#RSAC: The Invisible War of Internet Misinformation

#RSAC: The Invisible War of Internet Misinformation

RSA Conference keynoter Theresa Payton outlines how misinformation works and what organizations can do to help combat it.

Misinformation is everywhere on the internet today, but there are ways to spot it and limit its risk, according to Theresa Payton, CEO of Fortalice Solutions.

Payton detailed her firm’s research into internet misinformation campaigns in an afternoon keynote session at the 2021 RSA Conference on May 17. Payton has been writing about and tracking the activities of misinformation groups on the internet for several years and has identified a number of key patterns. While there are different objectives for different groups, at the core, internet misinformation campaigns are about encouraging distrust.

“Manipulators promote misinformation to encourage populations to doubt what they believe,” Payton said. “The end game is to make you doubt everything you believe, which leaves you open to believing anything.”

The Misinformation Multiplier

Payton commented that although political and social espionage is centuries old and well documented, technology gives it a new twist. She noted that in 2013 the World Economic Forum listed online misinformation as one of the top trends.

The reason why online misinformation is so widely used is because it works. Payton added that the business of misinformation is also very lucrative, generating lots of money for certain groups that are able to execute campaigns effectively.

“Research shows that a false story reaches people six times faster than just the actual news or the truth,” she said.

Public Health Misinformation

Among the many topics that are the target of misinformation on the internet today is public health related to the COVID-19 vaccine.

Payton said that one rough estimate shows that misinformation on public health alone generated billions of social media views in a year. The impact of one such misinformation campaign was revealed in a UK poll that Payton cited, reporting that 8% of UK residents believe that 5G technology actually spreads the coronavirus. In the United States, she said, 27% of Americans are hesitant to get the COVID-19 vaccine, much in part due to manipulation campaigns.

“These theories are just a small part of the global infodemic that is running largely unchecked on social media platforms,” Payton said. “It doesn’t have to be this way.”

The end game is to make you doubt everything you believe, which leaves you open to believing anything.Theresa Payton

How Misinformation Spreads

There are various ways that misinformation spreads on the internet, though there are a few key recurring patterns.

The first step is the creation of the news item, which is then posted on independent news sites.

Popular but innocuous hashtags are used, and a combination of real people, fake personas, and bots re-share the original post.

Payton referred to the sharing of the news as an information laundering process, which is repeated over and over until the misinformation takes hold.

What Users Can Do to Combat Misinformation

Among the different steps that users can take to combat misinformation is to be vigilant and look out for sensational headlines.

Payton said that the fact that a topic is not being reported on traditional news media outlets could be another red flag. Traditional media outlets typically have to properly source and attribute news before it is published.

There are also tools that organizations can use to help identify potential misinformation campaigns. Payton recounted how her firm was able to use a series of tools to help identify the perpetrators behind one particular COVID vaccine–related misinformation campaign. Among the tools her team uses is Botometer, which can be used to identify the likelihood that a given social media account is a real person or is a bot. Another tool that her team uses is the Facebook Crowdtangle tool that can help to identify and correlate social media activities, which can be further visualized with the NodeXL tool for social media visibility.

For companies, Payton suggests that they consider building a playbook around how to respond to potential manipulation campaigns.

“Think about having an incident response playbook where either your industry, your executives, or your actual company fall prey to some type of misinformation or disinformation campaign,” Payton said. “Go on offense now and create debunking and pre-emptive measures.”

Payton also recommends that the standard operating procedure at organizations of all sizes should include scanning for misinformation about the industry the company is in, the company itself, and its executives.

“The only fix is for all of us to be enraged by what the manipulators are doing,” Payton said. “It is time for this digital generation to rise up against those who are trying to hijack our minds and manipulate what we know to be true.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: RSA CEO Details the Challenges of Resilience in a World of Chaos

#RSAC: RSA CEO Details the Challenges of Resilience in a World of Chaos

The 2021 RSA Conference got underway on May 17, with RSA CEO Rohit Ghai explaining what resilience is all about and what that means for cybersecurity.

Resilience is the theme for the 2021 RSA Conference, which is being held as a virtual event as the ongoing global pandemic continues to restrict in person gatherings. Ghai opened the conference and his keynote with an acknowledgment that this year’s conference follows a year of trial and tribulations for everyone. The path and the way forward in his view was summed up in one word – resilience.

“Resilience isn’t just about getting up when you fall,” Ghai said. “To be good at it, we must fall less often, withstand the fall better, and rise up stronger every time.”

