Friday, November 29, 2024

Pitch Elastic in my Style

My Elevator pitch


Like Google is a great tool to search content on Internet - We build a similar search tool for Intranet. Using Elastic your employees can search for internal information. A classic example can be - name a customer from India who uses APM on google cloud.

To build a search tool - Elastic will scan, search and index a whole lot of internal information. This is stored in a vector data base. In fact - Elastic is the world's most downloaded Vector Database. The search tool is the most superior in the market with a focus on Speed, Scale and Relevance in search results

You can integrate Elastic in your application to build your own search feature.

The rich vector database can also be leveraged to use the Out of box feature of Observability.

O11Y tools generally build tools that gather data and the dashboards sit on top of it. In our case - we have collected all the required data in our Vector database for Search and O11Y is the OTB feature

On Similar lines - Elastic can be used for SIEM as well

Before I conclude - I am sure you have used ChatGPT - we can build a similar tool for your internal usage. The Vector Database can be integrated with any leading LLM. When a query is asked - the vector database can search the query and share the results with the LLM. The LLM will now be able to generate an informed result that is relevant. This feature is called RAG - Retrieval-Augmented Generation.

 


Friday, March 10, 2023

What is ZT - CDR?

Ever wondered why cyber security always has to follow cyber crime?

The pattern always is:

Malware is born -> Zero day attacks -> Malware is discovered -> Signatures are written -> Databases are updated -> Malware is contained.

This cycle repeats for every single malware and as we now know - we are still after the malware.

The basic signature based method has its own flaws and to date has never been able to stop the malware menace.

CDR is a rare cyber security solution that is not dependent on Signatures.


Why CDR?

The bad actors hide malware in files and attempt to infect networks. These are difficult to detect zero day attacks. Networks that use CDR in their threat vectors like Email or Cloud apps or internet traffic are benefited by having a Zero Trust CDR which is 100% fool proof. It works by scanning incoming files to copy only the content from the file, the copied content is written on to a new file. The clean file with the reconstructed content is delivered to the end-user.






CDR reduces the risk of data breaches and system infections. It also ensures that files can be safely shared within a network without compromising the security of the system.

While CDR is an effective security solution, it is not a silver bullet. It should be used in conjunction with other security measures, such as email security or proxy or CASB. By combining these different security measures, businesses can reduce the risk of cyber attacks and ensure the safety of their data.

In conclusion, Content Disarm and Reconstruction (CDR) is a powerful security technology that can help businesses defend against file-based attacks. By removing potentially malicious elements from files, CDR reduces the risk of data breaches and system infections. It is an effective tool in the fight against cybercrime and should be used in conjunction with other security measures to create a comprehensive security infrastructure.
Use-cases:
1. For outgoing traffic - can block Steganography attacks.
2. For Incoming traffic - email such as these will tempt some of our employees to open the attachment and compromise the whole network. CDR with email will block such attacks.


Tuesday, September 13, 2022

GO#WEBBFUSCATOR

GO#WEBBFUSCATOR

How does it work?

Hacker send an EMAIL with MS Attachment. The Attachment has a XML in it. Once the attachment is opened - the XML connects to XMLSchemeFormat[.]com and downloads a malicious Macro.

The Macro runs a VB script and downloads an image of the outer space – the famous image from the James Webb Telescope.


This image contains a hidden Base64 file, which when decrypted turns into a 1.7MB windows executable file. Once executed it makes DNS connections and using DNS data exfiltration techniques steals data.

This is sophisticated multi-stage attack that includes email, web, native endpoint tools, steganography and DNS exfil.

Signature based technologies / non of the AV vendors, were able to detect and stop this as of Aug 31st 2022. The very basis of signature based methods cannot stop something like this and this has been a bane to the cyber security industry.

What we need is a technology that does not rely on signatures.

CDR - Content Disarm and Reconstruction (CDR) is one technology that does not rely on Signatures. CDR just extracts the content and writes it on to a new file - leaving behind the hidden malware.

Only networks using CDR are protected against such sophisticated attacks. 

CDR cleans the files of macros and as you can see below – the before and after of the file properties of the image– most of their properties are same except for the file size.

 

 Further reading:

https://www.forcepoint.com/blog/x-labs/combatting-james-webb-telescope-image-malware-attack

https://securityaffairs.co/wordpress/135090/malware/gowebbfuscator-james-webb-space-telescope.html

https://www.securonix.com/blog/golang-attack-campaign-gowebbfuscator-leverages-office-macros-and-james-webb-images-to-infect-systems/

 

 

Saturday, May 23, 2020

To do or not to do….the Covid app.



