researchers found, was the currency changer. This meant the currency of the reward money shown would change depending on the user’s location.

Upon detection, Group-IB’s Digital Risk Protection team reached out to UNICC’s Common Secure team as a trusted contact for cyberthreat intelligence matters within the UN ecosystem. Group-IB collectively with UNICC then took down all the recorded scam domains.

The Scam Syndicate 

The researchers ran the discovered connections between the blocked 134 websites involved in the WHO scam and their other data sources and surprisingly established that one scammer collective, codenamed DarkPath Scammers, is likely to be behind the campaign.

Brands impersonated by DarkPath Scammers broken down by industry.

This scammers’ group is known to have at least 500 other scam and phishing resources impersonating more than 50 well-known international brands. However, it is worth noting that after the takedown efforts by UNICC and Group-IB, the scammers were forced to stop using the WHO branding across their entire network.

To avoid falling prey to such schemes, Group-IB’s experts suggested online users to “carefully examine the website they visit.” It said, “It is never a waste of time to check whether the link you will click on is identical to the domain of the organization’s official website — fraudsters often register domain names mimicking official ones. Anyone who wants to keep their personal data and money safe should foster a habit of always being suspicious of any website on which they plan to enter their data.”

Related News

Group-IB Finds Half a Million Credit Cards of Indian Banks on Darknet

Operation Falcon: INTERPOL Nabs Three Nigerian BEC Scammers