The Intersection of Chaos and Resilience

Ghai commented that the concept of chaos is a good way to describe the cybersecurity landscape. He noted that in cybersecurity, defenders are dealing with multiple, connected technology stacks across different cloud providers. On top of that, Ghai said that there is the added randomness of malicious actors trying to disrupt operations and instil fear.

“How can you secure chaos?” Ghai asked rhetorically. ” You can’t, you don’t –  you focus on resilience by embracing chaos.”

Embracing chaos in Ghai’s view is about expecting the unexpected, trusting no one and compartmentalizing failure zones. Going a step further, he suggested that cybersecurity reliability engineering teams should constantly assess and test their responses to different types of risks and attacks.

“If you don’t have visibility, then you don’t know what to defend,” Ghai said. “Once you do have visibility, use threat intelligence to understand your vertical’s likeliest antagonists, including their methods.”

Zero Trust and Resilience

The concept of zero trust is also critical to enabling resilience.

“Zero trust was always important, but in the post COVID work from anywhere, always on world, it is an imperative,” Ghai said.

By prioritizing based on risk and protecting what matters most, we will ensure that when we fall, we will withstand thatRohit Ghai

He added that zero trust is a mindset as well as an architecture. With zero trust organizations make use of microsegmentation to divide up a network, as well as  providing application layer threat prevention. Zero trust also involves the use of risk based, continuous multi-factor authentication as a critical component.

“Most important of all is to limit trust to what is absolutely required, and never elevate trust based on unreliable factors,” Ghai said. “By being prepared for chaos, we will fall less often.”

Taking a Risk Based Approach to Resilience

Resilience is also about understanding and managing risk.

“We have to protect the address that represent the greatest risks, not where we see the most holes,” Ghai said.

There are a number of different ways that organizations can take a risk based approach to resilience. Ghai pointed out that the NIST cybersecurity framework does an excellent job of proposing a risk based approach to cyber security. In his view, every organization needs to deploy an integrated risk management solution and implement methods to quantify all risk, including cyber risk.

“By prioritizing based on risk and protecting what matters most, we will ensure that when we fall, we will withstand that,” Ghai said.

Kintsugi: Rising up Stronger

Ghai also emphasized the need for the cybersecurity community to be inclusive and diverse, in order to help grow the overall community.

“We need to recruit better than the adversary,” Ghai said.

While the past year has been challenging, Ghai emphasized that there is need to remain vigilant and to build back up after failure. Building back after being broken, is what the Japanese art of Kintsugi, also known as golden repair, is all about as well. Ghai explained that in Kintsugi, gold lacquer is used to help fix and restore broken pottery and ceramics. For Ghai, Kintsugi is the perfect metaphor for what resilience should be.

“Kintsugi does more than restore –  it transforms, it doesn’t hide faults and breaks, it highlights them,” Ghai said. “The golden wound becomes a celebration of the hand that put things back together, a celebration of the purposefulness and learning from the process, a celebration of resilience.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC: Netflix Exec Explains Where Infosec Pros are Going Wrong

#RSAC: Netflix Exec Explains Where Infosec Pros are Going Wrong

Information security professionals need to be more open to adaptation and embrace emerging ideas to enhance overall cyber-resiliency, according to expert speakers during an opening keynote on day 1 of the virtual RSAC Conference 2021.

Jimmy Sanders, information security, Netflix DVD, and Angela Weinman, head of global governance, risk and compliance, VMware, set out three “hard truths” about the sector, and how these negative practices can be addressed. 

1. The Security Risk Picture is Out of Focus

This is a major issue, “because if you can’t accurately determine risk, it becomes difficult to rapidly recover from impacts,” explained Sanders. 

Weinman noted that the industry is not currently “managing the risk well enough,” and she cited a recent VMWare study with MIT, which showed that under half (46%) of top executives stated they were happy with how their resiliency risk plans were executed last year.

Weinman said this was as a result of security professionals being “too conservative when predicting risk impacts and necessary treatment,” emanating from their desire to be accurate. She added this was highlighted by the shift to remote working during COVID-19, where planning for critical staff to be working from home for a period of time was not enough – it needed to be for all employees.

The solution to this, according to both speakers, is to “zoom out” and look at a spectrum of impact, rather than a narrowly defined scenario. Sanders explained: “We must broaden our views and prioritize environments so we ensure that not all environments are protected and viewed the same.”

2. Legacy Security Practices Are Slowing Us Down

The two speakers highlighted that traditional, and often uneccessary practices are commonplace in the sector, which is holding back progress.  This is borne out of a lack of diverse voices in cybersecurity, according to Sanders. He argued that in order for fresh perspectives to be brought on security practices,  ideas need to “be voiced without the fear of ridicule and condemnation.”

