Home Blog Page 95

API Risks: What Are They and How to Manage Them

Risk management is essential to every business. You can’t eliminate risk, but mitigation strategies will help lower the impact and likelihood of catastrophic events such as data breaches.

SPONSORED CONTENT

By Dan Gordon, DevSecOps Evangelist and Marketing Leader at Traceable.ai.

As more companies develop Application Programming Interfaces (APIs), those who manage risk need to understand what risks APIs introduce to the business. Those who equip themselves to handle API risks will be better able to weather any cybersecurity storms ahead.

Let’s break down three significant sources of risk in APIs and how you can reduce your exposure.

1. Coding Risks

The most basic risk is poor coding practices that lead to exploits by malicious actors. Poorly designed or written code could be a ticking time bomb hiding within your application.

Impact of Coding Mistakes

Vulnerable code can lead to account takeover, theft of personally identifiable information (PII), or denial of service.

Broken Object Level Authorization (BOLA) is a common API flaw with potentially catastrophic effects. Many APIs use unique identifiers to retrieve records. For example, an application might request your Facebook profile from an API by calling “facebook.com/api/profile/12345678”. The number on the end of the URL is a “resource identifier.” It uniquely identifies your profile.

BOLA can occur when changing the number at the end of the URL results in viewing someone else’s profile as that person. When something like this happens with sensitive information, such as in medical records or banking applications, a significant data breach could occur, costing millions to the offending company.

It’s not difficult to write the code to protect against vulnerabilities like these, but it sometimes is forgotten or pushed aside by developers for the sake of quick delivery of features.

How to Manage Coding Risks

Education is your best bet to manage coding risks. Your engineers need to know what pitfalls exist and how to avoid them. Automated security scanners have come a long way, but most still miss the big stuff. For example, BOLA will likely bypass web application firewalls and Runtime Application Self-Protection. These tools know that the URL should have an ID at the end, but they won’t know if it’s the wrong ID. The code must be written to protect against these types of business logic attacks.

The OWASP API Top 10 is an excellent way to educate software engineers on the most common API flaws. Work these risks into onboarding and security training. Task your brightest engineers to build frameworks and patterns into the codebase to help make secure code automatic.

Automation can help, but humans on the front line are the actual investment you need to protect against severe coding mistakes.

2. Asset Management

Do you know how many publicly available APIs your company deploys? Do you know all of their endpoints and how to access them?

Many companies are seeing the number of APIs exploding as they add more functionality to an application. It’s not uncommon to see hundreds of microservices deployed, each with an API endpoint used to communicate with other components.

“Shadow APIs,” or APIs created without proper oversight or approvals, are dangerous if no one knows they exist. Leftover testing endpoints and domains could be publicly available without anyone’s knowledge.

Impact of Poor Asset Management

Old endpoints that are still internet-facing could have outdated and insecure code. Several years ago, Facebook left an authentication endpoint exposed on beta.facebook.com and mbasic.beta.facebook.com. The APIs left on the two testing endpoints didn’t have rate limiting enabled and allowed an attacker to brute force password recovery tokens and take over any Facebook user’s account.

If an API endpoint is left available, but no one within the organization knows about it, it could be attacked without your knowledge. You could be leaving a back door unlocked with no guards or security cameras. People can come and go as they please.

From a financial standpoint, if these rogue APIs are running in cloud services, you could be wasting money paying for resources you don’t need or want.

How to Manage Asset Management Risks

An essential tool in asset management for APIs is API discovery. API discovery is automation that helps you find all exposed and vulnerable endpoints. You can then review and shut down unsafe or unwanted endpoints.

If unwanted endpoints are using cloud resources, you can use tools like Swabbie to find and shut down unused resources. Swabbie can find the endpoints no one uses but are still hanging around, costing you money.

3. Excessive Data Exposure

Data exposure occurs when APIs return too much data to the client. Each client should only receive the data they need to perform their function. Otherwise, another vulnerability could be compounded by exposing PII or other sensitive data.

Uber’s API had a vulnerability that led to excessive data exposure. An endpoint returned information about the user, including their email and physical address. Unfortunately, this endpoint was susceptible to a BOLA attack and produced another user’s record when the client used a different user’s ID. The API gladly spits out the personal information of any user in the system. The client only used a fraction of the data returned.

Impact of Excessive Data Exposure

Excessive data exposure can lead to account takeover and theft of PII. It often is chained to another vulnerability to steal data to impersonate someone to another service or steal their identity.

How to Manage Excessive Data Exposure

APIs shouldn’t serve data not used by the client. This practice reduces exposure and the chance that another vulnerability leads to a data breach.

Also, APIs that aren’t meant to collect or distribute sensitive data shouldn’t return it as part of a request. Microservices typically have a unique data store, and copying personal data into multiple places isn’t safe. Keep a close eye on where your data is stored and how someone can access it.

Tools exist that can find sensitive data. For example, Amazon Macie can scan what you have stored in your AWS S3 buckets for sensitive data, and Traceable AI can help detect sensitive data leakages at run-time. You can use this information to decide what you should store and where. AI-driven automation can make it easier to find and classify data, so you know what you’re exposing to the outside world.

Managing Risks in an API World

APIs are everywhere. If software is eating the world, APIs are the teeth.

APIs and microservices help companies become more agile. They help speed up the delivery of new products and features. They connect different services so business owners can automate almost everything.

But these new advancements bring new risks. Learn to identify and manage these risks so the APIs don’t end up eating you.


About the Author

Dan Gordon is a DevSecOps evangelist and marketing leader at Traceable.ai. He is an IT software and product leader from companies such as GitLab, Electric Cloud, HP, and Opsware with over 20 years of IT leadership and software experience including the ideation, product management, and positioning of multiple award-winning DevOps tools. He is guided by his “time in the trenches” as an application developer, system and network security administrator, systems architect, and IT leader. Dan also draws from his experience leading the software delivery and Agile transformations of several product organizations.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Has Babuk Ransomware Gang Attempted a Slam Dunk on Houston Rockets?

houston rockets ransomware attack

It is the Rockets vs the Babuk ransomware gang, and it seems like Babuk has drawn first blood with a slam dunk. No, we are not talking about a basketball match here. We are talking about an alleged ransomware attack that claims to have leaked Houston Rockets’ internal business data on the dark web. The investigation is still ongoing, and a team spokesperson said that they are coordinating and working with the FBI in close quarters.

