Home Blog Page 98

Scraped Data from 500 Mn LinkedIn Profiles Sold at a 4-digit Price

BigBasket Allegedly Suffers Data Breach, Customer Data on Dark Web for Sale

It seems like no online platform is immune to cyberattacks. Small or big, almost every internet-based enterprise has a data breach history. A few days after Facebook’s massive data breach news, LinkedIn data exposure is now making headlines.

According to a report, cybersecurity researchers found a massive database belonging to LinkedIn users kept for sale on the dark web. The exposed database contained scraped data from over 500 million LinkedIn profiles that contained private information, including full names, employment information, contact details, email addresses, links to other social media profiles. Threat actors even leaked two million user records as a proof-of-concept.

Data Sold at  4-digit Price

Cybercriminals have allegedly advertised the sale of the database that hosted over 500 million user records at a 4-digit minimum price.

Image Courtesy: Cybernews

While threat actors claim that the leaked data was scraped from LinkedIn, researchers stated that it’s unclear whether the exposed data is from up-to-date LinkedIn profiles or taken from previous data breaches. “We asked LinkedIn if they could confirm that the leak was genuine and whether they have alerted their users and clients, but we have received no reply from the company at the time of writing this report,” researchers said.

The Data Leak Impact

Cybercriminals could misuse the compromised data against LinkedIn users in several ways like launching targeted phishing attacks, spamming the leaked emails and contact numbers, and performing brute-force attacks on LinkedIn profiles with the leaked email addresses. Though the exposed information does not include any sensitive data like credit card details or legal documents, adversaries can cause maximum damage with just email addresses and contact details.

“Particularly determined attackers can combine information found in the leaked files with other data breaches to create detailed profiles of their potential victims. With such information in hand, they can stage much more convincing phishing and social engineering attacks or even commit identity theft against the people whose information has been exposed on the hacker forum,” the researchers added.

 Strengthen Your Online Accounts

If you suspect your LinkedIn profile to have been compromised in the data leak, follow these security measures to boost the security of your online accounts:

  • Don’t respond to suspicious LinkedIn messages and connection requests.
  • Use a strong password/passphrase that’s hard to crack.
  • Change your LinkedIn and email accounts’ passwords regularly.
  • Enable two-factor authentication (2FA) on all your online accounts for additional security.
  • Never click/open unknown links on websites or in emails from external sources.
  • Install anti-phishing and anti-malware software to prevent cyberthreats.

Check if your email or phone has been compromised

The data breach search website Have I Been Pwned?, created by web security consultant Troy Hunt, allows users to check whether their personal information has been compromised in any data breaches. Once they enter the required details, the breach notification service indexes all the data breaches – the largest and the most recent – to check if users’ email IDs/phone numbers were exposed. Users can also sign up to be notified if their email address appears in future dumps.

CISO MAG’s April 2021 Issue Highlights Attack Vectors with COVID and Vaccine Themes

It would not be an exaggeration to say that COVID-19 vaccines are the most sought-after commodity today. Vaccine producers are working overtime to produce enough vaccine doses to fulfill government commitments and timelines. While pharmaceutical companies stepped up their production schedules to develop and test vaccines, adversaries tracked the news and devised campaigns to leverage the momentum generated by news coverage. They capitalize on the fear, uncertainty, and doubt (FUD) of people to spread misinformation and to plan attack vectors. Fake websites are purporting to offer (mis)information about vaccine distribution. There are attacks on vaccine supply chains and networks of pharma companies too.

Some of these attacks on pharma companies originate from mixed motivations. Some adversaries launch cyberattacks for financial gain – to steal and sell vaccine-related information or clinical trial data, while others are directed to disrupt vaccine production.

Cybersecurity MagazineThe Cover Story of the April 2021 issue of CISO MAG focuses on the types of attack vectors on pharma companies and consumers. Security experts from various organizations offer solid evidence and testimonials – with advice to contain these attacks.

In the Under the Spotlight section, we have interviewed Heath Renfrow, CISO of Conversant Group and former CISO of United States Army Healthcare, where he stressed how sabotage of vaccine either through propaganda or manipulation is his biggest concern.

In our Insight section, Samantha Humphries, Head of EMEA Marketing & Security Strategy, Exabeam, pens her thoughts on protecting the COVID-19 vaccine supply chain from phishing attacks. She recalls the cyber-espionage attempt focused on the international vaccine supply chain that was leveled as a precisely targeted phishing campaign against the companies involved in the “cold chain” used for preserving and controlling the strict storage temperatures of Pfizer’s COVID-19 vaccine in transit.

Moving ahead, the Buzz section of the issue details the cyberattack against the Indian Power Sector by the Chinese hacking group, RedEcho. The article also offers expert opinions from some of the industry leaders including Dick Wilkinson, CTO, New Mexico Judicial Information Division; Stan Mierzwa, M.S., CISSP, Director and Lecturer, Center for Cybersecurity, Kean University; and Tari Schreider, C|CISO, CRISC, ITILf, MCRP – Senior Analyst, Aite Group.