He added that there are currently “many intelligent minority voices that do not get heard within the security community.” This requires being intentional about allowing different viewpoints to be heard, particularly from women and ethnic minorities.

Weinman pointed out that this leads back to the first hard truth surrounding the security risk picture, as “we can get a better risk management picture if we have more points of view.”

Another aspect to this issue is the growing use of automation in security processes, which have led to a tick box culture. “Is everything we’re doing adding to our security posture? If not, why are we doing it?” asked Weinman. Again, diversity of thought is critical in this respect, to provide a fresh perspective on outdated practices, and question why things are being done, linking back to cyber-hygiene and the goals of the business.

3. Security is Not a Solo Sport

Sanders emphasized that no matter how good a security professional may be, resiliency cannot be achieved without collaboration across the sector. He described the need for a “snowball effect,” where great ideas build upon each other. “We, the security community, need to ensure that the best security practices are accessible to everyone.”

This requires organizations putting aside rivalries to “share knowledge and effective techniques to achieve what a single company can’t,” in the view of Sanders.

Weinman noted that it is “a common misconception that because of what we do, we must work in individual secrecy.” She advised security professionals to join a study group, working alongside people from other vendors.

Sanders, who leads the emerging technology group for ISSA International, added: “the most rapid growth in mini security practices happens when they start sharing what went right, but also what went wrong.”

Wrapping up the session, Sanders commented: “The ultimate lesson that I want you to take home is that we need each other now more than ever in these exciting times.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Deputy US Marshal Allegedly Framed Ex as Cyber-stalker

Deputy US Marshal Allegedly Framed Ex as Cyber-stalker

A serving deputy US marshal from California has been accused of conspiring with his ex-wife to frame his former girlfriend as a potentially violent cyber-stalker. 

Brea resident Ian R. Diaz was indicted by a federal grand jury in the Central District of California on charges of conspiracy to commit cyber-stalking, cyber-stalking, and perjury.

The 43-year-old is accused of plotting with his un-indicted former wife while they were still married to pose as a woman with whom he was previously in a relationship. In court documents this woman is unnamed and referred to simply as “Jane Doe.”

It is alleged that Diaz impersonated Jane Doe to harass both himself and his former wife through frightening electronic communications. The messages appear to show Jane Doe threatening to arrange a series of sexual assaults to be perpetrated against Diaz’s former wife. 

In the messages, the sender writes that they will run personal advertisements on the website Craigslist to solicit a number of men. These men will then be tricked into sexually assaulting Diaz’s ex-wife by being told that they are carrying out “rape fantasies” with the woman’s consent.

Later messages made it appear as though one or more such sexual assaults and attempted sexual assaults against Diaz’s former wife had occurred. 

“Diaz and his then-wife then reported this conduct to local law enforcement, falsely claiming that Jane Doe posed a genuine and serious threat to Diaz and his then-wife, and thereby caused local law enforcement to arrest, charge, and ultimately detain Jane Doe in jail for nearly three months for conduct for which they framed her and in fact perpetrated themselves,” stated the Department of Justice.

As alleged in the indictment, Diaz and his former wife took steps to conceal their actions, including using falsely registered email accounts, masking their identities by using virtual private networks to access the internet anonymously, and communicating with each another using encrypted messaging services.

Diaz is charged with one count of conspiracy to commit cyber-stalking, one count of cyber-stalking, and one count of perjury for his false testimony in a deposition in connection with a federal civil lawsuit brought by Jane Doe. Each count carries a maximum penalty of five years in prison. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Miss Universe Speaks Out Against Cyber-bullying

Miss Universe Speaks Out Against Cyber-bullying

Delegates of the Miss Universe competition have drawn attention to the negative impact of cyber-bullying in a new video campaign. 

In the video, the delegates appear one by one to voice their experiences of being cyber-bullied. Insults thrown at the women include comments that they are too fat, too ugly, or too old to be competing for the Miss Universe title. 

Miss Universe Cambodia was told that she was “too small” to have a shot of winning the crown, while Miss Universe Barbados said: “I often heard feedback that I didn’t look quite Barbadian enough.”

Cyber-bullies criticized how the women dressed and how they wore their hair. One contestant was even bullied over her dyslexia. 

“Having received many hateful comments about my skin color, it’s hurtful and it just shows we have a lot of work to do,” said Miss Universe 2019, Zozibini Tunzi from South Africa.

“If you were in my shoes, would you be ok to receive those hateful comments and messages?”

Delegates urged people to use their love and empathy and to choose to put their energy into actions with positive impacts.