Corona or Covid-19 as some like to call it – is in the news everywhere. It has practically become the central theme of the world now. With due respects to people and families who lost their loved ones – it would be safe to say that Covid-19 has also spun off many unexpected positives. Low levels of pollution,  Himalayas visible from far off places, free movement of wild animals etc. It also has spun off a technology challenge / opportunity.

‘How can we?’ or ‘can we at all?’ use technology to map the infected patients and alert the healthy ones?

There are several countries like Australia, Singapore, China and many more that have launched COVID apps for contact tracing. Aarogya Setu is one such app launched by Govt of India.

Not surprisingly there are naysayers and sceptics who are thrashing this initiative.  In this article – let us take a view into some of these and objectively look at it.

How do the contact tracing apps work?
Not very different than Google Maps. The first step is to get as many people as possible to use this app. Now, when a person (of course with the app) is moving around say in city – his movements are kept track of in the app. If the person happens to be Asymptomatic patient and figures it - 2 days later, then all the people he was in touch with for the past 2 days can be alerted. The app also helps to identify clusters or hot spots of infection, helping local authorities to initiate containment in that area.
Great logic and will work for sure. The Govt needs to make sure a large volume of people use the app for this to be successful.

Privacy concerns?
One of the biggest concerns is that there is no specific Data Protection Law in India under which this App could have been safeguarded or evaluated. Though there is a proposed bill - Personal Data Protection Bill 2019 – but that is yet to become a law. Work in progress.
The other big concern is what happens to the data being collected. I installed the app on my phone to figure that app takes information like name, gender, travel history, telephone number, basic health info and location. I will be concerned if this data is misused by tele-callers who inundate me with unsolicited sales calls. There is no financial data or major identity data– so I do not have to be bothered about losing my identity or bank balance.
On one hand most of the users would happily and voluntarily part with data on social media platforms and other apps. How else do you think Amazon and Facebook know what is (was) on my mind? Which product or service interests me. I can say with confidence that possibly Facebook, Amazon and Google know more about us than any company HR where we work or even our near and dear ones.

Track the tracker!
Various benchmarks are used to track the tracker– of course there is no standard way of doing it. Looking at the way MIT Technology review does it. It looks at 5 areas:
a)       Is the App voluntary?
To begin with the app was said to be Mandatory. Driver’s license is mandatory, and one can be punished for driving without one. This app was compulsory, but cops were not stopping you to check if you obeyed the Govt. The government, to their credit, is trying to allay the fears around data misuse and have made the use of Arogya Setu completely non-compulsory. The app now holds the record for world's fastest-growing mobile app with over 100 million downloads.

b)      Limitation on data use?
The govt has not clearly mentioned nor the data protection provisions elaborate on this. We just need to trust the govt here. People who are worried this could be used for surveillance should remember that if you use anything that is “SMART” – it is watching you – Smart phone, Smart TV or Smart home.

c)       Data Destruction?
Here the Govt has come clean. It has a data destruction policy and most of the data is stored in the phone itself for unaffected people.

d)      Data Collection?
This is a relative comparison. Compared to China and Turkey – India is collecting data that is absolutely required. Compared to some EU countries – India may be overstepping – like it asks questions like – do you have Diabetes or BP? Anyway, for most of the Indians Health info is not a very big secret.

e)      Transparent coding?
The app is developed by NIC. Not sure if they have adhered to any specific standards but if the app must be successful in the long run – it will become standardized and interoperate. I am hoping it will work well with Apple and Google’s initiatives.

Conclusion:
Comparing the potential upsides and the potential downsides – I would choose to have the app installed on my phone with a hope that all those around me too do it as well. Until the vaccine comes – until corona is overcome – let us do all that we can to stay safe.

Tuesday, October 1, 2019

Almost Hacked...

I always kept wondering why the bad guys (in Cyber security) succeed most of the times and I got my answer this morning.
It is that time of year when we have all file our IT returns and await our refunds or confirmations from the IT department. It is almost a month since I filed my returns and have been waiting for that SMS. This morning at 4:47am my phone beeped and the much awaited SMS popped. 


I was excited when I saw my name and ITFUND as source of the message.  I was wee bit disappointed on the amount as I was expecting a higher refund. Nevertheless I clicked on that link from my mobile. I noticed it got re-directed a couple of times and landed on this Income Tax Department page (look alike page).







