Home Blog Page 92

Adversaries Offer Fake COVID-19 Vaccine Certificates on Darknet Forums

COVID-19 Cyberthreats

Cybercriminals around the world are taking advantage of the situation and offering everything from counterfeit vaccines to fake vaccination certificates, and test reports. In fact, state government authorities in India recently uncovered a racket where bus operators were offering fake COVID test certificates to enable travelers to cross borders between states. In response, law enforcement authorities and drug suppliers across the world are urged to step up their anti-counterfeiting measures to tackle this growing problem of evolving COVID-19-themed risks. The International Hologram Manufacturers Association (IHMA) stated that it has found a 300% increase this year in advertisements on various dark web markets on fake Coronavirus-related products and services.

The Fake for Real Business

The IHMA stated that cybercriminals are selling fraudulent vaccines on various dark web forums for $500 and $1000 per dose. The vaccine research centers and manufacturers are urged to boost their authentication and verification technologies to protect consumers against rising fake vaccine scams.

“COVID-19 presents opportunities for criminals, who are infiltrating global supply channels, deploying scams, and counterfeiting measures to trick worried people and damage legitimate manufacturers. Falsified medicines and test kits among other items can pose a terrible threat and endanger lives. Supply chains and drugs’ infrastructures across the country must be bolstered with stronger, more effective security plans, including the introduction of hard-hitting anti-counterfeiting regulations and strategies,” said Paul Dunn, Chair of the IHMA.

Growing Demand for Fake Certificates

The roll-out of vaccine shots to treat Coronavirus continues to accelerate globally. There are billions of people who are still waiting for their first dose of vaccine. However, there will always be people who look for alternatives and shortcuts to fulfill their needs. With COVID-19 restrictions imposed globally to allow those who have been vaccinated or tested negative to board flights, cross international borders, attend events, or start new jobs, several people showing up on darknet forums to obtain fake vaccination certificates and forged negative COVID-19 test reports quickly.

“As our societies struggle to return to pre-COVID norms, a negative COVID test result or a vaccination certificate is becoming the golden key that will unlock restrictions and enable people to move and mingle with greater freedom. And of course, this creates an opportunity for criminals and scammers to exploit those people who are willing to risk using fake documents to achieve that freedom,” Check Point said in its research.

Key Findings

  • Fake vaccine passport certificates on sale for $250 – users are simply required to send their details and the money, and the seller emails back the fake documents.
  • Fake negative COVID-19 test results on sale from various sellers from just $25.
  • Multiple vaccine variants for sale: AstraZeneca, Sputnik, SINOPHARM, and Johnson & Johnson, with prices ranging between $500 and $1000 per dose.
  • The vaccines advertised include Oxford – AstraZeneca (at $500), Johnson & Johnson ($600), the Russian Sputnik vaccine ($600), and the Chinese SINOPHARM vaccine.

“As COVID-19 is likely to play a major role in dictating what we as individuals can and cannot do in our daily lives for the foreseeable future, countries’ Governments should be aware of this fast-growing illegal and dangerous trend for fake vaccination certificates and official medical records being sold and produced to whoever wishes to pay for them,” Check Point added.

Integrating Ethics with Technology

security, tech provider

Tech is not above us. It should be governed by all of us, by our democratic institutions. It should play by the rules of our societies. It should serve our needs, both individual and collective, as much as our wants.

The above excerpt is from the Copenhagen Letter 2017 which Milestone co-authored highlighting the importance of integrating ethics with technology for the larger good of society and our way of life.

By Sandesh Kaup, Country Manager, Milestone Systems, India & SAARC

Last year, the 2020 Edelman Trust Barometer Special Report: Trust in Technology revealed there are many concerns about technology and how it is being used. 61% of respondents feel that the pace of technology is accelerating, and regulators are finding it challenging to understand emerging technologies and finding ways to regulate them effectively.

Consider data and privacy. Theft and misuse of IP and personal data can affect the very existence of an organization or people (customers, employees, suppliers, vendors, etc.), causing identity theft, huge financial losses, and more. Organizations lose credibility when they find that technology cannot protect the sensitive data of their stakeholders.

Innovative, technology-driven sectors show even lower levels of trust. For instance, artificial intelligence is trusted at 63%; driverless cars are almost neutral at 58% according to the 2020 Edelman Trust Barometer report.

Cybersecurity is rated as the second-highest source of risk for enterprises. A major source of misuse of technology is ransomware attacks, phishing attacks, denial of service attacks, etc. According to Gartner, 40% of boards of directors will have a dedicated cybersecurity committee by 2025, up from 10% today.

What we see is that as technology extends its reach into society, organizations must prepare themselves for potential misuse.  It is for this same reason that we encourage “continuous, public, and critical reflection on our definition of success as it defines how we build and design for others.”

Together, the security technology industry must put in place robust procedures to protect our customers and nurture the potential of our partners to do good with the technology we create.

Technology as a solution to present-day challenges

Shouldn’t technology offer solutions to the challenges we face?

The answer is yes, but it should also make our lives better.

For example, remote working was tested and used by many organizations in 2020. It not only delivered on promise, but it has also helped companies stay afloat during the pandemic.