Babuk Operators Go 1-up on Rockets…or Did They?

As per a Reuters report, Houston Rockets’ “internal security tools” successfully defended the alleged ransomware attack however, a few systems were impacted during the attack. Tracey Hughes, the team’s spokesperson told Bloomberg that the “attack has not affected any operations” of the team in the ongoing NBA season. He added that the attack did not curtail “our ability to take care of our fans, employees, and players.

Houston Rockets’ spokesperson did confirm that it was a ransomware attempt but when asked about the name of the criminal gang behind the attack, he remained tight-lipped. However, Bloomberg’s report called out the newly discovered Babuk ransomware gang, which is said to be targeting known organizations off late.

Related News:

New Year Brings New Ransomware Strain “Babuk Locker”

Babuk ransomware gang reportedly posted 500 GB worth of Houston Rockets’ internal business data on its dark web forum. The alleged data includes contracts, non-disclosure agreements (NDA), and financial data, which the gang is threatening to make public if the Houston Rockets fail to pay. Hughes admitted that the team’s management was aware of these claims from Babuk and was examining if it stands true.

Know More About Babuk

Babuk Ransomware is turning out to be one of the most successful ransomware campaigns to hit organizations in 2021. Until mid-January, five organizations have already confirmed to have been breached by the newly discovered strain — and one is known to have paid a ransom of as much as $85,000 to the criminals. To know more about Babuk ransomware, read CISO MAG’s interview with John Fokker, Head of Cyber Investigations and Principal Engineer, McAfee, who discussed Babuk’s unique vectors/techniques, and methods to evade detection.
John Fokker quote for CISO MAG

Related News:

McAfee Reveals the Unknown About Babuk Ransomware

FBI Removes Malicious Web Shells from Microsoft Exchange Servers

Brand Phishing Attacks

The FBI executed a court-authorized operation to copy and delete malicious web shells from hundreds of vulnerable systems in the U.S. that were running Microsoft Exchange Server software.

The Unpatched Flaws

Microsoft Exchange Server software provides enterprise-level email services to organizations globally. Multiple state-sponsored cybercriminal groups like Hafnium and DearCry exploited zero-day vulnerabilities in Microsoft Exchange Server software between January and February 2021. Threat actors deployed web shells and malicious scripts to gain continued remote access to email systems. Cybersecurity experts found a massive amount of information being transferred from the compromised Exchange servers to unknown IP addresses.

However, Microsoft released fixes in March 2021 to address the four critical Zero-day vulnerabilities (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) and three other vulnerabilities (CVE-2021-27078, CVE-2021-26854, and CVE-2021-26412) in its Microsoft Exchange servers and urged organizations and users to apply them as early as possible.

“Many infected system owners successfully removed the web shells from thousands of computers. Others appeared unable to do so, and hundreds of such web shells persisted unmitigated. This operation removed one early hacking group’s remaining web shells which could have been used to maintain and escalate persistent, unauthorized access to U.S. networks,” the DoJ said.

Removing the Malicious Web Shells

Ever since the Exchange flaws were disclosed, Microsoft and other industry experts released security updates, detection tools, and other preventive measures to assist victim organizations to protect against the series of cyberattacks. Even the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) released a joint advisory to provide enterprises guidance on detecting, protecting, and remediating against this malicious activity.

The FBI removed the web shells on hundreds of servers by issuing a command through the web shell to the server. This command is specially crafted to make the server delete only the web shell by identifying its unique file path. However, this operation did not fix any Microsoft Exchange Server zero-day vulnerabilities or remove any additional malware that threat actors may have deployed on victim networks by exploiting the web shells.

“This court-authorized operation to copy and remove malicious web shells from hundreds of vulnerable computers shows our commitment to using any viable resource to fight cybercriminals. We will continue to do so in coordination with our partners and with the court to combat the threat until it is alleviated, and we can further protect our citizens from these malicious cyber breaches,” said Acting U.S. Attorney Jennifer B. Lowery of the Southern District of Texas.

97% of Organizations Suffered a Mobile Malware Attack in 2020

Malware and Vulnerability Trends Report, Mobile malware threats

The number of threats that our mobile devices encounter increases every year and the risks from mobile malware has a large share in it. Research from Check Point revealed that every organization has encountered at least one mobile-related attack last year. In its 2021 Mobile Security Report, Check Point revealed that nearly 97% of organizations in 2020 faced mobile threats that used multiple attack vectors. Around 46% of organizations had at least one employee download a malicious mobile application. Banking Trojans, mobile Remote Access Trojans (MRATs), Clickers, Dialers, and Ad fraud were among the most common malware applications downloaded.

Key Findings

  • At least 40% of the world’s mobile devices are inherently vulnerable to cyberattacks.
  • Of 93% of security incidents originated in device network attacks, 52% are phishing attacks, 25% are related to C&C communication with malware already on the device, or 23% involved infected websites/URLs.
  • Among the applications that had major vulnerabilities in 2020 are the world’s most popular social apps, including Facebook, Instagram, WhatsApp.
  • COVID-19 is the new app attack premise, with skilled threat actors exploiting the public’s concerns with the pandemic via malicious apps that are masquerading as providers of legitimate help in times of crisis.
  • Ransomware has gone mobile as in the case of Lucy, a Malware-as-a-Service (MaaS) botnet and a dropper for Android devices.
  • Mobile Device Management (MDM) is a powerful new attack vector as was seen, for example, with a new Cerberus malware variant that infected over 75% of one company’s devices via corporate-owned MDM.
  • Major threat groups are focusing on mobile, conducting elaborate and sophisticated targeted attacks, improving their mobile arsenal with capabilities that have yet to been seen on mobile.

Top Five Mobile Malware

Check Point’s report also revealed the top five mobile malware in 2020. These include:

  1. Hiddad
  2. xHelper
  3. Necro
  4. PreAMo
  5. Guerrilla

“Researchers have been observing a continuous rise in the number of attacks and data breaches that are coming in through the mobile endpoint. As such, it has become all too clear that the new normal means more numerous and more sophisticated mobile security threats, making robust mobile security a key business imperative,” Check Point said.