In our Table Talk Section, John Fokker, Head of Cyber Investigations and Principal Engineer, McAfee, discloses some of the unknown facts about the infamous Babuk Ransomware.

The Knowledge Hub section highlights the responsibilities of a CISO, post-COVID-19. It stresses several CISO powers like securing remote employees, averting social media threats, managing third-party risks, among several others.

Our Campus Corner section talks about EC-Council CodeRed and how the learning platform is tackling the cybersecurity skills gap through commitment, collaboration, and most importantly, change. CodeRed has been made available to students and faculty via EC-Council Academia. Students have access to the latest and most relevant cybersecurity courses developed by world-leading practitioners.

Lastly, in our Kickstarter section, we profile ByteChek, founded by AJ Yawn and Jeff Cook. ByteChek has introduced a cloud-based SaaS solution to automate IT audits and streamline cybersecurity reporting. This platform fits well for companies of all sizes. The ByteChek platform provides a stable security program, automates cybersecurity readiness assessments, and completes SOC 2 audits faster, and the best part – it does all of this from a single platform. Subscribe to CISO MAG


About CISO MAG

CISO MAG – a thought-leadership publication from EC-Council, provides vital stories, trends, interviews, and news from around the security world to help security leaders stay informed. The magazine includes comprehensive analysis, cutting-edge features, and contributions from thought leaders.

About EC-Council

EC-Council, officially incorporated as the International Council of E-Commerce Consultants, was formed to create information security training and certification programs to help the very community our connected economy would rely on to save them from a devastating Cyberattack. EC-Council rapidly gained the support of top researchers and subject matter experts around the world and launched its first Information Security Program, the Certified Ethical Hacker. With this ever-growing team of subject matter experts and InfoSec researchers, EC-Council continued to build various standards, certifications, and training programs in the electronic commerce and information security space, becoming the largest cybersecurity certification body in the world. Learn more at https://www.eccouncil.org.

Cybersecurity Post-COVID: A New Era of Sophistication

COVID-19, Corona, Coronavirus

2020 was an immensely challenging year for everyone, including the cybersecurity sector. An explosion in remote working endpoints and new technology investments brought about by the pandemic have created fresh security challenges and visibility gaps. The trend continues in 2021, with the SolarWinds attack demonstrating the level and sophistication of threats organizations are facing.

By Jamie Brummell, Founder & CTO, Socura

But what are the emerging types of threats and threat vectors, and what do CISOs need to do to put in place strong foundations to secure the new, hybrid ways of working? I will outline my top five tips on how to tackle threats in a new era of sophistication.

Prioritize endpoint security for home workers

At its core, cybersecurity is a people problem. Phishing has become a top threat vector for attackers precisely because it works so well. You can have the most advanced email security system in the world, but if a phishing message slips through the net, it takes just one untrained user to click through and your organization can be exposed to crippling ransomware or large-scale data theft.

The people factor has become even more critical because of the rise in remote working. There’s strong evidence to suggest that those at home are more likely to click through on something suspicious. The problem is amplified by the fact that many home workers may be connecting to company networks from personal devices which aren’t suitably protected.

One global study found that even though most (72%) remote workers say they are more conscious of their organization’s cybersecurity policies since the start of the pandemic, large numbers are using non-work apps on corporate devices (56%), or a work laptop for personal browsing (80%) and are often, or always, accessing corporate data from a personal device (39%).  All these scenarios represent varying degrees of security risk.

Gain full visibility of the ‘Internet of Things’

And it’s not just the remote laptops and tablets, there’s also the rise of IoT to consider as well. According to forecasts from leading analyst house Gartner, the world will be filled with as many as 25 billion connected “things” by the end of 2021. A big part of this surge is down to the Internet of Things (IoT): programmable gadgets, machines, sensors, and other bits of hardware that collect data and transmit it to cloud servers for analysis and processing.

There’s no denying the potential for such devices to deliver an increasingly connected future, but these devices also represent a major security risk. Why? Because they may be more difficult to patch or may not be protected with adequate access controls, whilst visibility gaps and a lack of network segmentation also increase the risks. Further, many IoT devices will only run old, unpatched (and often ‘unpatchable’) operating systems with lax security configuration and no security agents protecting them.

Gaining full visibility and control is critical, with IT leaders, in my experience, requiring a better understanding of where their assets are and how devices are being used to effectively manage cyber risk.

The good news for CISOs is that the security of consumer IoT devices is being bolstered by the introduction of new international standards, such as ETSI EN 303 645. The standard covers 13 areas designed to put in place a baseline level of security for connected devices. For example, it requires IoT manufacturers to provide transparency on the minimum time for which the product will receive security updates. It also provides guidance on best practice cryptography to ensure confidentiality of personal data transiting between a device and a service.