Throughout the pandemic, video technology has also become an important and integrated part of our lives. It has helped keep employees and the public secure as they returned to the streets and offices. Video went beyond traditional security functions to assist in social distancing in crowded public places such as retail malls and railway stations by integrating with thermal mapping, data analytics, and facial recognition. It freed up guards and security forces for more valuable work, keeping them safe from the risk of infection.

In the following years, we can expect video to get even smarter and cheaper with integrated technologies such as 5G and Artificial intelligence (AI). It is no doubt that video will be integrated into our lives, in areas of transport, automation, and in the development of the Internet of Things. In 2021, Gartner expects IT spending in India to go up by 6% from 2020, to be driven by digital innovations.

Using technology responsibly

If you look at the technology value chain in any organization, the onus for responsible use of technology cannot lie only with selective stakeholders. All stakeholders – from design to sales to end-users of technology – are equally responsible.

In the video technology industry, we see how video management solutions (VMS) play a vital role in improving safety, efficiency, and well-being in our society. And at Milestone, we strongly believe that video and technology should and must be used as a force for good.

Moving forward, we are committed not only to help our customers optimize their business processes and protect their assets, but to also be a strong voice to encourage the industry, our communities, and partners to use technology in a responsible manner in their respective sectors; with a shared goal of making society wiser, safer and a better place for all of us to live.

As the Copenhagen Letter states: Let us build from trust. Let us build for true transparency. We need digital citizens, not mere consumers. We all depend on transparency to understand how technology shapes us, which data we share, and who has access to it. Treating each other as commodities from which to extract maximum economic value is bad, not only for society as a complex, interconnected whole but for each and every one of us.


About the Author

Sandesh-KaupSandesh Kaup comes with over two decades of experience and significant exposure handling multiple global companies. Milestone has been a part of his DNA since 2011, running the local business until 2016 and largely responsible for the incredible growth the organization experienced in that time. In addition, he has developed expertise in building businesses for companies like Bosch Security, Ingram Micro, and Anixter during his early career. Sandesh comes with a Bachelor of Engineering in Instrumentation from Mumbai University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

After 7 Years of Reigning Malicious Terror, Emotet’s Uninstallation Sets in Motion

BazaCall BazaLoader

The law enforcement and judicial authorities globally have geared up to takedown the infamous email spam botnet Emotet from all infected devices using a malware module. The Emotet botnet is responsible for various malware campaigns affecting multiple organizations over the years across the globe. The operators behind Emotet malware are used to sending millions of spam emails with malicious attachments to infect victims’ devices. The notorious malware, which wreaked havoc in the last seven years, is also linked to various other botnet-based cyber campaigns delivering malicious payloads like TrickBot and Ryuk ransomware by renting its botnet to other cybercriminal groups.

The Takedown of Emotet 

The takedown of Emotet is the result of an international coordinated action performed in January 2021, which disrupted Emotet’s malicious operations. The operation was a collaborative effort between authorities in the Netherlands, Europe, Germany, the U.S., the U.K., France, Lithuania, Canada, and Ukraine, and carried out in the framework of the European Multidisciplinary Platform Against Criminal Threats (EMPACT).

Emotet Uninstaller Module

The law enforcement authorities distributed a new Emotet module in the form of a 32-bit EmotetLoader.dll to the users of all infected computers to automatically uninstall the malware. “The version with the uninstaller is now pushed via channels that were meant to distribute the original Emotet. Although currently the deletion routine won’t be called yet, the infrastructure behind Emotet is already controlled by law enforcement, so the bots are not able to perform their malicious action. For victims with an existing Emotet infection, the new version will come as an update, replacing the former one. This is how it will be aware of its installation paths and able to clean itself once the deadline has passed,” Malwarebytes said.

According to Malwarebytes security researcher Jérôme Segura, the uninstaller module deletes the services associated with Emotet, deletes the run key, and moves the file to %temp%, and then exits the process, without disturbing other operations on the infected devices.

Several industry experts stated that the successful removal of Emotet malware will help various organizations and over a million infected systems. “Pushing code via a botnet, even with good intentions, has always been a thorny topic mainly because of the legal ramifications such actions imply. The lengthy delay for the cleanup routine to activate may be explained by the need to give system administrators time for forensics analysis and checking for other infections,” Malwarebytes added.

Securing Industrial IoT Infrastructures

Internet of Things

Industries across the spectrum are embracing the emerging possibilities of IoT and the connected device ecosystem. The benefits of IoT include unlocking the potential of analyzing real-time, historical behaviors of the edge devices for effectiveness, better management, and productivity by connecting edge traffic to the cloud. The recent innovation in increasing the “bandwidth of the pipe” has enabled bulk uploads through networks and begins a new chapter in deciphering the Internet of Everything. In the past, the focus has been on enabling the faster movement of edge data to the cloud, however, not much focus has been laid upon two very important aspects of data: the quality of the data ingested and the potential vulnerabilities that can present itself as backdoors.

By Raghunath Venkat Thummisi, Founder & CEO, Cannon Cyber

Critical Industrial Automation systems stand apart in terms of complexity, associated legacy technologies, and established governance when it comes to monitoring and management. Critical infrastructure grids such as utility, power, and nuclear don’t push data at the same intervals as other IoT systems do. Moreover, legacy protocols are still in use for communication in many industries, one example being the industrial automation space where we grapple with ModBus, ProfiBus, and Fieldbus communication technology. This opens up a large surface for security attacks across endpoints. The increasingly mandated regulatory compliances for IoT security aim to pre-empt the threats posed by cybercriminals who take advantage of the legacy, siloed technology stack, and protocols to launch network-based endpoint attacks and threaten large asset bases of organizations. IoT and connected devices need to reassess methods by which the attack surface can be minimized, which is the focus of the ISA99/ IEC622443 security standards for Industrial Automation Systems.