Security Precautions Against Mobile Malware

While mobile devices are vulnerable to various malware attacks, there are certain security measures to avoid them. These include:

  • Use a virtual private network (VPN) to secure the data transfer while using public Wi-Fi networks.
  • Download apps only from legitimate sources.
  • Make sure to encrypt any sensitive data in the mobile. Your valuable information will remain secure, even if malware steals it.
  • Use mobile vulnerability scanning to identify unknown vulnerabilities.
  • Regularly update the mobile software and applications in the device to fix potential vulnerabilities.
  • Install mobile security software.

Cybercriminals are constantly looking for new ways to break into victims’ devices. We need to consider our mobile devices the same way we treat our computers and servers, where we store a large amount of information. Since mobile devices carry most of our sensitive data like banking details, emails, and other private information, it is imperative to include them in the data security model.

Episode #10: The Case for Virtual Cybersecurity

Virtual Cybersecurity

With the rapid pace of digitalization, businesses are increasingly exposed with more attack surface for cyber criminals to compromise their private data and networks.

SPONSORED CONTENT

Traditional methods of deploying on-premise cybersecurity cannot with this changing demand. For improved responsiveness to threats, one must look at virtualized cyber security solutions such as a Virtual (vFirewall) deployed on a Software Defined Network to close the gaps with on demand provisioning and scaling. End users are also turning to Managed Security Service Providers (MSSP) with the expectation of greater speed to deploy and scale cyber security.

In this episode, Ho Chin Chow, Deputy Director, Product Management, SPTel explains how virtualized cyber security such as vFirewalls can help businesses react quickly to the changing threat landscape and control security spending with just in time provisioning.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

 

Unlike other vFirewall solutions, SPTel’s vFirewall can be deployed as-a-Service, swiftly, over SPTel’s end-to-end software defined network. It is also a dedicated vFirewall service (unique in the market) which means end users will have improved control over security policies and updates.

Ho Chin Chow is the Deputy Director of Product Management in SPTel and Product Owner of SPTel’s product portfolio consisting of Connectivity, Internet, SDWAN, IoT-aaS, Managed Network & Security. He is engaged in thought leadership within SPTel and leads the product track in its digitalization project.

He is an accomplished product management professional with 18 years of telecommunications experience. His product knowledge spans both local and regional spheres.

RELATED STORY

Stay Ahead of Cyberattacks with Virtual Cybersecurity

 

 

 

 

 

 

COVID-19 and the Current Cyberthreat Landscape in India

SideCopy Malware Campaign

It’s been over a year since the first COVID-19 death was reported in the state of Karnataka, India, in March 2020. With concerns of high mortality rates from the global pandemic, the government of India announced strict lockdowns to implement isolation, social distancing, and contact tracing. In November 2020, the country saw COVID cases plummeting, with patients showing mild to moderate symptoms compared to other countries. And while India was heaving a sigh of relief in the new year, the deadly disease made its way back in February, putting the health care sector in shambles. As of today, April 14, 2021, the COVID figure in India has skyrocketed to approximately 180,000 cases. The state of Maharashtra — with over 50,000 cases per day — has announced strict curfew-like restrictions on the movement of people, newly making India a soft target for cybercriminals.

By Pooja Tikekar, Sub Editor, CISO MAG

A CoWin Decoy?

India has been aggressive with its vaccination drive since its launch in January 2021, for health care and frontline workers first in line. The second phase of the vaccination program for the public kickstarted on March 1, 2021. The two vaccines being administered include “Covishield” from the Serum Institute of India and “Covaxin” from Bharat Biotech. Technology plays a critical role in planning, deploying, and monitoring vaccination programs. Hence, citizens are urged to register via Aarogya Setu or on the CoWIN website. However, hackers are testing the country’s digital architecture, and allegedly impersonating the legitimate CoWIN website to coax citizens into registering on the fake portal and exfiltrate their personal information.

RDP Attacks Skyrocket

Remote work continues to top the business continuity operations in India. According to a cybersecurity report from Kaspersky, India witnessed 9.04 million brute-force attacks against remote desktop protocol (RDP) in February 2021, compared to 1.3 million in February 2020 and to 3.3 million in March 2020. Working in decentralized environments has become the new normal and brute-forcing RDPs, the most common technique for cybercriminals to gain access to Windows systems and execute malware.

“Remote work isn’t going anywhere. Even as companies begin considering re-opening their workplaces, many have stated that they will continue to include remote work in their operating model or pursue a hybrid format,” said Dmitry Galov, security expert at Kaspersky. “That means it’s likely these types of attacks against remote desktop protocols will continue to occur at a rather high rate. 2020 made it clear that companies need to update their security infrastructure, and a good place to start is providing stronger protection for their RDP access.”

The New-age Oil Leaks Copiously

The data breach landscape in India, pre-COVID, was simple. Adversaries launched ransomware attacks by encrypting the data on vulnerable systems and demanding ransom in exchange for a decryption key. Cybercriminals were complacent in inventing new attack vectors. But as the adage goes, change is the only constant. Today, ransomware groups are re-inventing their modus operandi to not just attack the data or “the new-age oil,” but the brand image of a business. With improved infrastructure, India is opening its doors to global market players. Threat actors are leveraging this opportunity to attack the brand image of a business/enterprise by dropping malware payloads on the targeted system and exporting data, in turn damaging intellectual property and national security.

The recent MobiKwik data leak exposed the data of 3.5 million users, with 6TB of KYC details and 350 GB of compressed MySQL dump. To add to the list, the personal information of 533 million Facebook users from 106 countries was leaked for free on an underground hacking forum – with 6.1 million users from India alone. And if this was not enough, India’s second-largest stockbroker, Upstox, was reportedly the latest victim of a breach, allegedly leaking data of 2.5 million users.

Souring India-China Relations

Ever since the pandemic broke out, India’s relationship with China turned sour. This was evident in the Mumbai power outage in October 2020, which crippled the financial capital with chaos. An investigation from Maharashtra cyber department revealed a malware attack with unaccounted data transfer from a foreign server to the Maharashtra State Electricity Board (MSEB) server. However, evidence from Recorded Future underlined the geopolitical tensions and border clashes between the two Asian neighbors. It claimed that Chinese-state sponsored group “RedEcho” targeted India’s power grid. However, it did not stop here. CERT-In averted a hacking attempt on Telangana state power utilities, TS Transco and TS Genco, by a Chinese cybercriminal hacking group.