By now, I knew this was a fraud but went ahead and choose a bank – obviously – these fellas have setup a trap to steal banking credentials – I did choose a random bank and gave some random credentials – the hackers now take me to a RBI website (look alike) and ask for all personal data. With this they will create a fake ID and swap my SIM to steal my OTP as well.

Tell me one thing – would you have clicked on that link and would have keyed in your password? - Put your answers in the comment section

I also clicked that link from my laptop and as expected our web security solution blocked that link.


Friday, June 22, 2018

Disgruntled employees can pose serious threat


Tesla, the American multinational corporation that specializes in electric vehicles, energy storage and solar panels. A disgruntled Tesla employee broke into the company’s manufacturing operating system and sent highly sensitive data to unknown third parties. This is a steadily growing trend that is being witnessed in various parts of the world. Unhappy employees / sacked employees and some cases even high performing ex-employees try to actively damage their ex-employer. Such employees should be ashamed of themselves.

What can Employers do?

well, there is help available now. Technology can help address this issue. We now have Behavior analysis solutions that can figure out the current mood of your employees - are they happy? sad? Angry? Frustrated? Pose a danger to organization? The solution is called User and Entity Behavior Analytics.




Saturday, May 26, 2018

Fancy Bear returns


The hackers responsible for Democratic National Convention (DNC) hack in 2016 are back in the news again. On May 23rd - Cisco announced a major breach of over 500,000 routers and network storage devices. FBI acted swiftly and seized the internet domain that was used in the attack, cutting off the communication between the hackers and the infected devices. For now, the hackers will not be able to exploit these half a million devices for their malicious intentions but the malware still resides in all these devices. The infected devices are spread over 50 countries and the most likely author of this Malware is Fancy Bear - the hackers behind the 2016 DNC hack.

Researchers found VPNFilter source code on these infected devices - the malware that was used by Russia to attack Ukraine including the massive power outage. VPNFilter is hard to detect, works in Stealth mode and is known to steal critical data from Infrastructure systems.

As an immediate next step - it is advised to reboot the devices, change the passwords, do not use default passwords and disable remote admin on all internet facing devices. Legacy security systems depend on static policies and rules for their providing security, In an ever changing threat landscape of current times - there is a need for RAP - Risk Adaptive Protection, which will understand the behavior of people and adversaries to dynamically change policies and rules to provide better security.



Thursday, May 3, 2018

Forcepoint helping its customers build a secured data environment

My interview with VAR India
By VARINDIA    2018-04-23


Calling for a shift in the way cyber security is approached, Ajay Dubey, National Manager - Partners & Alliances – Forcepoint tells VAINDIA of how as a security focused company, Forcepoint is trying to address the challenges that crop up while securing its customers and their critical data - 
 
How is your organization geared up with security strategies for the industry at large?
Cyber security as a domain is going through a constant churn to help organisations stay focused on protecting against breaches, protecting critical business data at all times and complying with regulations. This is the reason, over the years, cyber security budgets have increased multi-fold, making it a huge industry. But, despite all these investments, the cyber security attacks have only increased. 

This calls for a complete shift in the way cyber security is approached. If you look at threats and technologies, they continue to evolve, but one thing that has remained constant throughout is people. This is what Forcepoint is doing, it is rethinking security from a human-centric approach. The approach emphasizes understanding human behaviour and user interaction with critical data over networks of different trust levels to combat cyber-attacks. 

Can you highlight the solutions you are offering for addressing the growing challenge of cyber security?
At Forcepoint, we have unique cyber security solutions for protecting the data - 

•    Our CASB (Cloud Access Security Broker) is designed to secure data on the cloud. CASB solutions address cloud service risks, enforce security policies, and comply with regulations, even when cloud services are beyond their perimeter and out of their direct control. We acquired Cloud Access Security Broker (CASB) firm Skyfence that has helped increase visibility, control and security as users interact with data wherever it resides, including within cloud applications.

•    Forcepoint’s UEBA (User and Entity Behaviour Analytics) helps organizations to baseline behaviour of users and also entities like endpoint servers or applications and then see if there are any deviations from normal baseline. We acquired Red Owl, a leader UEBA (User and Entity Behaviour Analytics) technology to better understand and manage human risk.

•    Forcepoint’s Web and Email Security Solutions protect users against multistage advanced threats that often exploit user’s data, which penetrate the organisation’s IT defences. 

•    Forcepoint NGFW (Next Generation Fire Wall) caters not only to network needs but also security needs of all the networks of our customers. With NGFW 6.4, network security admins can more clearly see and understand the rhythm of their people as they use network resources. 