Breaching IoT devices allows attackers to build networks across an army of connected devices that can be used to launch massive Distributed Denial-of-Service attacks to bring down large omnichannel platforms. The above example represents only the tip of the iceberg in terms of the challenges that IoT security practitioners face; creating the need for all the associated entities in an IoT security data chain to come together and build a robust security infrastructure that reassesses North-South traffic. The paradigm changes taking place in designing an effective and secure IoT infrastructure have to explore an IoT-native architecture and not merely transpose tools from typical software architectures. As an example, network firewalls are a critical security gatekeeper in traditional infrastructures. However, the same doesn’t hold true when we explore Industrial Automation devices or Industrial IoT (IIoT). Connected devices in industrial automation have been there for decades, however, the know-how needed for managing completed critical Infrastructure grids and nuclear installations has been the responsibility of operational teams. The IT and operational teams have been brought together to build effective and high-response teams, but they come with a price of negatively affecting the decision-making of cybersecurity teams staffing the security infrastructure and hence delaying an effective response to the incoming attacks. Management of the edge devices requires a different approach that prioritizes securing each connected endpoint, to protect against the possibility that the breach of a single device opening a backdoor into other systems.

Traditional designs of deploying a combination of firewall policies, access control lists, and virtual private network nodes complicate an IoT infrastructure, rendering it suboptimal. Excessively intricate IIoT infrastructures with a dynamic network flow may create additional junction points that necessitate the deployment of additional firewall points, sometimes numbering in the hundreds or thousands. A better approach may be to explore endpoint segments and access management.

The above scenarios call for better management, mandates, and regulations to explore holistic design and deployment.

Manageability – A driving factor in the effective design of IIoT security

Given the increasing vulnerabilities, patch management, hotfixes, and upgrades as we know them in the traditional software world prove much more critical in IIoT infrastructures. Also, given the remote deployments, production instances, and complex environments governed by underlying dependencies, “re-fueling in-flight” essentially figuring out a hybrid approach on rolling the upgrades as soon as possible, must be achieved. For example, the time for deploying a hotfix for a particular CVE is much more cumbersome depending on how far apart the endpoint devices are located and if they are within the realm of online patch updates.

Better support and user experience

We see that often, most devices are shipped with default, factory-set passwords that can’t be changed, while some IoT vendors make it harder for customers by not having a simple UI to navigate. Product support is another area of challenge, especially with smaller vendors, which makes it harder for customers to have a secure perimeter.

Hence, it is imperative for IoT vendors to have a mechanism to better deploy authentication using unique credentials on every device, including designing an organization, specific passwords, and secrets management system while enabling their customers to better utilize the product features through ongoing device security and management.

Now, let’s focus on some of the most prominent IIoT Security Attacks:

  1. Firmware Hijacking: Firmware vulnerabilities and a lack of consistency infrequent updates present an opportune moment for an attacker who may leverage vulnerabilities to hijack devices and launch a more coordinated attack.
  2. Distributed Denial of Service (DDoS): DDoS attacks present a serious risk of critical applications being compromised by attackers and losing access to key control systems governing the critical infrastructures. While these types of attacks might not necessarily steal data, the possibility of losing access to critical systems may yield catastrophic results. Some of the largest known DDoS attacks in history were based on IoT devices.
  3. Botnets: Cybercriminals devise botnets by hijacking IoT devices, infecting them with malicious code, and using them as a command center to launch attacks across the device ecosystem and expose the entire network. The largest known Botnet attack that occurred in 2016 when the Mirai botnet literally brought down the internet including a host of businesses across different geographies was a result of the botnet launch leveraging unsecured security cameras.
  4. Port 7547: Attacks targeting this port are well known and there are millions of devices with this flaw. This trend continues despite high visibility through several recent incidents that were targeted at a leading telecom provider’s routers, debilitating the network for a long time.
  5. Malicious packets: Injecting malicious snippets of code or packets and taking control of important applications isn’t new, but this presents a much larger challenge in IIoT ecosystems where attacks in a similar situation might lead to a complete, dangerous override of our critical infrastructures.
  6. Network packet sniffing: In this type of attack, a hacker intercepts network traffic in order to steal sensitive information via a weakened connection between an IoT device and a server. Eavesdropping typically occurs by listening to digital or analog voice communication or via the interception of sniffed data. The attacker could walk away with sensitive, corporate data using this method. Taking advantage of the legacy Layer 7 level communication protocols, attackers can secretly intercept messages by deceiving either party.
  7. Brute Force: Scripting and guessing password patterns and increasing the attack surface upon gaining control presents endless opportunities to cause harm. While there are ways to mitigate them with multi-factor authentication and key management systems, it is important to propagate this technique into IIoT ecosystems.