In the past, the Indian government alleged Chinese threat actors for attacks on the National Informatics Centre (NIC), the National Security Council (NSC), and the Ministry of External Affairs (MEA). The transformative role of technology impacted Indian cyberspace and the information sector. Another report stated that India was named one of the most cyber-targeted countries globally in 2019, with over 50,000 cyberattacks from China alone. Whereas, the IBM Security report titled “2021 X-Force Threat Intelligence Index,” revealed that India was the second most cyberattacked country in the APAC.

Chief of Defense Staff, General Bipin Rawat says…

https://www.youtube.com/watch?v=RI_2eoiuOX8&t=55s

Where do we go from here?

Apart from vaccine disruptions, RDP attacks, and foreign intrusion, team CISO MAG continues to observe common attack trends such as phishing and business email compromise directed towards Indian governments and enterprises. Armies in countries like the U.S. have a cybersecurity unit (U.S. Cyber Command) that is responsible for countering cyberwarfare. India has cyber cells attached to its state police forces, and in a similar vein, the Indian government needs to seriously consider a cyberwarfare unit within the armed forces and scale up its cyber maturity.

Cyberwarfare is here to stay threat actors are eyeing every chance to sabotage the country’s defense mechanism. Out of the many attempts made by security agencies, India’s agility in incident response has been inadequate. And with the soaring second COVID-19 wave, it would be interesting to watch how India combats the vicious nature of existing and new cyberthreats.

What are your thoughts on this? Write to us at [email protected]


About the Author

Pooja Tikekar is the Sub Editor at CISO MAG, primarily responsible for quality control. She also presents C-suite interviews and writes news features on cybersecurity trends.

More from the author.

NSA Alerts About Four Critical Vulnerabilities in Microsoft Exchange Servers

Microsoft November 2021 Patch Tuesday, Windows 10, Microsoft PrintNightmare

The National Security Agency (NSA) informed Microsoft about four critical vulnerabilities that could be exploited by attackers to compromise Microsoft Exchange Servers remotely. The vulnerabilities CVE-2021-28480CVE-2021-28481CVE-2021-28482, and CVE-2021-28483 are present in 2013, 2016, and 2019 versions of the Exchange Server. If exploited successfully, the vulnerabilities could allow threat actors to perform remote code execution on targeted systems.

However, Microsoft clarified that there is no evidence of hackers exploiting the vulnerabilities reported by the NSA. Besides, Microsoft released security patches for the bugs to avoid any risks.

“Cybersecurity is national security. Network defenders now have the knowledge needed to act, but so do adversaries and malicious cyber actors. Don’t allow them to exploit this vulnerability on your system,” Rob Joyce, NSA’s Director of Cybersecurity, said in a media statement.

Microsoft Releases Security Patches

Cybersecurity hygiene and patch management have become an important aspect for organizations after a series of attacks on Microsoft Exchange Servers. In its April 2021 Patch Tuesday, Microsoft released security fixes for 108 vulnerabilities, with 19 classified as Critical and 89 as important. There are also five zero-day vulnerabilities patched in this update along with the four critical vulnerabilities discovered by the NSA.

Image Courtesy: Microsoft

“Customers who installed the March 2021 security updates for supported CUs can install the April 2021 security updates and be protected against the vulnerabilities that were disclosed during both months. If you are installing an update manually, do not double-click on the .msp file, but instead run the install from an elevated CMD prompt,” Microsoft said.

The four vulnerabilities that were publicly exposed but not exploited include:

CVE-2021-27091 – RPC Endpoint Mapper Service Elevation of Privilege Vulnerability

CVE-2021-28312 – Windows NTFS Denial of Service Vulnerability

CVE-2021-28437 – Windows Installer Information Disclosure Vulnerability – PolarBear

CVE-2021-28458 – Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability

The Win32k Elevation of Privilege vulnerability CVE-2021-28310, discovered by Kaspersky researcher Boris Larin, was found exploited in the wild by the BITTER APT group.

“We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access. Unfortunately, we weren’t able to capture a full chain, so we don’t know if the exploit is used with another browser zero-day, or coupled with known, patched vulnerabilities,” Kaspersky said.

CISA’s Deadline to Patch Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) recently ordered federal agencies to install the newly released Microsoft Exchange security updates by April 16, 2021. The agency stated that threat actors might reverse engineer the updates to create working exploits due to their severity and public disclosure.

“CISA has determined that these vulnerabilities pose an unacceptable risk to the Federal enterprise and require immediate and emergency action. “This determination is based on the likelihood of the vulnerabilities being weaponized, combined with the widespread use of the affected software across the Executive Branch and high potential for a compromise of integrity and confidentiality of agency information,” CISA said.

Global Median Dwell Time Drops Below One Month: FireEye Report

median dwell time, Supercharged AI Cyberattacks are Unavoidable

Global Median Dwell Time (defined as the duration between the start of a cyber intrusion and when it is identified) has been reducing over the past decade. For the first time, it has dropped below one month. Today, organizations are independently detecting most of their incidents. In fact, internal incident detection rose to 59% in 2020 – a 12-point increase. The top five most targeted industries, in order, are Business and Professional Services, Retail and Hospitality, Financial, Health care, and High Technology. These findings are revealed in the FireEye® Mandiant® M-Trends® 2021 report. Now in its 12th year, M-Trends brings together the best of cybersecurity expertise and threat intelligence with statistics and insights gleaned from recent frontline Mandiant investigations around the globe.[1]

FireEye is an intelligence-led security company. Mandiant, a part of FireEye, brings together the world’s leading threat intelligence and frontline expertise with continuous security validation to arm organizations with the tools needed to increase security effectiveness and reduce organizational risk.

This year’s report outlines critical details on trending attacker techniques and malware, the proliferation of multifaceted extortion and ransomware, preparing for expected UNC2452 / SUNBURST copycat threat actors, growing insider threats, plus pandemic and industry targeting trends.