A key strategy to address endpoint security for managed devices includes the adoption of Endpoint Detection and Response (EDR) agents that record all activity, including network connections that are no longer seen by centralized network security systems when users are working remotely. With traditional antivirus vendors building EDR capability into their agents, endpoint security investigations have been simplified and their visibility has improved. The visibility into all endpoints is further enhanced with Extended Detection and Response (XDR), where activities across endpoint, network, identity, and cloud are stitched together for even deeper insight.

Tackle escalating ‘social engineering’ in critical services

One prominent target for compromise right now is the cold supply chains associated with vaccine rollout. A global phishing campaign uncovered by IBM involved sending out phishing emails to organizations associated with Gavi, The Vaccine Alliance’s Cold Chain Equipment Optimization Platform (CCEOP) program. This was a ‘spear’ phishing attack involving precision targeting where messages were developed to specifically appeal to certain individuals.

Along with precision targeting, spear-phishing campaigns are grounded in thorough research of information available online, such as social media profiles, to create a credible email with a strong call to action.

Phishing is a tried and tested tool in any cybercriminal’s toolbox but during the pandemic, we have seen the emotional appeal exploiting the fear surrounding COVID-19­­ evolving into precision ‘social engineering’.

Creating a positive security culture that raises awareness and provides the necessary training so that victims feel empowered to report an attack are all essential measures but don’t go far enough. CISOs need to limit threat surfaces by ensuring that employees only have access to data and systems that are fundamental to doing their job.

Establish transparent supply chains

Data breaches are a pressing concern not just in ‘physical’ supply chains of vaccine supplies but also in software supply chains spanning an organization’s third-party relationships.

Supply chain breaches are not new, but their severity and ramifications have certainly become more far-reaching, as recently demonstrated by SolarWinds.

The challenge can only be addressed through industry-wide collaboration. An interoperable metadata approach based on the Software Bill of Materials (SBOM) helps manage supply chain risk through increased transparency. SBOM is a record of various components used in building software that enables faster identification and remediation of vulnerabilities.

An important, recent initiative aimed at managing vulnerabilities in an open-source ecosystem has been introduced by Google. OSV is a database for open-source vulnerabilities that automates the triage workflow for an open-source package consumer, making it easier for users to identify which vulnerabilities impact them. Such initiatives are essential if the cybersecurity industry is to reduce the growing trend of key software supply chains being compromised.

Clearly define shared responsibilities in the cloud

With the rise in remote working further accelerating cloud adoption, cloud misconfiguration has become one of the biggest sources of cyber risk today—often providing an open goal for attackers. Threat actors are constantly scanning for exposed cloud systems to compromise, with frequent success, so the trend of cloud-related breaches is unlikely to abate in the future.

When used appropriately and configured correctly, the public cloud can be more secure than on-premises environments. But there are two key sources of risk. The first one is a shortage of skills that have already led to countless cloud data breaches and leaks through misconfiguration, exposing highly sensitive customer data and IP. The second important cause is an insufficient understanding of the Shared Responsibility Model, leading to a misconception of the demarcation between the security responsibilities of cloud providers and those of their customers.

Security teams must ensure they clearly define what the cloud provider is securing, and what they are responsible for. The ‘grey’ areas of the Shared Responsibility Model that normally require extra clarification include applications, operating systems, network controls, and identity and directory infrastructure.

What next for CISOs?

Addressing security challenges and visibility gaps in the post-COVID era is no mean feat. Aside from securing adequate resourcing and funding, CISOs need to put in place the tools and processes to tackle the growing levels of threat as well as their evolving sophistication.

Zero Trust, conceived by John Kindervag, has been co-opted by a multitude of security vendors, often focussing on only one part of the ‘never trust, always verify’ concept. However, the NSA has recently published official guidance on the Zero Trust Security Model, giving it the much-needed neutrality and endorsement it deserves.

By assuming that a breach is inevitable or has likely occurred, organizations are set to constantly limit access to only what is needed and monitor for suspicious activity. In a supply chain breach, for example, a Zero Trust model would adopt a deny-by-default security policy, for all users, systems, and applications. Real-time protective monitoring would detect suspicious activity and provide an alert on any unauthorized attempts to access an application.

Managed threat detection and response (MDR) services can be helpful here as they have accrued all the necessary expertise, experience, and threat context through visibility of multiple customer environments with a laser focus on security operations and incident response.

This focus also enables them to apply optimal automation alongside human analysis, adding human context and intelligence to decision making. The end result is a faster response to threats and a reduction in attacker dwell time and risk.

WRITE FOR CISO MAG

Do you want to write for CISO MAG? Please read our guidelines here.


About the Author

Jamie Brummell is Founder and CTO of Socura (www.socura.co.uk). He is a cybersecurity leader with over 20 years of experience working with multinational organizations, security vendors, and systems integrators. Responsibilities have included security design, engineering, consultancy, and strategy.