And then there is the advent of 5G…

Quantum speeds and versatility in data traffic through 5G Networks present a generational set of opportunities for making enterprise systems faster and smarter. However, this comes with risks in terms of dealing with newer adversaries through cybersecurity. As 5G is now quickly shaping up to be a global reality and already in action in select countries, it is now possible that it will completely disrupt IoT connectivity, and more specifically, IoT security.

5G Security – An unknown proposition

5G’s bandwidth and speed give rise to the prospect of new threat vectors within networks which could result in increased sophistication in security attacks. It is a great opportunity for telecom service providers to think about enhanced security frameworks embedded in the 5G service delivery network to provide better security hygiene for their customers.

Virtualized 5G ecosystems provide an opportunity for new services that can be delivered with no installation or upgrading required at the subscriber’s premises, quite literally moving the upgrade and monitoring to a real-time delivery mode. Hence, there is a big opportunity for security solutions operating at the network tier to discreetly sniff suspected packets and block using behavioral patterns driven by Artificial Intelligence and Deep Learning. These services can be managed by service providers to deliver an additional layer of security for their edge devices.

IoT-based cyberattacks continue to grow and the level of malware signals continues to grow at thrice the pace. This is a challenge and opportunity to innovate ground-breaking security products more rapidly and keep pace with the attack engine if not overpower them. Remember, Cybersecurity is probably the only space where both the problems and solutions are equally funded!

This story first appeared in the August 2020 issue of CISO MAG. Subscribe to CISO MAG


About the Author

Raghunath Venkat Thummisi is a passionate product builder, Security practitioner and Evangelist focused on building the next generation Security Products for businesses who are experiencing a rapid change in their Security perimeter. Venkat’s experience is in building scalable Infrastructure Cloud-native SaaS Products with a focus on Security across the landscape from Core to Edge. In doing so, he has built strategic ecosystems of Customer and Channel partnerships. His experience spans big companies such as EMC, RSA, Trizetto as well as his current startup (Cannon Cyber). He is a contributing member of Forbes Technology Council and CISO MAG, he loves to be in the midst of action advising emerging startups to foster innovation.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“Security patching should be a part of a system’s basic maintenance procedure”

A well-rounded and seasoned leader in the field of IT & Information Security, Ashish Thapar is the Vice President and Head for Security Consulting Services – Asia Pacific, NTT Ltd. Prior to this role, he has been responsible for the business and portfolio management of security professional services including Incident Response, Digital Forensics, Threat Intelligence, Security Strategy, T&V, GRC, PCI team within the APAC region while working for several top global organizations. Thapar has a long history of serving countless high-profile clients across multiple business verticals, assisting them with their cybersecurity strategy, governance, and risk management needs.

In an exclusive interview with Augustin Kurian from CISO MAG, Thapar talks about his journey, cybersecurity trends across the world, ransomware attacks, attacks against the health care sector, and more.

In a career spanning two decades, you have held several key security roles. Were you a part of security when the security sector was at a nascent stage in India or the APJ region? What was the journey like? How far has the region and its adoption of cybersecurity evolved?

Yes, it has been almost two decades of learning, practicing, and advising in the cybersecurity field for me and I can say that the journey has been exhilarating, challenging, and very rewarding. Specifically, with respect to India, I have seen a tremendous amount of positive change. I have seen a lot of difference in the way Indian companies used to see security many years ago compared to how they treat security in the present times. That whole compliance mindset to ensure a tick-in-the-box and a single-track product/box-centric approach have thankfully transitioned into a more comprehensive one focusing on all three aspects (i.e. people, process, and technology) while elevating the importance of cybersecurity as a business enabler. Cybersecurity is now not a function that used to struggle to get funding and support from the management; instead, it now enjoys board-level visibility in several companies.

In my opinion, India’s story is not very different from many other regions, apart from some places where data security and privacy regimes have been more mature from a legal/regulatory/industry standpoint. The RBI in particular should be given due credit as they have done a tremendous amount of work in driving cybersecurity maturity in the financial sector. As a practitioner in the field, I can say that the kind of services we used to engage in earlier were typical vulnerability assessment, penetration testing, and some assessment/ certifications. Today we support our customers on threat hunting, advanced SOC services, cyber risk monitoring, red/purple teaming exercises, incident response readiness assessments, tabletop testing, and data breach investigations. The advancements in digital adoption, organizational maturity, cybersecurity service offerings, and the changes in the legal/regulatory landscape that have taken place in the last decade have been phenomenal. Today we have many countries that have enacted stringent data security or privacy laws/regulations not only in the APJ region but globally.

The latest Data Breach Investigation Report (DBIR) suggests a rise in attacks motivated by financial gain, up from 71% in 2019 to 86% in 2020. With the world now dealing with the COVID-19 situation, do you feel the trend will only move upward? What does that mean for the security community?

DBIR is an annual publication from Verizon with incidents and breach data from 81 contributors globally. While the DBIR 2020 is based on a 2019 dataset, we’ve already started seeing in recent months that the phishing attacks are leveraging the COVID-19 chaos and have increased significantly. With reference to the DBIR report from a financial gain perspective, we can say that activities like ransomware, social attacks, malware were already on the rise in the past few years. We are observing a mix of trends with both direct and indirect financial motive gains. Currently this year we see ransomware doubling up since January. We do expect financial motives to move upwards or hover around the same level. Another important insight to look at is the espionage-related cases, which are very specific/targeted and are often under-reported because most of the attacks are covert and complex in nature. Due to the sheer number, most of the time, gullible users and companies are targeted with cyber extortion, ransomware, even cardholder data breaches. Looking at the current social-distancing scenario a lot of countries will be moving very swiftly towards digital currency, China being the first one to launch such state-run digital currency. With this development and forced digital shift for many companies in the unplanned work-from-home situation, we can expect the number of cybercrimes to increase as everything will start moving towards a digital world. The data today can live anywhere, in an end-user system, data center servers, or in the cloud. Hence, the cybersecurity community should be careful about implementing the data-centric perspective and not only be focused on data center security.