“UNC2452, the threat actor responsible for the SolarWinds supply chain attack, reminds us that a highly-disciplined and patient actor cannot be underestimated. This actor’s attention paid to operational security, counter forensics, and even counterintelligence set it apart from its peers. Defense against this actor will not be easy, but it is not impossible. We have learned a great deal about UNC2452 in recent months, and we believe that intelligence will be our advantage in future encounters,” said Sandra Joyce, Executive Vice President, Global Threat Intelligence, Mandiant.

“This year’s M-Trends report identified the three most frequently used initial vectors of compromise as exploits (29%), phishing emails (23%), and stolen credentials or brute-force (19%). While phishing remains a preferred vector by cyber threat actors, we saw more actors leveraging exploits to compromise victims. The increase in exploit usage should remind organizations to have a more robust plan for patching product vulnerabilities. One of the challenges here is identifying what sources and information are available to make better risk-based decisions when prioritizing what systems and applications to patch now and what to patch at a later stage based on current knowledge about exploitation and targeting by threat actors,” said Jurgen Kutscher, Executive Vice President, Service Delivery, Mandiant.

Global Median Dwell Time drops below one month for the first time

Over the past decade, Mandiant has observed a trending reduction in global median dwell time. This measure went from over one year in 2011 to just 24 days in 2020 – that’s more than twice as quickly identified in comparison to last year’s report with a median dwell time of 56 days. Mandiant attributes this reduction to continued development and improvement of organizational detection and response capabilities, along with the surge of multifaceted extortion and ransomware intrusions.

Median dwell time trends varied by region. The Americas continued to decrease. The Americas median dwell time for incidents discovered internally improved the most – dropping from 32 days down to only nine days – marking the first time a region has dipped into single digits. Conversely, APAC and EMEA experienced an overall increase in median dwell time, which Mandiant experts believe to be influenced by a greater number of intrusions with dwell times extending beyond three years, as compared to the Americas. 

Median Dwell Time
Steve Ledzian, Vice President and Chief Technology Officer, APAC, Mandiant

“Organizations in APAC took a median of 76 days in 2020 to learn of intrusions into their networks. Ransomware and extortion crews need much less time than that to find critical data, encrypt it, and then extort the victim with threats to make that critical data public. With modern multifaceted extortion, breach disclosure is now in the control of the attacker, not the victim,” said Steve Ledzian, Vice President and Chief Technology Officer, APAC, Mandiant. “In striving to be cyber resilient, organizations must continue to endeavor to have a capability to detect and respond to inevitable prevention failures.”

Ledzian said the challenge here is the detection and response technologies required to notice these intrusions – they need to be piloted by cybersecurity analysts who can interpret and investigate the data they return. The lack of available cyber talent in the market compounds this problem making it a top challenge for organizations to address. He observes that Managed Detection & Response (MDR) services are gaining in popularity as a result of these challenges and are providing a quick fix for organizations who don’t want to build out this expertise in-house. 

Internal Detections on the Rise

While last year’s report noted a drop in internal detections of intrusions compared to the previous year, Mandiant experts observed a return of organizations independently detecting most of their incidents. Internal incident detection rose to 59% in 2020 – a 12-point increase compared to 2019. This return to organizations detecting the majority of intrusions within their environments is in line with the overall trend observed over the last five years.

Notably, internal detection was on the rise across all regions year-over-year. Organizations located in the Americas led the internal detection trendline at 61%, followed by EMEA and APAC closely aligned at 53% and 52%, respectively. In comparison, APAC and EMEA organizations received more notifications of compromise from external entities, versus North American organizations.

Median Dwell Time, FireEye, Mandiant
Yihao Lim, Principal Intelligence Advisor, APAC, Mandiant

Yihao Lim, Principal Intelligence Advisor, APAC, Mandiant said, “In 2020, APAC organizations most commonly received notification of compromise from external entities, compared to the detection intrusions themselves. Looking ahead to 2021, developing in-house threat intelligence capability is imperative, so organizations can cross-reference their observations with external notifications without being over-reliant on third-party vendors.” 

 

 

 

Attackers Narrow Sights on Retail & Hospitality and Health care

The top five most targeted industries, in order, are Business and Professional Services, Retail and Hospitality, Financial, Health care, and High Technology.

Mandiant experts observed that organizations in the Retail and Hospitality industry were targeted more heavily in 2020 – coming in as the second most targeted industry compared to 11th in last year’s report. Health care also rose significantly, becoming the third most targeted industry in 2020, compared to eighth in last year’s report. This increased focus by threat actors can most likely be explained by the vital role the healthcare sector played during the global pandemic.

View the full report here: https://www.fireeye.com/mtrends


[1] Report metrics are based on Mandiant investigations of targeted attack activity conducted between October 1, 2019 through September 30, 2020.

Identity Management Day: Here’s What Experts Have to Say

Research has pointed out that nearly 80% of organizations have faced some sort of security breach due to identity-related issues, even here nearly every single participant of the survey (99%) believed that the incident could have been prevented had there been a proper security measure in place. The latest Verizon’s DBIR also points out that 81% of security incidents hark back to weak/compromised passwords. To shed light on the precariousness of weak passwords and identity-related security, Identity Management Day is observed to raise awareness on securing digital identities and establish best practices.

To know the key areas organizations and individuals must focus on to prevent an untoward cybersecurity incident, CISO MAG has gathered opinions from several industry experts who talk about the relevance of Identity Management Day, best practices in identity management, and more. Read on:

1. Importance of Protecting Our Digital Identities

digital identity service, Identity and Access Management

“Identity Management Day emphasizes the importance of protecting our digital identities (which is increasingly critical as the acceleration of digital transformation efforts opens new doors for threat actors). With many internet users holding dozens of online accounts across various services, it has become more difficult for them to memorize numerous, complex passwords. Unfortunately, password reuse has become common malpractice that increases the chances of account hijacking when one set of a user’s credentials are leaked. More than 80% of hacking-related breaches are tied to lost or stolen credentials and it is now self-evident that passwords alone are not enough when it comes to authenticating users.