•    Our data protection is integrated with DLP (Data Loss Protection) solution and now we have augmented our DLP with insider threat and UEBA (User Entity Behaviour Analytics) solution that understands the context and intent of user behaviour and dynamically applies enforcement policies to activity representing the highest risk.

How are you seeing the security trend to continue in 2018? 
The biggest security trend in 2018 will be EU’s GDPR regulation which will have a considerable impact on nations that control or process data of EU citizens. With the regulation of GDPR coming into action in May 2018, the focus should now shift towards three areas like the adoption of the prescribed nature of controls in the regulation in specific areas, improvement of the existing privacy structure to work according to the requirements of the regulation and reassessing the opportunity of processing in the context of GDPR. 

The second massive trend that’s being observed is the adoption of cloud. Even highly regulated industries like banks have started to adopt cloud on a big scale but the problem with cloud is that it opens up everything and it does not restrict the access anymore.  

Additionally, the IT security solutions are unable to understand behaviour of malicious, accidental or compromised users in spite of the technology investments. Therefore, cyber security must move from a technology-centric view to one that understands human behaviour and intent and employ a security system that can effectively do the same.

With new wave of security intelligence and its intensification, what are your prospect marketing plans?
Forcepoint’s unique brand strategy of focusing on cyber behaviours instead of emphasizing just on technology to protect a perimeter that no longer exists has helped customers in building a data secured environment. This approach requires both intelligent systems and transparent collaboration between an organization’s stakeholders. 

Our brand’s theme of protecting organisations against accidental, compromised or malicious users to protect against data thefts reflect the shift in the current security paradigm, which is largely technology-oriented, to focus on people as they interact with critical business data and intellectual property. 

How are you going to leverage your market strategy to further boost your presence in the country?

Our approach is to help our customers increase their security effectiveness while lowering risks as they accelerate digital transformation of their business. We continue to engage with companies across the entire ecosystem including Banking and Finance, IT and ITeS, Manufacturing, Government, Pharmaceutical, Insurance and many more to help them understand the need to protect critical data and importance of providing their employees access to the right data whenever and wherever it’s needed. 

Friday, April 6, 2018

The World This Week - April 1, 2018


The World This Week.

Truth is sometimes stranger than fiction. But for the whistle blower - It would have been impossible to believe that a company like Facebook would have allowed itself to be used by such spurious app developers.

In a nutshell – A company called Cambridge Analytica paid nearly $1M to Cambridge psychologist Aleksandr Kogan to create an app called ‘thisisyourdigitallife’. The intent of the app was to collect Facebook user profile data and pages liked in the guise of an online personality quiz. The app was able to directly access 270,000 user’s data. Here is the real catch – using this data the app developers were able to access data of 50M users – which they then misused to allegedly influence Donald Trump Victory in 2016. They apparently also influenced several other democracies including India, Argentina, Kenya, Nigeria, The Czech Republic and others.

There have been several data breaches in the recent past – Equifax, Yahoo, Deloitte, NSA, Indian telco giant – Reliance Jio and few more but there is none as damaging as this Facebook fiasco. Facebook itself seems to be under fire with the “#DeleteFacebook” hashtag trending, Mark Zuckerberg has formally apologized but his troubles are far from over. Many governments will be under pressure – political parties will have to answer a lot of questions. You and me – public at large are the helpless victims – what more this borrowed phrase summarizes this point – “If you’re Not Paying for It; you’re the Product”.

Among other major whistle blower new grabbers were the leak of CBSE board exam papers in India and possible fraud / conflict of interest at board room level of India’s ICICI bank.

Yet another data leak - US based Orbitz – a subsidiary of Expedia – has suffered a leak 880,000 credit card numbers putting that many people in risk.

So here’s what we can start doing differently from tomorrow. Be alert and vigilant on what you share on social media, when creating online account – avoid using Facebook to login or authenticate yourself. Don’t believe everything that you see in the social Media – especially WhatsApp. Think before you forward.

Business are equally vulnerable if not more to data thefts. Among the few options that companies have – the prominent one is to safeguard and have controls over PPT – People, Process and Technology. Like they say – never try to make a Matchbox at home – it will not only cost more – it will be a far from a perfect product – Cyber security is similar – In-house is fine for certain areas but for most of the other areas outside help is always better. It will not only cost lesser dollars – it is sure shot to work.