What else were the biggest takeaways from the latest DBIR? Did any trends from the report come as a shock to you?

I would not say shock, but it did come as a surprise as “Errors” definitely win the award for best supporting “action”— refer to the schema of VERIZ (Vocabulary for Risk and Incident Sharing) on Github — this year. They are now equally as common as social breaches and more common than malware and are truly ubiquitous across all industries. Only hacking remains higher, and that is due to credential theft and use, which we have already touched upon. Misconfiguration errors have been increasing. This can be, in large part, associated with internet-exposed storage discovered by security researchers and unrelated third parties. While publishing errors appear to be decreasing, we wouldn’t be surprised if this simply means that errors formerly attributed to publishing a private document on an organization’s infrastructure accidentally now get labeled “Misconfiguration” because the system admin set the storage to the public in the first place.

In the North American region, stolen credentials account for over 79% of hacking breaches with 33% of breaches being associated with either phishing or pretexting. Why do you think industries are still not evolved to handle this common threat vector?

I wouldn’t say that this a crisis with every industry or company in North America, but yes, it is the problem with the laggards. The laggards are still dependent on single authentication, using passwords and usernames to authenticate their users, which is just a basic hygiene measure. We need to understand that just using credentials is not going to sufficiently secure your critical systems or data. Also, some of the industries are still not regulated and the need to adopt stringent security controls is not felt by several companies. Having said that, I think the onset of global legislations like the GDPR and other data security and privacy mandates have started to make a difference.

DBIR also stressed that the ongoing patching has been successful against a lot of vectors with fewer than one in 20 breaches exploiting vulnerabilities. Should patching be the part that the industry should focus on? What else can be improved?

Security patching should be a part of a system’s basic maintenance procedure as there are numerous amounts of vulnerabilities that get disclosed every week. Patching helps in protecting where you are completely exposed against known vulnerabilities. Hence, patching should be a major focus and it should be done on a timely basis as part of regular maintenance of a system/platform. But remember, patching would only help where the vulnerabilities are known, and the patches are available. The next level of maturity comes when you start limiting your attack surface by disabling services or features that are not required, disabling users that are not needed, and hardening systems with best-practice security benchmarks.

The focus would be the CIS Critical Security Controls (CSC). Here are the top controls that our DBIR data suggests will be worthwhile for most organizations:

  • Continuous Vulnerability Management (CSC 3): Use this method to find and remediate things like code-based vulnerabilities; also great for finding misconfigurations.
    • Secure Configurations (CSC 5, CSC 11): Ensure and verify that systems are configured with only the services and access needed to achieve their function.
    • Email and Web Browser Protection (CSC 7): Lock down browsers and email clients to give your users a fighting chance when facing the Wild West that we call the internet.
    • Limitation and Control of Network Ports, Protocols, and Services (CSC 9): Understand what services and ports should be exposed on your systems, and limit access to those.
    • Boundary Protection (CSC 12): Go beyond firewalls to consider things like network monitoring, proxies, and multifactor authentication.
  • Data Protection (CSC 13): Control access to sensitive information by maintaining an inventory of sensitive information, encrypting sensitive data, and limiting access to authorized cloud and email providers.
    • Account Monitoring (CSC 16): Lock down user accounts across the organization to keep bad guys from using stolen credentials. The use of multifactor authentication also fits in this category.
    • Implement a Security Awareness and Training Program (CSC 17): Educate your users on malicious attackers and on accidental breaches.

The attacks on the cloud continue. Now, small and medium businesses are becoming the biggest targets of the recent cloud attacks. How can you empower small and medium businesses against cyberattacks?

There is an inherent problem seen in the way SMBs handle cybersecurity. They do not have the same level of management support and funding that you get to see in large organizations and if the SMB belongs to one of the unregulated sectors, then even the worst scenario can be expected. From that perspective, the SMBs should at least follow the 80/20 rule, where 80% of the protection can be built with just 20% of the safeguards and with minimal financial investments. These safeguards can be spread across the three key focus areas, namely protect, detect, and respond. SMBs can also look at adopting “security by design,” which may not require very expensive technology but can surely leverage inherent procedural/ governance security controls. Simple but effective countermeasures such as, but not limited to implementing robust security policy, segregation of duty, least privilege principle controls, and not storing data that is not needed, can go a long way in securing an SMB. They can also look at other emerging avenues like cyber insurance where they can get some level of in-built security protection controls as part of the policy coverage. SMBs should also leverage government-provided cybersecurity expertise, public/private expertise and evaluate some of the niche open source security tools available in the market.

During ransomware attacks, there is an upward trend where hackers are targeting backups and even NAS devices. How can there be tighter airgap?