Jamie works with senior executives, architects, analysts, and engineers alike; helping them manage cyber risk and improve their cyber defense capability.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Shadow IT is Creating an Ever-growing Problem with Remote Teams

Cybersecurity is standard business practice for most large companies: Survey

Most organizations have a centralized IT department with the apps and software approved for certain activities. However, remote workers might choose to find other apps and software that lacks the perceived limitations of the centralized and approved IT resources. Anytime a remote worker uses an application or software that your IT department is unaware of, your organization is exposed to different security threats that cybercriminals can exploit.

By Matt Shealy, President, ChamberofCommerce.com

Shadow IT includes messaging applications and software, portable data storage devices, and online document sharing software among others. While shadow IT could help a remote worker navigate the perceived limitations of the officially accepted software in an organization, it also creates significant cybersecurity vulnerabilities that the organization might fail to detect.

Why Shadow IT is a Concern

Cloud computing is driving the increased use of applications and software to complete various functions in the organization. Employees can easily download the apps or software they need to do their work and use different devices to access these applications and software.

The shift to remote work in the COVID era and the ease of accessing third-party software and applications have contributed to the rise of shadow IT. Remote workers will look for options when they need to complete a task but do not know how to use the approved software or can find an approved alternative that completes the same job efficiently.

Since shadow, IT often goes undetected by IT teams, the threats and vulnerabilities remain unknown. The major threats of shadow IT include:

Security Gaps

Shadow IT introduces vulnerabilities to an organization. Since the IT department has not vetted shadow IT, this software and hardware have not undergone similar security procedures as the approved technology.

So when an employee downloads software without the knowledge of the IT team, it opens up a potential route for cybercriminals to access your enterprise’s network and data. Whereas these remote workers could be using harmless software, some of the applications could have permissions that allow sharing of sensitive data. Others have security vulnerabilities that expose your company’s endpoints to risks.

When your employees give shadow IT applications access to key assets, they can easily make the entire network vulnerable to attacks.

Security gaps can also arise when employees fail to update their applications and software when these updates are available. Even with approved software tools, it becomes hard for the IT department to track whether remote workers have updated their software to the latest version. Hackers and cybercriminals can use the vulnerabilities in older versions of the software to access sensitive company data.

Compliance and Regulations

Governments have created regulations and standards that organizations must comply with to protect consumers and other businesses. Enterprises have these standards in mind when creating an approved list of technologies that their employees should use.

Therefore, when an employee chooses to use shadow IT, they are putting the organization at risk of non-compliance, heavy fines, and potential incarceration. It also increases the risk of not detecting or reporting security threats or the extent of a security breach.

Configuration Management

A configuration management database enables your IT department to identify how systems work together. But when remote workers are using shadow IT, the software and hardware they use are not included in the database.

The lack of visibility that comes with shadow IT also means that the IT department is unable to deal with problems that might arise when using these applications as they lack the knowledge and documentation to deal with the problem.

Inefficient collaboration

When different employees are using different software to complete their work, collaboration becomes problematic. For example, when two teams need to work together and one uses Google Drive while the other uses DropBox, a lot of time will be wasted trying to share or collaborate on the project.

Mitigating the Risks of Shadow IT

As more workers are working remotely, the threat of shadow IT has increased. However, there are steps IT leaders can take to reduce the use of shadow IT and mitigate the threats arising from shadow IT. Some of these steps include:

Monitor Your Network

The first step CIOs should take in mitigating the risks of shadow IT is monitoring your network to find out where you are experiencing problems with shadow IT. You need to monitor unknown devices and applications and determine when they occur.

You can collect log data from the firewalls, SIEMS, MDM, and proxies, to help you identify the services used outside the purview of your IT department. You can also identify the people using shadow IT and the frequency with which they use these resources.

Identify the Unmet Need

Most employees seek out shadow IT applications due to gaps with the approved infrastructure. They want apps that support efficient work and are easy to use. Communicating with your remote teams to identify the applications they use outside your approved infrastructure.

Communicate with your employees and create a policy that allows them to inform the IT department of newer solutions that do the same job efficiently. This way, your IT department can review these apps and software for security and find alternatives or adopt those that are safe for your organization.

Set policies that allow easy communication and collaboration between the IT department and IT users to promote the understanding of the needs, experience, and feedback from end-users.

Set Remote and Work from Home Policies

Most employees do not use shadow IT out of malice. Instead, they are seeking easy-to-use and efficient solutions. You should engage your employees through training and education programs that help them use the approved software and understand the threats of shadow software. When your employees know the security threats and consequences of security breaches due to shadow IT, they are more likely to find appropriate solutions (often with the involvement of the IT department) to solve their technology needs.

Your policies should also include cybersecurity best practices such as:

  • The use of strong passwords
  • Changing passwords regularly
  • Using secure routers for internet access, especially when accessing corporate resources or using work devices. You should include recommendations for router and network security measures that your remote employees should implement.
  • Policies that ban the access of work-related data using non-work devices
  • Encryption of sensitive data

In addition to training your remote workers, train your network administrators and IT staff of the best practices when managing systems and users when employees are working remotely.