Thursday, March 22, 2018

iNews - Around The World This Week


1)     Cyber security, AI top technologies for healthcare firms - Cyber security (77 per cent), Big Data analytics (72 per cent) and AI (59 per cent) are the three digital technologies most utilized by healthcare firms currently," Infosys said in its report titled "Digital Outlook for Healthcare and Life Sciences Industry. According to the report, nearly 76 per cent of the life sciences firms that were surveyed considered investing in cyber security over the next three years for protecting patient data.

2)     Powerful APT Malware “Slingshot” Performs Highly Sophisticated Cyber Attack to Compromise Router - Slingshot is one of the powerful cyber threat actor that mainly targeting individuals and organization and the major victims belong to Africa and the Middle East. Slingshot  attacked 100 of victims who is located in Kenya, Yemen, Afghanistan, Libya, Congo, Jordan, Turkey, Iraq, Sudan, Somalia and Tanzania

3)     Endpoint and Mobile Top Security Spending at 57% of Businesses - Businesses say data-at-rest security tools are most effective at preventing breaches, but spend most of their budgets securing endpoint and mobile devices. There is a disconnect between businesses' ideal security practices and their actual strategies. Some 77% of companies cite data-at-rest security tools as the most effective for preventing breaches but fall toward the bottom (40%) of security spending priorities, new data shows.

4)     Frost Bank Says Data Breach Exposed Check Images - According to the company, it discovered last week that a third-party lockbox software program had been compromised, resulting in unauthorized users being able to view and copy images of checks stored electronically in the image archive. Frost Bank systems weren’t impacted in the incident, Frost says. The information that was accessed as part of the incident could be used to forge checks, the company says.

5)     Walmart Jewelry Partner Exposes Millions in Latest Cloud Storage Misconfig - The Chicago, Illnois-based jewelry company, which operated under the name Limogés Jewelry, left names, addresses, ZIP codes, phone numbers, email addresses, IP addresses and passwords publicly available in an AWS S3 bucket – data that can be used to carry out targeted fraud or phishing attempts.

6)     Dragonfly Compromises Core Router to Attack Critical Infrastructure - Dragonfly, the threat actor that was recently called out by the United States as an arm of the Russian government, has been observed using a compromised core router as one of its primary tools in attacks against government agencies and critical infrastructure in Western Europe. “This is a discovery whose significance far outweighs its size, given that core router compromises are considerably harder to detect, analyze, patch, and remediate than compromises of PCs,” Cylance researchers said.

7)     Cybersecurity Incident Response Still Major Issue - Over 75% of respondents across the globe admitted that they do not have a formal cybersecurity incident response plan in place across their organization. However, nearly three-quarters (72%) of organizations report feeling more cyber-resilient today than last year and feel confident about their skilled personnel. This confidence may be misplaced, with the analysis revealing that 57% of respondents said the time to resolve an incident has increased, while 65% reported the severity of the attacks has increased.

8)     Chinese APT Takes Aim at Pharma - A Chinese advanced persistent threat (APT) actor has been spotted using the infamous PlugX malware to target pharmaceutical organizations in Vietnam, aimed at stealing drug formulas and business information. A remote access Traojan (RAT), allows attackers to perform various malicious operations on a system without the user’s permission or authorization, including copying and modifying files, logging keystrokes, stealing passwords and capturing screenshots of user activity.

9)     Twitter Users Bilked out of Big Money by Elon Musk Clones - Twitter users are collectively being conned out of tens of thousands of dollars per day via fraud schemes involving accounts impersonating celebrities, including Elon Musk and Vitalik Buterin, the man behind the Ethereum cryptocurrency. The scam tweets ask for a small sum to be sent to an account, promising victims that they will receive much larger amounts back in a classic chain-letter gambit. An analysis of the Ethereum blockchain showed that the tactic is working, with thousands of dollars being sent to the bad actors. The fake accounts have struck hundreds of times over the last two months, with the most successful taking away over $70,000 per day.

10)  Nearly 90% of Firms Will Use Biometrics by 2020 - The vast majority of organizations will use biometric authentication technology by 2020, but concerns over vendor transparency persist. 62% use it already in some form, while an additional 24% will do so in the next two years. However, although most believe it to be a more secure alternative to static passwords, PINs and personal security questions, just 10% claimed biometrics are secure enough to be used as the only form of authentication.

Monday, February 5, 2018

iNews - Around The World This Week

1)     3 Ways Hackers Steal Your Company's Mobile Data - The most effective data exfiltration prevention strategies are those that are as rigorous in vetting traffic entering the network as they are traffic leaving it. It's the unfortunate reality of the cybersecurity threat landscape today that malicious actors are advancing their tactics at a breakneck pace, finding new vulnerabilities in network defenses to execute attacks faster than IT teams can keep up.