As the security landscape evolves, consumers and businesses must work together to ensure the privacy of corporate and personal data. To properly verify the identities of their employees and customers, companies must enhance their security protocols by establishing continuous, context-based security throughout the entire login experience. Solutions like multi-factor authentication (MFA) and single sign-on (SSO) don’t require users to remember countless passwords, while also mitigating the risk of account compromise. On a consumer level, users can safeguard their digital identity by educating themselves on the risks of password reuse, following cybersecurity best practices, and staying informed on rising threats. Because we now live in a time when our daily lives revolve around the internet and our various accounts therein, identity management awareness has never been more critical.”

– Anurag Kahol, CTO and Cofounder, Bitglass

2. Pandemic has created a breeding ground for scams

Senior citizens data

“According to the FTC, cases of identity theft nearly doubled from 2019 to 2020, reaching an astonishing 1.3 million cases in the U.S. While this is undoubtedly a drastic increase, malicious actors are still leaning on many of the same tactics to impersonate innocent consumers and cause personal or financial harm. As hackers only require a few tidbits of information to build an online profile, consumers can take several measures to properly defend themselves and not fall into common pitfalls.

First, any time you download a new app, create an online account or configure a new electronic device, data is collected and potentially shared. One of your first orders of business should be to look up the privacy settings of whatever platform you’re using to understand how you can further protect your personal information and leverage additional security measures like two-factor authentication and data encryption. You should also be mindful of applications that incorporate location services and how they’re collecting, utilizing and/or sharing this data. Additionally, make sure you’re using various, unique passwords for meaningful accounts as it’s incredibly easy for hackers to access more information by recycling stolen credentials. Lastly, avoid any suspicious messages (emails, texts, voicemails, etc.) and websites that don’t seem legitimate as this is often an attempt at phishing or malware.

While the pandemic has created a breeding ground for scams, fraud and identity theft, it also led to a surge in cyberattacks. Organizations play a vital role in safeguarding consumer data and Identity Management Day is an important reminder that it’s also their responsibility to ensure sensitive information doesn’t fall into the wrong hands. Enterprises must be fully transparent with consumers about what information they need, how they utilize it and what they’re doing to protect it. Any business or agency that is operating within any digital capacity needs to treat customer data as if it were their private information. Establishing a culture that puts the customer and security first will better prevent data leaks and breaches that lead to identity theft.”

– James Carder, CSO, LogRhythm

3. Everyone, In Some Form, Is Vulnerable to Attack

data breaches, Verizon Data Breach Investigation Report

“So much Personally Identifiable Information (PII) has been exposed in breaches over recent years that it is quite easy for hackers to use our identities against us. Everyone, in some form, is vulnerable to attack. In particular, the rich amount of compromised passwords and the rise in cloud-based applications has left companies more vulnerable to compromise than ever before.

The security landscape has completely shifted since the pandemic and businesses need to be able to support a long-term hybrid workforce going forward. New research from Centrify showed that an overwhelming percentage (90%) of cyberattacks on cloud environments in the last 12 months involved compromised privileged credentials.

Should a cybercriminal attain an employee’s credentials, they are able to log into their email, and then use that information to access more company services and applications – all with the company and victim being none the wiser. If the credentials entered are valid, the same alarms are not raised as to when an authorized user attempts entry from the outside.

This means identity access management (IAM) solutions will need to be front and center during strategy discussions to ensure that the right employees have access to the correct resources with an appropriate level of privileges. Otherwise, you run the risk of cybercriminals exploiting these weaknesses and your business ultimately becomes an embarrassing headline in the news, such as the recent breach at Verkada where credentials were compromised.

Organizations need to look at where identity management and data security meet. First and foremost, developing a working relationship between data security and IAM teams is key. Furthermore, deploying data-aware cybersecurity solutions will significantly minimize the risks because even if an adversary has “legitimate” access to data through stolen credentials, they are prevented from copying, moving, or deleting it.  Also, the roll-out of multi-factor authentication (MFA) is another component to fighting the growing tide of compromised credentials.”

Tim Bandos, CISO, Digital Guardian

4. Nex-Gen Identity and Access Management solutions that could save a lot of time and effort

Identity Access

“Nowadays, the Corporate network has expanded beyond the traditional organization boundary to the public and private cloud infrastructure. With this comes, the requirement to provide access to individual network entities (users and devices) to a variety of cloud and on-premises applications. Users may include customers, partners, and employees; devices include computers, smartphones, routers, servers, controllers, and sensors.

It becomes cumbersome to manage everything manually while maintaining a high compliance level. Therefore, it is required to manage all the user identities and access across corporate assets as one user could have multiple identities and accesses across multiple resources. This in turn creates a high-security risk as most of the data leaks happens due to misuse of user identities present in the system. In 2017, Identity theft accounted for 69% of all data breaches. Moreover, malicious outsiders were the leading source of data breaches, resulting in 1,269 incidents in 2017 and despite 45% of American companies paying their hackers during a ransomware attack, only 26% of those businesses had their files unlocked.

Thus, the goal of identity management is to grant access to the enterprise assets that users and devices have rights to in respective contexts. That includes onboarding users and systems, permission authorizations, and the off-boarding of users and devices promptly.

So, what we need is a mechanism that can create, modify, track user activities and manage identities across all the corporate resources along with system admins manually checking and auditing everything regularly to avoid any possible security risk and to ensure compliance with corporate policies and government regulations. Many of these manual activities can be automated with advanced AI ML capabilities present in Nex-Gen Identity and Access Management solutions that could save a lot of time and effort for the people managing the system. I think in this way we can securely govern and manage identities in an ever-growing corporate environment with users requiring more and more accessibility across all resources with this work from home COVID scenario.”

– Kunal WasonTechnical Product Manager- Security, TechnoBind

5. IAM Is Now Needed More Urgently Than Ever

Zero Trust, cybersecurity

“Identity Management, also referred to as Identity and Access Management (IAM), is about managing and accessing identity and privileges of customers, partners, and employees in accessing applications. The need for the right identity management is to provide those needed with the right level of access and resources. By using IAM not only can organizations authenticate and control access of the individuals which plays a very important role in securing the data and the identity of the users. With remote working and in case of organizations located across the globe, there is a need for secure access through central systems. With IAM, there is no safer way to ensure that only the right people access the right applications.