When setting policies around shadow IT, CIOs need to discover and classify the shadow IT resources in the organization. Once you have the list of shadow IT resources you can take the following steps:

  • Move shadow IT applications to the authorized list of applications that pose no threats to the organization
  • Replace the shadow IT solution with an existing IT function that solves the need that drove your workers to find these shadow options
  • Discontinue the use of risky shadow IT solutions

Restrict Access to Third-Party Applications

Your organization can avoid the risk of shadow IT by identifying risky applications and blocking them even before users can access them. This will make it impossible for your employees to download, purchase or use these tools on company devices.

You can take this step further by having authorized devices that can access your enterprise network. This way, employees cannot access corporate files or networks using unauthorized devices.

Be Proactive to Lower Your Risk

IT teams need to act now. IT leaders, CIOs, and CISOs need to lobby for the resources needed to plug these security gaps. CEOs, COOs, and CFOs need to allocate the funds to make security a priority. If you don’t have the right person on staff or need to supplement your work team for additional skillsets, to manage the move to remote work, there are staffing agencies that can help find IT professionals to help you through it on a temporary or full-time basis.

Final Thoughts

Shadow IT is a growing cybersecurity concern as more organizations work with remote workers. Shadow IT introduces threats to organizations without the IT department knowing about these threats. CIO and IT leaders should be aware of the threats that shadow IT poses and the steps and technologies they can employ to mitigate these risks.

SPECIAL FEATURES

About the Author

Matt Shealy is the President of ChamberofCommerce.com. Chamber specializes in helping small businesses grow their business on the web while facilitating the connectivity between local businesses and more than 7,000 Chambers of Commerce worldwide.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

ICS is Becoming a Hot Favorite of Threat Actors: Kaspersky Report

cybersecurity

ICS (Industrial Control System) or SCADA have faced large volumes of attacks from notorious threat actors in the recent past. Be it the China-linked group RedEcho targeting the Indian power sector or an unidentified cybercriminal attempting to poison Florida city’s water supply and treatment plant, the attacks have not just evolved but have become a “life-threatening” affair. Backing these citations, a report from Kaspersky now confirms that 33.4% of ICS computers worldwide were hit by a cyberattack in H2 2020.

Kaspersky Report

The report from Kaspersky titled, “The Industrial Control System Threat Landscape 2020,” is based on the data received from ICS computers that are running Kaspersky security products and hosted in networks of industrial infrastructures. Kaspersky researchers observed a downward trend in H2 2019 and H1 2020 when it came to cyberattacks targeting the ICS infrastructure.

cyberattacks on ICS
% of ICS Computers Attacked Globally. Image Credit: Kaspersky

As per statistics, the percentage of ICS computers targeted with a cyberattack in the second half of the year was 33.4%, which was 0.85% more than the number in H1 2020. In other key observations of the report, the ICS computers targeted on a global level with ransomware attacks dropped from 0.63% in H1 2020 to 0.49% in H2 2020. However, when it came to developed nations, these numbers saw a contrasting surge. The U.S. and Canada saw a +0.25% spike, whereas Australia with +0.23% and Western Europe with +0.13% were not lagging either. One of the most surprising names in this list though is Saudi Arabia. The country saw the maximum growth in the number of attacks with a +8.2% rise.

Related News:

RedEcho Attacked 10 Indian Power Sector Companies and 2 Seaports: Recorded Future

Apart from this, Kaspersky researchers termed the COVID-19 remote working scenario as one of the prime reasons why threat actors were majorly targeting the ICS infrastructure’s RDP setup. The majority of the attacks took place through this and we already mentioned one such example.

For a brief overview of the other findings from the report, refer the infographic below:

cyberattacks on ICS
Image Credit: Kaspersky

Related News:

Cybercriminals Attempt Poisoning Florida City’s Water Supply

Google Play Restricts QUERY_ALL_PACKAGES Permission

Fleeceware Applications

Threat actors often leverage fleeceware or fake apps to drop malware on consumers’ devices. Usually, cybercriminals use these kinds of apps to break into users’ devices and obtain access to sensitive financial data. Google promptly removes such fraudulent apps from the Play Store whenever security experts report.

In its latest update on Developer Program Policy, Google announced that it is going to prevent apps from viewing other apps that are installed on an Android device. The search engine giant stated that they wanted to make the installed apps on the device to be private from other apps to boost users’ data security.

Why did Google initiate this move?

Certain apps can transfer users’ app data to third-party developers without consent. Threat actors often misuse this option to find out users’ financial data, political interests, or dating profiles. With Google’s new initiative, there will be a limit for apps from knowing what is installed on users’ mobile devices. Hence, from May 5, 2021, consumers and developers will have to provide a reason to get access to apps info.

The new initiative also restricts the QUERY_ALL_PACKAGES permission that gives visibility to the installed apps on a device.

“If your app does not meet the requirements for acceptable use, you must remove it from your app’s manifest to comply with Play policy. If your app meets the policy requirements for acceptable use of the QUERY_ALL_PACKAGES permission, you will be required to declare this and any other high-risk permissions using the Declaration Form in Play Console,” Google said.