2)     ANZ Bank suffers 10-hour internet banking outage - ANZ Bank suffered a major outage of its internet banking service with users reporting problems for much of Monday. The outage appears to have started just after 10am Sydney time and was not resolved until just before 8pm - resulting in 10 hours of downtime. Earlier, users took to social media to complain about the issues, which the bank said on its Twitter account were “intermittent” and the IT team was working to fix “as a matter of priority”.

3)     Cyberattacks on Israeli banks rose in last six months - Israel's banking regulator warned banks and their customers on Sunday to be more vigilant against cyber criminals following a rise in hacking attempts in recent months. "In the last half year, we have seen an increase in attempts at fraud via phishing, aimed at banking system customers with the intent to steal funds from their accounts," the central bank said, adding that the attacker initially tries to steal the customer's login and other personal details aimed at transferring funds between accounts.

4)     Cryptocurrency Mining Malware Infected Over Half-Million PCs Using NSA Exploit - 2017 was the year of high profile data breaches and ransomware attacks, but from the beginning of this year, we are noticing a faster-paced shift in the cyber threat landscape, as cryptocurrency-related malware is becoming a popular and profitable choice of cyber criminals. According to the Proofpoint researchers, cybercriminals are using at least 25 machines to scan the internet to find vulnerable Windows computers.

5)     Cyberattack Impersonates FBI Internet Crime Complaint Center - A new cyberattack scams people into providing personal data and downloading malicious files by impersonating the Internet Crime Complaint Center, a division of the FBI intended to give the public a reliable means of reporting suspected illegal activity online. Threat actors trick victims into sharing personal information with fake IC3 messages laced with malware.

6)     APIs Pose 'Mushrooming' Security Risk - As APIs grow in prominence, top security concerns include bots and authentication. The application economy has now become the API economy. And as the importance of application programming interfaces (APIs) grows within the enterprise, organizations must keep their security top-of-mind, lest they put the entire software stack at risk as APIs deployed without security measures expose organizations to yet another class of attack vectors.

7)     3 Simple Steps to Securing Your ICS Systems against Digital Threats - We live in a world where connectivity is key. It’s brought conveniences to our personal lives, and organizations are adopting it into the industrial world to boost productivity. Industrial control systems (ICS), which manage utilities like water, gas, and electricity, are one such example of this ongoing trend. Organizations are putting ICS systems online so that jobs once carried out manually can now be carried out remotely or with the help of automation. ICS systems are a key target for cybercriminals. Security should therefore be a priority; given the importance of ICS, one would assume these systems would be running the most secure technology available. This is not the case. Much of the equipment is at risk of aging out, that is, requiring replacement or upgrade with very little security.

8)     Infrastructure-Based Security Vulnerabilities Put Your Business in Peril - With dozens of breaches and millions left violated, 2017 has witnessed a historic amount of hacking. This year has been stained with numerous hacking incidents, including WannaCry, Petya and Cloudbleed. Of these many cases, the Equifax data breach can be crowned the most significant hack of the year, having exposed the personal data of nearly 148 million people.

9)     How to Utilize the Cloud to Mitigate Cybersecurity Risks to Security Hardware - Today, cybersecurity is on all our minds. Every other day, we get news of another cyberattack. As more organizations struggle to keep up with the onslaught of these new threats, many are asking: “What can we do to strengthen our cybersecurity posture?” When we want to quantify it, consider the concept of risk. In its simplest form, the risk associated with a system is the impact of it malfunctioning, multiplied by the likelihood that a malfunction will occur.

Can We Be Smarter Than The Smart Cities We’re Building? - Imagine a world where everything is connected. All information and communication technologies are integrated into a single, consolidated platform. With the rapid increase in smart city capabilities, this idea may soon become our reality. The smart cities vision is to seamlessly integrate information and communication technologies with the internet of things (IoT) to increase efficiency, reduce costs, and enhance communications between networks. The end goal is to enable cities to leverage their IoT devices to create a more cohesive and connected environment. As more locations embark on adopting the smart city vision, reliance on data accuracy and speed of transmission will continue to grow, allowing all infrastructures to be connected through a single network.