IAM is now needed more urgently than ever considering the changing dynamics in the office-work dynamics post-pandemic. Currently, experts believe Unified Access Platform, AI-powered IAM and adaptive authentication, Customer Identity and Access Management (CIAM) and SaaS-delivered Access Management are predicted to be the latest trends in the IAM sector.

For the first time, The National Cybersecurity Alliance and the Identity Defined Security Alliance (IDSA) started the Identity Management Day, with its inaugural on April 13, 2021. This has been started to ensure organizations and individuals create awareness about the importance of identity management. This is a great initiative that will bring the focus of the C-Suite on the need for the right IAM solution. With more focus and research on IAM, organizations can focus on fighting data breaches and cyber identity thefts leading to catastrophic damages in such situations.”

– S Sriram, Chief Strategy Officer, iValue InfoSolutions

6. “Identity First” cybersecurity strategy can address evolving threats

WhatsApp Biometric Security

“On the first Identity Management Day, I would like to recognize the Identity Defined Security Alliance and National Cyber Security Alliance for leading this awareness. As the market continues to shift toward leveraging Cloud Infrastructure, SaaS solutions, IOT explosion, etc., it introduces new challenges, and traditional cybersecurity approaches are not adequate to address these new threats. This provides a great platform to acknowledge the benefits organizations can realize by shifting toward an “Identity First” cybersecurity strategy to address the next generation of evolving threats.”

– Andy Walker, Identity and Access Management Leader, Cyber Protection and Identity, Optiv Inc.

7. Passwordless Is the Way Ahead

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

“We are tracking three key trends in identity management. The first is the adoption of passwordless authentication. By this we mean eliminating passwords as one of the authentication factors, enabling companies to stop ransomware attacks based on brute-forcing RDP and eradicate the entire class of credential-based attack TTPs used in account takeover attacks. Second, many organizations are looking to replace traditional multi-factor authentication (MFA), which often uses passwords or other ‘shared secrets,’ with solutions that implement only secure factors and reduce friction for end-users – for example, by not requiring employees or customers to pick up a second device or fish a one-time password out of their SMS or email. The last, and maybe most important trend, is the confluence of cybersecurity and identity management. One important manifestation is to evaluate the security posture of the endpoint device at the time of login and make a risk-based decision on whether to allow access to cloud apps and resources.”

Tom (TJ) Jermoluk, CEO/Co-Founder, Beyond Identity

8. Identity Management has been departing from traditional password-based outlook

User Verification Policy, zero trust approach

“Identity Management Day is a great occasion to remind companies of the importance to have thorough identity management practices, processes, and technologies, since the sad truth is that companies most frequently give a thought to it as a follow-up to an incident.

Judging from Group-IB’s experience, the need for identity management and security proves to be a challenge for companies, with many organizations failing at it. The goal of identity management is to ensure that only authenticated users are granted access to specific applications, systems, or IT environments. This means that every employee should be given access only to the services that they will need to perform their tasks and support the existing business processes. Such an approach is also known as the principle of least privilege.

In the past several years, identity management has been departing from the traditional password-based outlook, with additional factors being added to the authentication process. Companies like Google, for example, have been deploying hardware tokens based on FIDO2 to evade phishing. Another trend contributing to the greater credibility of the authentication process is the use of AI and machine learning to track user behavior with the aim of adding extra context to the identity verification process to detect abnormalities in the user behavior. The latter didn’t come unnoticed by Group-IB and was implemented in its Fraud Hunting Platform that utilizes machine-learning algorithms to create a unique digital fingerprint for identities and devices. This enables the system to distinguish between legitimate actions and malicious activity even if the criminals have physical access to a user’s device as the system correlates and matches user behavior with their devices. This technology was dubbed «Global ID» by Group-IB.”

– Shawn Tay, Senior Threat Intelligence Analyst, Group-IB

9. It Is Every Organization’s Responsibility to Better Equip Their Workforce

Fortinet VPN, VPN, VPN devices

“Cyberthreats, especially identity theft, have significantly increased since the pandemic began. With remote working becoming the norm and resulting in greater dependence on digital devices, tools, and platforms, cybercriminals are increasingly using unsecured network connections and unsafe apps and portals to steal financial data and personally identifiable information of unsuspecting users. Indian users are experiencing loss of personal data more than ever before. According to NortonLifeLock Cyber Safety Insights Report in 2019, 70% of respondents were worried about their identity being stolen, and that 39% of Indian respondents had experienced identity theft. The study had also revealed that 63% of respondents were unaware of the steps that had to be taken in the case of identity theft and more than three-quarters (79%) wished they had more information about what to do next.

Now, when it is clear that remote working is here to stay, it is every organization’s responsibility to better equip their workforce to deal with such threats. It is advisable to always use the company’s tech toolbox, as it likely includes firewall and antivirus protection and security features such as VPN and two-factor authentication. I recommend that individuals should keep their Virtual Private Network (VPN) turned on, as it provides a secure link between employees and businesses by encrypting data. A VPN helps keep information secure from cybercriminals and prying eyes. While working remotely, it is important to understand that online safety is a shared responsibility that begins at the individual level.

Against the backdrop of accelerated digital transformation and the evolving cybersecurity landscape, the occasion of Identity Management Day serves as an important reminder of the need for organizations and individuals to reassess and strengthen their security measures to ensure fewer or no data breaches.”

Ritesh Chopra, Director Sales and Field Marketing, India & SAARC Countries, NortonLifeLock

 

Why Businesses are Investing in Data Privacy

personal data collection, Personal data. Data Privacy

Stories about data leaks from social media sites surface with alarming regularity these days. And it’s not just social media. Stock exchanges, credit card companies, banks, payment processors, airline companies, and other businesses have also experienced data breaches — their customer data has illicitly fallen into the wrong hands, making it easily available for sale on the dark web. A 2019 survey by PCI Pal shows that 44% of Americans, 38% of Brits, 33% of Australians, and 37% of Canadians have been the victims of a data breach. Studies show that consumers across the globe take a serious view of data privacy and are quick to abandon a service provider and move to a competitor when they hear that their databases and infrastructure have been compromised. That can have a major impact on the topline of the affected company. Besides, their share price and reputation would be tarnished. According to the Ponemon Institute’s Cost of a Data Breach Report, the average cost of data breaches in 2020 was $3.86 million.