“Apps that fail to meet policy requirements or do not submit a Declaration Form may be removed from Google Play. If you change how your app uses these restricted permissions, you must revise your declaration with updated and accurate information. Deceptive and non-declared uses of these permissions may result in a suspension of your app and/or termination of your developer account,” Google explained.

Which apps can use QUERY_ALL_PACKAGES permission

Certain applications can make use of the QUERY_ALL_PACKAGES permission if their core user purpose requires broad visibility into installed apps on the device. Apps like file managers, browsers, and antivirus apps along with banking apps, digital wallets, and other finance-based apps will be allowed to access other apps’ data.

Cases that won’t be permitted to request the QUERY_ALL_PACKAGES permission include:

  • Where use of the permission is not directly related to the core purpose of the app. This includes Peer-to-Peer (P2P) sharing. P2P must be the core purpose of the app to qualify as a permitted use.
  • When the data is acquired for the purpose of sale.
  • When the required task can be done with a less broad app visibility method.

Booking.com Fined €475K for Delay in Reporting Data Breach

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

The Netherlands Data Protection Authority slammed Booking.com with a €475,000 fine (around $560,860) for a data breach that exposed sensitive information of over 4,109 customers. The Dutch data privacy watchdog claimed that Booking.com delayed reporting about the incident. Booking.com is a Dutch online travel agency for lodging reservations.

What Happened

According to a report from Autoriteit Persoonsgegevens (AP), threat actors illicitly broke into the Booking.com system and managed to extract the login credentials of employees belonging to 40 hotels in the United Arab Emirates. Hackers used phishing and social engineering techniques to trick the employees into revealing the login credentials. They allegedly accessed users’ sensitive information including names, addresses, telephone numbers, and hotel booking details. The threat actors also obtained the credit card details of over 300 victims.

“Booking.com customers ran the risk of being robbed here. Even if the criminals did not steal credit card details, but only someone’s name, contact details, and information about his or her hotel booking. The scammers used that data for phishing. By pretending to belong to the hotel by phone or email, they tried to take money from people. This can be very credible if such a scammer knows exactly when you have booked which room. And asks if you want to pay for those nights. The damage can then be considerable,” said AP Vice President Monique Verdier.

GDPR Violation

Booking.com noticed the security incident on its systems on January 13, 2019, informed the affected customers on February 4, 2019, and reported it to the authorities on February 7, 2019 — 22 days after the incident, putting customers’ personal information at risk.

As per Article 33 of the European General Data Protection Regulation (GDPR), organizations are mandated to report a security incident within 72 hours. Failing to obey this guideline would attract huge penalties. Ever since the GDPR was launched (on May 25, 2018), the data regulators in European Union (EU) have imposed sizable penalties on various organizations that misused customer information or failed to report any security incidents.

“This is a serious violation. A data breach can, unfortunately, happen anywhere, even if you have taken good precautions. But to prevent damage to your customers and the repetition of such a data breach, you have to report this in time. That speed is very important. In the first place for the victims of a leak. After such a report, the AP can, among other things, order a company to immediately warn affected customers. To prevent criminals from having weeks to continue trying to defraud customers, for example,” Verdier added.

Consequences of Data Breach

The breach of sensitive information could bring severe security risks to the users whose data was affected or compromised. Threat actors could misuse the compromised information for personal gains like selling it on the dark web, launching spear-phishing, or credential-stuffing attacks.

Organizations must ensure that their employees are aware of various social engineering and phishing attacks. Despite enhanced security measures, sometimes companies fall prey to evolving cyberthreats with grievous consequences. Reporting security incidents to the data privacy authorities will help organizations investigate the situation and avoid unnecessary fines.

Related Stories:

“Application Security is not a process”

Application security is a complex topic, which software developers and even security professionals are trying to understand today. There was a need for a book to simplify the topic and all the jargon.

With this in mind, bestselling author Ted Harrington wrote the book Hackable: How to Do Application Security Right.

In an interview with Brian Pereira, Editor-in-Chief, CISO MAG, Harrington talks about his book, the genesis of the topic, and who will benefit from the book. He delves into the challenges of building security into applications at the beginning of the software development cycle. The book also breaks many misconceptions about application security.

Harrington is also the Executive Partner at Independent Security Evaluators (ISE), the company of ethical hackers famous for hacking cars, medical devices, and password managers.

The 7 Steps of Ethical Hacking

To beat hackers at their own game, you need to think like them. They’re going to probe your software systems to find security vulnerabilities; you need to do this too.

But…how?

If you’re like most people, you struggle to understand how attackers think, how they operate, and how they break systems. Worst of all, you may struggle to know what to do about it.

Believe it or not, there’s a method to the madness, and I’m going to show you exactly what it is.