Monday, January 22, 2018

iNews - Around The World This Week

1)     Understanding Supply Chain Cyber Attacks - Today's cybersecurity landscape has changed dramatically due to digitalization and interconnectivity. While the benefits of each push businesses toward adoption, security risks associated with interconnectivity between networks and systems raise major concerns. Everything-as-a-service removes traditional security borders and opens the door to new cyber-attacks that organizations might not be prepared to recognize or even deal with.

2)     Schneider Electric: TRITON/TRISIS Attack Used 0-Day Flaw in its Safety Controller System, and a RAT - Industrial control systems giant Schneider Electric discovered a zero-day privilege-escalation vulnerability in its Triconex Tricon safety-controller firmware which helped allow sophisticated hackers to wrest control of the emergency shutdown system in a targeted attack on one of its customers. Once the malware was inside the controller, it injected the RAT into memory by exploiting a zero-day vulnerability in the firmware, and escalating its privileges.

3)     Ransomware: Why the crooks are ditching bitcoin and where they are going next - The popularity of bitcoin is creating problems for criminals dealing in ransomware -- and some are already casting their gaze towards a less volatile cryptocurrency. While bitcoin has suddenly found itself in the public eye thanks to its rocketing -- and, more recently, plummeting -- value, it hasn't appeared from nowhere. We'll see a progressive shift in 2018 towards criminal use of cryptocurrencies other than bitcoin, making it generally more challenging for law enforcement to counter.

4)     Where to Find Security Holes in Serverless Architecture - Application security is getting a twist with the rise of serverless architectures, which introduce a new way of developing and managing applications - and a new wave of related security risks. Businesses are looking to serverless architectures to drive simplicity and reduce cost. Applications built on these platforms scale as cloud workloads grow, so developers can focus on product functionality without worrying about the operating system, application server, or software runtime environment.

5)     49% Indian companies not likely to secure sensitive data in cloud - While an overwhelming majority of global firms have adopted cloud services, there is still a wide gap in the level of security precautions applied by them, a survey has revealed. Almost half of Indian organizations say they are not likely to secure sensitive data in the cloud. Globally, organizations said only two-fifths of the data stored in the cloud is secured with encryption and key management solutions.

6)     Man pleads guilty to launching DDoS attacks against former employers - A man from New Mexico has admitted to launching distributed denial-of-service (DDoS) attacks against former employers, as well as possessing a firearm illegally. On Wednesday, the US Department of Justice (DoJ) said John Kelsey Gammell has pleaded guilty in a St. Paul, Minnesota court to directing DDoS attacks against former employers, business competitors, companies that refused to hire him and websites for law enforcement and courts, among others. Gammell not only set up the DDoS attacks, which launch traffic in such volumes that online services are disrupted, on his own computers but also paid DDoS-for-hire services to hammer victims further.

7)     Oman's stock exchange was easily hackable for months - The security flaw made the securities market an easy target and was only fixed after a security researcher sent more than half-a-dozen warning emails. A core router for Oman's stock exchange, the Muscat Securities Market, had both its username and password as "admin" for months, even after several attempts by a security researcher to warn the exchange of the security implications.

8)     Uber ignores security bug that makes its two-factor authentication useless - Uber has ignored a security bug that can allow an attacker to hack into user accounts by bypassing two-factor authentication because the ride sharing company says the flaw "isn't a particularly severe" issue. Two-factor authentication (2FA) is a vital part of protecting online accounts. It adds a second layer of security on top of your username and password -- which can be stolen -- by sending a code by text message to your phone, for example, which only you would have access to.

9)     Behavioral biometrics missing from cybersecurity - Recently, there’s been an uptick in the adoption of the NIST Cybersecurity Framework, a set of guidelines aimed at helping organizations improve their overall cybersecurity process. In December 2017, NIST released the second draft of its framework. Among the updates were two critical additions to the Identity Management, Authentication and Access Control guidance. Rather than being shocked by each new data breach, ransomware attack or instance of fraud, companies are increasingly working to improve their cybersecurity posture, and not just internal information security professionals.

Up to 40K Affected in Credit Card Breach at OnePlus - Chinese smartphone manufacturer OnePlus has reported a credit card breach affecting up to 40,000 users at oneplus.net. Users who entered their credit card data on the website between mid-November 2017 and January 11, 2018 could be at risk. The malicious script has been eliminated, the infected server quarantined, and all relevant system structures reinforced. Users who paid using a saved credit card, the "Credit Card via PayPal" option, or PayPal should not be affected, OnePlus reports.