The aim of a ransomware attack is to destroy data and its copies so that the organization possessing the data gets crippled completely. Health care and educational institutions are increasingly being attacked with ransomware. The digital adoption in the health care sector that was meant to save human life, is now under attack, which could be life-threatening as encrypting data belonging to patients in critical condition could hamper their timely treatment. There is a simple defense mechanism to such attacks. The first obviously being, implementing the CISCSC and the second is to actually make sure that you have very robust backup and disaster management strategies in line with your recovery time objective and recovery point objectives. Thirdly, make sure that the ‘write’ access to your file servers and NAS storage locations is not open to everyone and is marked “read-only” as per the strict least privilege principle. Lastly, segregation of network is important to make sure that you aren’t operating in a wide-open playground lateral movement of any threat is restricted to some extent.

With the COVID-19 situation upon the world, there is an alarming amount of attacks on the health care sector. How can we change this trend? Because at the end of the day, we need our hospitals to be safe.

We see that the health care sector is increasingly coming under attack. As per DBIR 2020, Miscellaneous Errors, Web Applications, and Phishing or Business Email Compromises represent 72% of breaches in the health care sector. The majority of the data under attack in the health care sector is personal data followed by medical data and credentials. Unless you really protect data at its core, no matter how many network-level protection or endpoint-level protections you put in, it won’t really keep you secured for too long. Further, the organizations must conduct a proper risk assessment to prioritize their investments and focus on the issues that matter the most — and accordingly mitigate the risk or bring the risk to an acceptable level. I would also recommend that health care organizations follow the defense-in-depth approach to safeguard their critical systems and data. Our research shows that increasing the number of layered controls — in essence, the number of steps that an adversary has to clear — could be very effective in decreasing the probability of occurrence of a data breach.

This interview first appeared in the August 2020 issue of CISO MAG while Ashish Thapar was at Verizon. He is currently the Vice President and Head for Security Consulting Services, Asia Pacific at NTT Ltd.

Subscribe to CISO MAG


Augustin KurianAbout the Interviewer

Augustin Kurian the Assistant Editor of CISO MAG. He writes interviews and features.

Certified Ethical Hacker (CEH) and Four Other EC-Council Certification Exams Earn College Credit Recommendations from the American Council on Education (ACE)

EC-Council is pleased to announce five certifications that recently received approval from the American Council on Education (ACE). This is a major step to help jump-start college careers as well as document skills and experiences so students and professionals alike can receive post-secondary credit in the U.S. for what they already know. The following certification exams have recently been endorsed:

  • Certified Network Defender (CND)
  • Certified Ethical Hacker (CEH)
  • Computer Hacking Forensics Investigator (CHFI)
  • EC-Council Certified Incident Handler (ECIH)
  • Certified Penetration Testing Professional (CPENT)

These certifications have now been added to the ACE National Guide, the official guide to find courses and exams that carry college credit or competency recommendations. As of February 1st, 2021, EC-Council candidates who become certified in CND, CEH, CHFI, ECIH, or CPENT are eligible to receive an ACE transcript with recommended credits. Although each college and university has different policies regarding credit for prior learning, ACE recommendations help colleges and universities grant credit for skills and knowledge like those demonstrated on EC-Council exams.

For U.S. & International Learners:

Contact your college to find out if you have earned credit through EC-Council exams that can help you make progress toward a college degree.

For the U.S. Military:

Military students may search for ACE-approved EC-Council certifications fitting their occupations to pursue credit opportunities.

For U.S. Colleges & Universities:

Grant credit for prior learning across EC-Council exams to recruit and support post-traditional students.

In May of 2018, EC-Council launched the EC-Council Academia Partner Program. This program offers a no-obligation partnership model where Secondary and Post-Secondary institutions can register and receive immediate benefits which include the following:

  • Automatic Exam Eligibility for students that purchase any full Academia Series
  • Discounted Learning Resources
  • Faculty certification scholarships
  • Complimentary evaluation resources for any faculty member
  • Discounted exam vouchers for any college university faculty member
  • Free Tickets to Hacker Halted USA

We are extremely excited about the recent ACE approval across 5 of our certifications. Aligning EC-Council certifications with ACE was always a goal of ours as we work towards expanding opportunities for students and professionals to receive credit for prior learning within post-secondary environments. We will also soon launch badges through Credly to reward certified members, linking their ACE transcript to their badge and offering a number of other advantages. This is very timely in the midst of many credit and non-credit accelerated workforce tracks and programs focusing on retooling and skilling across these Cybersecurity domains.

 

– Wesley Alvarez, Director of Academics, EC-Council

Along with earning ACE recommendations, EC-Council is also accredited by the U.S. Department of Defense (DoD), CREST, American National Standards Institute (ANSI), National Cyber Security Centre – Certified Training, and more. For more information on EC-Council Academia Partnership, please contact [email protected].


About ACE Recommendations

ACE recommends postsecondary academic credit equivalencies based on faculty expertise. Academic recommendations include a number of semester hours, level, and subject area, which vary based on the experience reviewed. In competency reviews, faculty also validate the skills and competencies that students are expected to master in order to pass the course or exam.

Experiences evaluated by ACE’s Learning Evaluations (formerly CREDIT®) are re-reviewed every three years to ensure that the recommendations remain aligned with current academic expectations in a given discipline.