By Ted Harrington, Bestselling author and Executive Partner at Independent Security Evaluators

1. Step One: Hire an External Security Partner

(Royalty-free image: https://www.pexels.com/photo/woman-standing-while-carrying-laptop-1181354/, Credit: Pexels / Christina Morillo)

Your first step is to hire an external security partner to do the hacking. You might think “we can handle this in-house,” but your ethical hackers offer several unique benefits.

You want complete independence. An external expert provides an unbiased view; they’ll tell you exactly how it is, even if it isn’t what you want to hear. They didn’t build your code, so they have no attachment to it.

By hiring an external partner, you capitalize on subject matter expertise that you probably don’t have in-house. You get both the breadth and depth that come with a diverse team of experts, which most companies don’t staff in-house. And you get all of that when you need it, and don’t pay for it when you don’t. Most companies don’t need a full-time team of ethical hackers in-house, so this is a cost-efficient way to get expertise within the financial constraints of your business.

Beware, however, that not all partners are the same. Specializations and levels of skill vary widely, so make sure to vet potential security partners in order to hire the specialization and skills you need (if you struggle with this part, chapter 1 of Hackable explains in-depth how to do this).

2. Step Two: Analyze the Design

(Royalty-free image: https://www.pexels.com/photo/midnight-black-samsung-galaxy-s9-2048774/, Credit: Pexels / Stefan Coders)

To understand how to break the system, your partner needs to understand how it’s supposed to work. That’s why the next step is to analyze the design.

Your security partner should learn the fundamentals of the software: the features, how users navigate through it, how access is provisioned, and where users can input values. They need to understand why it exists, what business problems it solves, and what it protects.

They’ll also want to evaluate for design flaws, which are vulnerabilities inherent in the system’s design. Give your partner time to analyze these flaws before moving on.

Unfortunately, many security approaches overlook this step. For example, if your partner is just running an automated scanner and that’s all, it won’t matter how the system works or why it works that way. Yet, the most important vulnerabilities tend to be impacted heavily by those factors.

3. Step Three: Run Scans

(Royalty-free image: https://www.pexels.com/photo/person-looking-at-phone-and-at-macbook-pro-1181244/, Credit: Pexels / Christina Morillo)

Next, your security partner should run scans, which are an efficient and inexpensive way to gain information that helps in later assessment stages. Scans quickly reveal the obvious issues that would require enormous effort to do manually. Most attackers run scans first, so it’s a good idea for you to do this, too. You want to see what they’ll see.

Keep in mind that scanning is not a comprehensive effort to find your security vulnerabilities; it’s just one piece of the overall puzzle. However, many security approaches try to do exactly that. Reject that.

4. Step Four: Look for Known Vulnerabilities

(Royalty-free image: https://www.pexels.com/photo/two-women-looking-at-the-code-at-laptop-1181263/, Credit: Pexels / Christina Morillo)

Attackers want the best results for the effort they invest, so the logical place to start is by looking where most people make mistakes. They seek these out as a shortcut to their success. Many software systems suffer the same mistakes, and so attackers explore the likely assumption that yours did too.

To defend successfully, your testing must check for common issues, including things like Injection Attacks, Broken Authentication, and Broken Access Control. This is just a sampling of the ever-evolving types of issues your attackers know to look for. Your security partner should, too.

5. Caution: There’s a Capability Gap

secure and private compute summit, data, data science
(Royalty-free image: https://www.pexels.com/photo/code-coding-computer-data-574077/, Credit: Pexels / Lukas)

Unfortunately, most security testing calls it quits at this point. Many approaches don’t even hit all of the steps mentioned so far: they rely solely on scans and fail to analyze the design.

The testing discussed so far requires minimal to moderate skill and experience and can be performed with a heavy emphasis on automated tools. But what comes next—the stuff that really matters — requires high skill, deep experience, and a manual emphasis.

When you vet your partner — and then later agree on scope and methodology — make absolutely sure you’re going to be getting everything that comes next. If you won’t, choose a different partner.

Your security partner should go beyond the fundamentals previously discussed and into the advanced tactics we’re about to get into.

6. Step Five: Abuse The System’s Functionality

(Royalty-free image: https://www.pexels.com/photo/blue-and-red-light-from-computer-1933900/, Credit: Pexels / Rahul Pandit)

Now that you’ve made sure to cross the capability gap, the next thing your security partner does is abuse the system’s functionality. This uses an application’s own features in an attack.

An example might be abusing the way a system treats integers: if the system is expecting positive integers, but negative integers are used instead, what happens? Or alternatively, can one user manipulate the password reset functionality to reset passwords for other users, thereby taking over their account?

Attackers want to abuse your system’s functionality. That means you need to have your partner look for this too. By finding these vulnerabilities first, you can fix them and prevent abuse.

There’s no tool for this. You can’t automate it. You must do it manually.

7. Step Six: Chain Exploits

(Royalty-free image: https://www.pexels.com/photo/blue-and-yellow-phone-modules-1476321/, Credit: Pexels / Free Creative Stuff)

The next step is exploit chaining, which is combining two or more vulnerabilities in order to multiply impact. Like timing jumps on a trampoline with a friend to send each other rocketing to new heights, chaining exploits enables attackers to cause even more damage.