Data is a key asset of any business today. As we move towards Industry 4.0 and digital business, investing in data protection is crucial for businesses today. They need to assure their customers that their data is being collected, processed, and transferred securely.

However, businesses need to implement a data privacy principle that adheres to international privacy laws and data protection requirements. Therefore, most organizations that enforce strict privacy laws get a reduced number of data breaches.

What is data privacy?

Data Privacy,” also called “Information Privacy,” is the technical aspect of information security that deals with the ability of an organization to handle PII, or an individual’s right to determine what kind of data can be collected/stored on a computer system and can be shared with third parties.

Privacy is an individual’s fundamental right to have control over the collection, usage, and dissemination of PII.

Personally Identifiable Information (PII) – The Information that directly or indirectly identifies an individual. For instance: name, address, date, and place of birth, National Identity Number, biometrics (e.g., photo, fingerprint, iris, etc.).

What Is the Difference between Data Security and Data Privacy?

People and organizations sometimes confuse Data Privacy for Data Security. Both pertain to PII but are distinct concepts. Data Privacy is about the control (related to usage and governance) over PII, such as policies and procedures being established to ensure that PII is collected, stored, used, and shared appropriately.

Data Security is about ensuring that technical controls (related to confidentiality, integrity, and availability) are implemented to protect PII from malicious cyberattacks. In other words, Data Security is a technical aspect of PII, whereas Data Privacy is a legal aspect. 

Why is Data Security and Privacy important?

There are many reasons why data security and privacy are important for organizations. Some of them are:

  • It helps reduce the number of data breaches that an organization can suffer
  • It helps prevent loss of revenue
  • It helps protect customer’s privacy
  • For maintaining and improving brand value
  • It supports an organization’s code of ethics
  • It gives a competitive advantage over other business

For these reasons, businesses are investing more in data protection and career opportunities are opening up. Here are some of the type of jobs available in this field.

Top Data Protection Jobs

  1. Data Security Specialist

Job role: They help the organization provide data protection and security against cyberattacks and analyze data breaches and network failures.

Average salary: $76,000

  1. Data Controller

Job role: They help the organization to determine the purposes and ways to process personal data.

Average salary: $41,531

  1. Data Protection Officer

Job role: They provide technical assessment, analyzing personal data, risk assessment, and mitigating data breaches for organizations.

Average salary: $85,286

  1. Cybersecurity Analyst

Job role: They help protect, detect, prevent, and manage cyberthreats.

Average salary: $75,891

How can Data Protection training help you stand out?

This training qualifies you to:

  • Advise staff on their data protection responsibilities
  • Advise management on whether data protection impact assessments (DPIAs) are necessary
  • Monitor your organization’s data protection policies and procedures
  • Serve as a point of contact for individuals on privacy
  • Serve as a point of contact between the organization and its supervisory authority

What courses can I take for data protection training?

There are several training courses offered by EC-Council’s CodeRed that can help you leverage data protection compliance at all levels in your business operations:

  1. Build A Secure and Unbreakable Business Environment

The Ultimate Privacy by Design MasterCourse (GDPR, CCPA, etc.) helps protect private information that can have vital implications for everyday life. The best way businesses can go about this is by creating a privacy culture. Therefore, Privacy by Design, a decades-old application design, and development strategy, is now used as a foundational strategy for entire organizations.

Furthermore, the major goal of Privacy by Design is to develop best practices that ensure application developers build privacy into their products from the beginning to the end. In this course, you will learn about the correct privacy-by-design process to help your organization comply with many regulations. This means you will learn how to build things that people can trust.

Learn more about this course here.

  1. Successful Implementation of Data Protection in your Enterprise

Learn How to Succeed in a Data Protection Officer Role-(GDPR-DPO). The General Data Protection Regulation (GDPR) is a privacy protection law with far-reaching implications. Before an organization can be compliant with the GDPR, significant structural changes need to be made. Therefore, organizations need a data protection officer (DPO) to keep up with the GDPR.

In this course, you will understand the requirement and role of a DPO. You will also gain intensive knowledge on ways to implement GDPR and ways to ensure the organization follows the compliance requirement and technical assessment needed for data privacy.

Learn more about this course here.

  1. Design, Implement and Comply with Data Protection Laws

In this course, you will learn how to Build EU GDPR Data Protection Compliance from Scratch (CIPT). Learn about the basic understanding of GDPR foundations, the concepts of data privacy and GDPR compliance, and its documentation process that you can reuse and adopt for your organization. You will also be able to identify vulnerabilities and take measures for maintaining privacy.

The course also talks more about the role of a Data Privacy Officer and its importance. Furthermore, at the end of the course, you will be proficient in developing a basic knowledge of the GDPR and ways it can affect your organization.

Learn more about this course here. 

  1. Ensure GDPR-regulated Data Protection in the Face of an Incident

Data breaches in organizations are becoming a common occurrence, and there is a need to eliminate them to avoid losses. In this course, you will learn how to Build a Security Incident Response Plan for GDPR Data Protection. Learn about the similarities between security incident response and GDPR data privacy act. Furthermore, you will get an insight into the ways of applying different security processes, methodologies, and frameworks in your organization.

The major highlight of this course is that you will learn how malware works and will be able to draft incident response procedures.

Learn more about this course here.

  1. Learn from the Past to Ensure a Safer Tomorrow

The course, GDPR Privacy Data Protection Case Studies Explained, can be best described as a follow-up for the other GDPR courses. In this course, you will learn how to identify and implement real-world scenarios and get hands-on experience about ways to follow compliance, the challenges, and how to overcome them.

You will also learn how you can start a privacy program, who to ask, what to ask, and in what order. The course’s highlight is that you will learn how you can look for compliance issues and how to address them. Furthermore, you will also learn the role and importance of a data protection officer (DPO).

Learn more about this course here.

  1. Learn to comply with CCPA

The California Consumer Privacy Act (CCPA) is a data privacy law that took effect in the state of California on January 1, 2020. In this course, you will understand how to operationalize the CCPA and the amendments published to the law. Furthermore, you will learn how to draft a privacy policy under the California Consumer Privacy Act and the ways to transfer to third parties.

The California Consumer Privacy Act (CCPA) – the complete course also explains consumer rights and ways to access their data under the act.

Learn more about this course here.