About EC-Council

International Council of E-Commerce Consultants, also known as EC-Council, is the world’s largest cybersecurity technical certification body. Operating in over 145 countries globally, EC-Council is the owner and developer of the world-famous Certified Ethical Hacker (CEH), Computer Hacking Forensics Investigator (C|HFI), Certified Security Analyst (ECSA), License Penetration Testing (Practical) programs, among many others. EC-Council is proud to have trained and certified over 200,000 information security professionals globally that have influenced the cybersecurity mindset of countless organizations worldwide. For more information, visit eccouncil.org.

Cyberthreats Still Loom Over E-learning Platforms

U.S. Schools Suffer Over 1,300 Data Breaches Since 2005

The year 2020 is certainly a year of change. The pandemic changed every aspect of our lives, keeping people more connected than ever virtually. From work from home to study from home, all the regular activities took a sudden shift towards the digital revolution. Like the health care sector, the education sector also encountered greater challenges while connecting with the students via digital classrooms.

Cyberattacks Rise with E-Learning

As educational institutions and students switched to e-learning options via online portals and applications, opportunistic cybercriminals paved a way to exploit the pandemic to their advantage. Various security incidents were reported in which threat actors targeted e-learning portals with various kinds of phishing attacks, fake domains, and other malicious activities to steal users’ personal information.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

survey from Kaspersky revealed a surge in distributed denial-of-service (DDoS) attacks on online educational services in 2020, compared to 2019. The total number of DDoS attacks increased by 80% in the Q1 of 2020, compared to Q1 2019. Between January and June 2020, the number of DDoS attacks affecting educational services increased by 350%, with the largest rise reported in January 2020, by 550%.

 Cybersecurity in Online Learning

Not only schools and colleges, but employers also relied on e-learning platforms to educate their employees on various security topics. Online learning portals share similar features and challenges as other internet-based services, requiring the sharing and distribution of users’ data.

E-learning platforms usually become victims to cyberattacks or any other security incidents when:

  • Cybercriminals deliberately launch malware or DDoS attacks
  • Users fail to patch vulnerabilities, coding problems, or unknown security loopholes
  • Employees or students inadvertently click on malicious links or phishing pages
  • Hackers deliberate acts like cyberespionage campaigns or unauthorized intrusion

Hence, organizations providing e-learning services should emphasize more on enhancing security risk management and users’ data privacy. They must provide a secure learning environment by analyzing the potential risks from various threats and vulnerabilities.

Mitigating Cyberattacks on E-Learning Platforms

1. Be Cyber aware

It is essential to be aware of the everyday cyber environment. Multiple incidents were reported where teachers were not able to recognize signs of potential phishing emails or links. Educational institutions need to proactively update their teaching staff on basic online safety and security measures, including information on ‘how to detect phishing emails,’ so that they can share the same with their students. This would help control human error because threat actors use social engineering techniques to exploit human psychology.

 2. Formulate a Disaster Recovery Plan

CISOs and security leaders need to be prepared to act immediately in a crisis such as ransomware, DDoS, or brute-force attack – to avert a data breach. Robust incident response and disaster recovery plan will help educational institutions to mitigate, recover from the situation and find out the root cause of the issue as well.

Conclusion

E-learning is here to stay. It is high time institutions consider additional security measures to protect students and staff from evolving cyberthreats. While most educational institutions primarily focus on in-person training related to administrative systems, implementing security measures for e-learning will be a good start towards secure virtual learning.

About the Author

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

FIDO Launches IoT Protocol for Onboarding to Cloud and On-premises Platforms

IoT devices

Based on a recent report titled “IoT Professional Services Market,” the global IoT service market is expected to grow from $98.8 billion in 2020 to $149.9 billion in 2026, at a compound annual growth rate (CAGR) of 7.2% during the forecast period. The report further states that, based on the deployment type, the on-premises IoT professional services segment is expected to lead the market during the forecast period.

The reason behind this is the fact that an organization using on-premises IoT professional services can have total control over the security of information related to their products. However, the onboarding of these IoT devices is still a task as these processes are usually done by a technician manually. This process is laboriously slow, expensive, and not too secure. Thus, the FIDO Alliance has noted these shortcomings and now introduced a FIDO Device Onboard (FDO) protocol. The alliance says that it is a new and open IoT standard that will enable the simple and secure onboarding of IoT devices to the cloud and on-premises management platforms.

The FIDO Device Onboard (FDO) Protocol

As stated earlier, through this FDO protocol, the FIDO Alliance intends to address security, cost, and complexity challenges that come laced with mass IoT device deployment. The IoT market is growing rapidly, and the International Data Corporation (IDC) expects it to surpass the $1 trillion mark in 2022. However, despite the projected growth, noticeably most businesses still have serious concerns about breaches to their infrastructures.

The FDO is an automated onboarding protocol for IoT devices. It leverages asymmetric public-key cryptography to provide the industrial IoT industry with a fast and secure way to onboard any IoT device to any device management system used by the organization.

As per the FIDO Alliance, following are the business benefits of the FIDO Device Onboard protocol/standard:

  •  Simplicity  Businesses no longer need to depend on technicians to install their IoT devices. This also lessens their cost burdens for their services. The highly automated FDO process can be carried out by people of any level of experience quickly and efficiently.
  •  Flexibility  Businesses have the option of choosing which cloud platforms they want to onboard the devices on at the point of installation (as opposed to manufacture). A single device stock-keeping unit (SKU) can be onboarded to any platform, thereby simplifying the device supply chain.
  •  Security  The FDO leverages an “untrusted installer” approach, which means the installer no longer needs – nor do they have access to – any sensitive infrastructure/access control information to add a device to a network.