Wednesday, January 17, 2018

iNews - Around The World This Week

1)     Hospital pays $55,000 in bitcoin to hackers after 'SamSam' ransomware locks systems - A US hospital has reportedly paid hackers $55,000 (£39,900) to restore control over its computer systems after they were infected with a strain of ransomware known as 'SamSam'. Last Thursday (11 January), staff at Hancock Regional Hospital, Indiana, found their computers had been infected with malware, which was demanding bitcoin to regain access. As reported, the hack impacted emails and health records, but no patient data is believed stolen.

2)     Privacy: The Dark Side of the Internet of Things - Before letting an IoT device into your business or home, consider what data is being collected and where it is going. There's a lot of buzz about the Internet of Things (IoT), but people aren't quite sure what to think of it. Back in fall 2016, there was a big attack on an Internet service provider in which a bunch of IoT devices became a botnet and made much of the Internet unavailable. It was a big moment that made people question the security of IoT. And although security risks are getting the headlines right now, and should certainly be considered, the bigger risk with IoT is privacy.

3)     Hackers hijack Twitter account of India's top diplomat to post photos of Pakistan's flag - The verified Twitter account of India's top diplomat to the United Nations was briefly taken over by suspected Turkish hackers early on Sunday, 14 January, morning. The Turkish hacking group Ayyıldız Tim claimed responsibility for the attack and managed to take over the president of the World Economic Forum's account over the weekend as well.

4)     IT Security Spending to Reach $96 Billion in 2018 - Worldwide IT security spending is expected to climb 8% next year to $96.3 billion, fueled by investments in identity access management and security services – two areas on tap to rise faster than the overall spending growth rate, according to a Gartner report released this week. Identity access management and security services to drive worldwide spending growth.

5)     The state of Israel’s cybersecurity market - The Equifax breach, WannaCry, NotPetya, the NSA leak, and many more cyber incidents – 2017 was certainly a busy year for hackers, illustrating yet again just how vital innovative cybersecurity solutions are in the fight against cyber threats. Second only to the U.S., in terms of cybersecurity investment 2017 was another excellent year for Israeli cybersecurity startups, with dozens of companies being formed, breaking fundraising records and producing solid exits. The 2017 data also suggest that the Israeli cybersecurity industry is maturing, as we see a shift in funding towards later stage companies.

6)     Top think tank warns cyberattacks could lead to 'inadvertent nuclear launches' - A new report from the Chatham House think tank has warned that cybersecurity vulnerabilities could lead to accidental nuclear war if countries carrying the hugely destructive warheads do not introduce new measures. While cybersecurity is a prevalent issue many sectors of society now have to consider, nuclear weapons systems were developed during a technological era when " little consideration was given to potential malicious cyber vulnerabilities", the report states.

7)     What is FakeBank? New banking malware can intercept SMS messages to steal sensitive data and funds – Security researchers have discovered a mobile malware strain that can intercept users' sensitive SMS messages to steal their banking details and funds, phone numbers, balance on a linked bank card and location data. According to Trend Micro researchers, the malware dubbed "FakeBank" has been spotted in several SMS/MMS management software apps and primarily targets victims in Russia and other Russian-speaking countries.

8)     Watch out for this Netflix phishing scam that will steal your credit card details - Netflix users are being warned to avoid clicking on any suspicious email links after a phishing scam was uncovered, which security experts say is designed to steal credit card details. Found by Australian cybersecurity firm MailGuard, and shared on Twitter by the New South Wales police, the fake emails use convincing social engineering tactics – including the official Netflix website layout – in an attempt to dupe recipients into entering financial details.


9)     Hyper-Converged Infrastructure To Accelerate IT Transformation - Technology is fast becoming the key pillar for organizations to stay competitive, spur innovations, and seize new growth opportunities. Despite increasing IT budgets, the traditional three-tier architecture, is proving to be a hindrance to meeting the rising business and market demands due to its inbuilt complexities. Apart from that, the stress to reduce operational costs and improve productivity is also forcing technology teams to explore alternative means to bring down complexity and costs through the adoption of agile architectures.

Blockchain Technology Goes Beyond Cryptocurrency - Cryptocurrency, the digital currency system that enables global monetary transactions between two parties without the need for a trusted third party financial institution, has gained tremendous momentum over the last few years. Bitcoin, the first cryptocurrency, came into existence in January 2009. Its inventor, Satoshi Nakamoto (an anonymous person or a group) published a whitepaper prior to this in October, 2008. Since then, numerous cryptocurrencies have come into existence. More recently, bitcoin has gained mainstream attention. Under the hood, the technological innovation is the blockchain that is seen as revolutionary foundational technology having a tremendous potential across different verticals.