In isolation, a couple of vulnerabilities might not be bad. In combination, they might be catastrophic. Vulnerabilities must be considered in the context of each other, rather than in isolation. Attackers seek to chain exploits, and you should, too. There’s no tool for this. You can’t automate it. You must do it manually.

8. Step Seven: Seek the “Unknown Unknowns”

(Royalty-free image: https://unsplash.com/photos/iIJrUoeRoCQ, Credit: Unsplash / Philipp Katzenberger)

Lastly, your security partner will want to seek out “unknown unknowns,” which are flaws so unexpected you don’t even consider them.

This comes in numerous forms, including novel versions of common vulnerabilities and previously unknown attack methods. Dealing with unknown unknowns is the absolute pinnacle of security testing. It entails the most important issues you’ll face.

To find the unknown unknowns requires skilled manual investigation. It is the only way to solve this part of the security puzzle, so vet your security partners before any of this work begins and make sure they’re up to the challenge.

9. Put it All Together

If you have valuable digital assets that are worth protecting, then you want to make sure you fix your security vulnerabilities before your attackers exploit them. To do that, you need a skilled, external partner helping you by investigating your system with the same malicious viewpoint your attackers would have.

They need to go beyond the basics, and execute the advanced tactics. All of them.

If you get the right partner and have them do the right testing, you’ll know exactly how to deal with your concerns about getting hacked.

WRITE FOR CISO MAG

Do you want to write for CISO MAG? Please read our guidelines here.


This article was adapted from the book “Hackable” written by Ted Harrington.


About the Author

Ted Harrington is the #1 best-selling author of “Hackable: How to Do Application Security Right,” and is the Executive Partner at Independent Security Evaluators (ISE), the company of ethical hackers famous for hacking cars, medical devices, and password managers.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

DHS to Launch 60-day Cyber Sprints to Prevent Ransomware Attacks

DHS

The increasing ransomware attacks have become a severe issue for all nations globally. From the health care sector to information technology, ransomware attacks continue to loom over cyberspace. Threat actors target organizations by encrypting their critical networks and demanding high ransoms. They also threaten victims by exposing the compromised data online. Federal agencies stated that preventing ransomware attacks is the primary goal, after the FBI received nearly 800,000 cybercrime complaints in 2020, with reported losses of $4.2 billion.

The Department of Homeland Security (DHS) stated that it is fighting against ransomware operators targeting the country. In a recent RSA conference, Alejandro Mayorkas, the U.S. Secretary of Homeland Security, revealed the present threat landscape, cybersecurity challenges, and their plans to mitigate cyber risks.

Mayorkas outlined five areas to improve on, which include:

  • Detection
  • Information sharing
  • Modernizing federal cybersecurity
  • Federal procurement
  • Federal incident response

Ransomware – A National Security Threat

Mayorkas stated that ransomware attacks significantly increased with threat actors adopting new tactics to encrypt organizations’ critical data. Ransomware operators even leveraged the pandemic, impacting several vulnerable sectors including health care organizations, e-learning platforms, and remote workforce.

“Let me be clear: Ransomware now poses a national security threat. There are actors out there who maliciously use ransomware during an unprecedented and ongoing global pandemic, disrupting hospitals as hundreds of thousands die. This should shock everyone’s conscience. With respect to responding to ransomware attacks, we will strengthen our capabilities to disrupt those who launch them and the marketplaces that enable them,” Mayorkas said.

The U.S. government is planning to step up robust security programs to fight against ransomware operators. According to Mayorkas, the government will launch an awareness campaign to engage with partners like cyber insurance companies. Besides, the DHS is stepping up law enforcement action against cybercriminals and dark web markets, which are the center for all kinds of cyberthreats.

“The Department will step up our efforts to tackle ransomware on both ends of the equation. To preventing ransomware incidents, we will take action to minimize the risk of becoming a victim in the first place. We will launch an awareness campaign and engage with industry and key partners, like insurance companies. With respect to responding to ransomware attacks, we will strengthen our capabilities to disrupt those who launch them and the marketplaces that enable them,” Mayorkas added.

60-day Cyber Sprints

To tackle the rising cyberthreats and cybersecurity challenges, the government initiated new programs like 60-day cyber sprints, which focus on the most important and urgent priorities:

  • The first sprint will focus on the fight against ransomware, a particularly egregious type of malicious cyber activity that usually does not discriminate whom it targets.
  • The Department will step up our efforts to tackle ransomware on both ends of the equation.
  • The second sprint will focus on the cybersecurity workforce, as we cannot tackle ransomware and the broader cybersecurity challenges without talented and dedicated people who can help protect our schools, hospitals, critical infrastructure, and communities.
  • The workforce sprint will focus on several elements. Front and center is support for our current workforce, who have done a heroic job protecting the election and now responding to two major incidents.