The FDO Protocol Development Team

FIDO Device Onboard or FDO was developed through collaborative work from the Alliance’s IoT Technical Working Group, led by co-chairs Richard Kerslake from Intel and Giridhar Mandyam from Qualcomm, and vice-chair Geof Cooper from Intel. The other additional contribution to this standard came from the editors of Amazon Web Services (AWS), Google, Microsoft, and ARM.

Christine Boles, Vice President, Internet of Things Group, and General Manager, Industrial Solutions Division at Intel said,

This is a major milestone that aims to solve one of today’s critical challenges with deploying IoT systems. The new FDO standard will help reduce cost, save time, and improve security, all helping the IoT industry to expand rapidly. Implementation of the FDO standard will enable businesses to truly take advantage of the full IoT opportunity by replacing the current manual onboarding process with an automated, highly secure industry solution.

The suggested protocol has reached the “Proposed Standard” status and is now open and free to be implemented by all. However, initially, the specification is targeted at industrial and commercial applications.

Related News:

Akamai MFA provides FIDO2 multi-factor authentication without hardware security keys

Biden’s 100-Day Plan to Enhance Electric Grid Security

Joe Biden, Biden, POTUS, new POTUS, U.S. President, SolarWinds, Solar Winds hack, SolarWinds cyberattack, cybersecurity, cybersecurity budget, cybersecurity head, national cybersecurity head, Joe Biden cybersecurity budget

With the rising cybersecurity incidents in the U.S., the Biden administration is focusing on elevating the country’s security strategy to protect its critical infrastructure and take a step further towards modernized technology.

Recently, the U.S. Department of Energy (DOE) launched an initiative to improve the cybersecurity of electric utilities’ industrial control systems (ICS) and secure the energy sector supply chain. The initiative, named as 100-Day Plan,  is a coordinated effort between the DOE, the electricity industry, and the Cybersecurity and Infrastructure Security Agency (CISA).

What is the 100-Day Plan?

The 100-day initiative implements swift and aggressive actions to tackle the rising cyberattacks. Over the next 100 days, the DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) will advance the technologies and systems to provide cyber visibility, detection, and response capabilities for industrial control systems of electric utilities. The initiative will enhance the cybersecurity defenses and:

  • Encourage owners and operators to implement measures or technology that enhance their detection, mitigation, and forensic capabilities.
  • Include concrete milestones over the next 100 days for owners and operators to identify and deploy technologies and systems that enable near real-time situational awareness and response capabilities in the critical industrial control system (ICS) and operational technology (OT) networks.
  • Reinforce and enhance the cybersecurity posture of critical infrastructure information technology (IT) networks; and
  • Include a voluntary industry effort to deploy technologies to increase the visibility of threats in ICS and OT systems.

A Collective Effort

The DOE also released a new Request for Information (RFI) from the electric utilities, energy companies, academia, research laboratories, government agencies, and other stakeholders for recommendations for supply chain security in U.S. energy systems. The RFI will enable the DOE to implement new initiatives to secure the nation’s critical infrastructure against state-sponsored cyber campaigns. The government and organizations in the U.S. have focused on improving the cybersecurity standards in the wake of the recent high-profile cyberattacks like the Russian-backed SolarWinds hacking campaign and exploitation of Microsoft Exchange server vulnerabilities.

What the Experts Say…

Commenting on the new initiative, the Secretary of Energy Jennifer M. Granholm said, “The United States faces a well-documented and increasing cyber threat from malicious actors seeking to disrupt the electricity Americans rely on to power our homes and businesses. It’s up to both government and industry to prevent possible harms—that’s why we’re working together to take these decisive measures so Americans can rely on a resilient, secure, and clean energy system.”

“The safety and security of the American people depend on the resilience of our nation’s critical infrastructure. This partnership with the Department of Energy to protect the U.S. electric system will prove a valuable pilot as we continue our work to secure industrial control systems across all sectors,” said CISA Director (Acting) Brandon Wales.

Latest Cybersecurity Alert Update CIOs and CTOs Need to Take Note of

CEO, cybersecurity, CISO, Future of the CISO

Since Aug 2020, there has been a new wave of ransom letters being sent to several organizations by actors posing as “Fancy Bear,” “Armada Collective” or “Lazarus Group.” The letters are sent to a generic email address and do not always immediately reach the right person in the organization. In some cases, letters were received by subsidiaries or branches in the wrong country.

 SPONSORED CONTENT 

By SPTel and Radware

The letters from “Armada Collective” were an earlier outlier and used different language compared to letters from the same period and more recent extortion letters from actors posing as “Fancy Bear” and “Lazarus Group.” The latter are consistent in their use of the English language, matching up paragraph by paragraph. The letters have been improved since the start of the campaign by fixing some typos, rephrasing some actions for better clarity, and press coverage of earlier DDoS attacks that impacted financial organizations have been added to instill more fear.

Who are the perpetrators, what is the cost to victims, how should you handle such threats to your organization? Read on to learn more.


Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.