Miss Universe 2018, Catriona Gray, shared the anti-cyberbullying campaign on her Instagram, along with a post revealing that she too had been targeted. 

“So many use social media as a consequence-free way to attack, put down and degrade others,” wrote Gray. “It started during my Binibini journey and escalated during my Miss Universe journey. I receive hate comments even today.”

Gray urged those able to comment online to use their freedom in a positive way.

“It is never okay to degrade someone to harass them in the name of sharing your opinion,” wrote Gray. “WORDS HAVE POWER. To both put down and pull up. I hope we would choose the latter.” 

The current holder of the Miss Universe title is Andrea Meza from Chihuahua City, who represented her home country, Mexico, as Miss Universe Mexico in the 69th annual Miss Universe competition. 

Meza is a 26-year-old software engineer who works closely with the Municipal Institute for Women, which aims to end violence against women.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two-thirds of CISOs Unprepared for Cyber-attack

Two-thirds of CISOs Unprepared for Cyber-attack

Two-thirds of respondents to a global survey of CISOs have said that they do not feel their organization is prepared enough to cope with a targeted cyber-attack. 

This widespread lack of readiness was unearthed by California enterprise security company Proofpoint during the creation of its first-ever annual “2021 Voice of the CISO Report.” The report examines global third-party survey responses from more than 1,400 CISOs employed by mid- to large-size organizations.

During the first quarter of 2021, one hundred CISOs were interviewed in each market across 14 countries: Australia, Canada, France, Germany, Italy, Japan, Saudi Arabia, the Netherlands, Spain, Singapore, Sweden, UAE, the UK, and the US. 

Just under two-thirds of CISOs (64%) reported feeling at risk of suffering a material cyber-attack in the next 12 months. More than half (53%) said they are more concerned about the repercussions of such an attack in 2021 than they were in 2020.

Quizzed over what form of attacks they expect to have to counter, the CISOs gave varying answers. Just over a third of respondents (34%) anticipated tackling Business Email Compromise (BEC) attacks, 31% thought insider threats would create a problem, and 33% were wary of cloud account compromise affecting O365 or G suite accounts.

Supply chain attacks, which have been prominent in the news of late, were a concern for 29% of respondents. Ransomware was the seventh most anticipated attack, with 27% of CISOs girding their loins against this particular threat.

The CISOs lacked faith in their coworkers’ ability to keep their organization safe from cyber-threats. More than half of survey respondents believe employees understand what they should be doing to protect their organization from cyber-threats; however, 58% percent of CISOs still cited human error as their organization’s biggest cyber-vulnerability. 

CISOs considered intentionally leaking data and accidentally clicking malicious links or downloading compromised files as the most likely ways employees will expose their business to risk.

Cybercrime was predicted to become more profitable over the next two years by 63% of CISOs. Nearly the same proportion (60%) predicted that over the same period, this form of crime would become riskier for those committing it. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Government May Force MSPs to Follow Security Standards

UK Government May Force MSPs to Follow Security Standards

The UK government is considering forcing managed service providers (MSPs) to follow updated security standards.

The Department for Digital, Culture, Media and Sport (DCMS) is asking for views on these measures and more to boost the cyber-resilience of the UK’s critical supply chains.

The DCMS revealed it is considering making it a requirement for MSPs to meet the current Cyber Assessment Framework, which comprises 14 security principles. These include having policies to protect devices and prevent unauthorized access, keeping secure and accessible backups of data, and training staff and pursuing a positive cybersecurity culture.

The government also wants the views of MSPs and companies procuring digital services to help understand whether it needs to update existing guidance for supply chain risk management, including the assessment framework.

Currently, the National Cyber Security Centre offers a range of information and resources to help organizations on how to assess the security or risks of their suppliers, including specific supply chain security and supplier assurance guidance.

The announcement has been made as organizations are increasingly moving their operations online, meaning they are more reliant on digital supply chains and third-party IT service operators. Despite this trend, the DCMS highlighted research earlier this year showing that just 12% of organizations review the cybersecurity risks of their immediate suppliers, and only 5% address vulnerabilities in their wider supply chain.

Digital Infrastructure Minister Matt Warman commented: “There is a long history of outsourcing of critical services. We have seen attacks such as ‘CloudHopper’ where organizations were compromised through their MSP. It’s essential that organizations take steps to secure their mission critical supply chains—and remember they cannot outsource risk.

“Firms should follow free government advice on offer. They must take steps to protect themselves against vulnerabilities, and we need to ensure third-party kit and services are as secure as possible.

“We’re seeking views from firms that both procure and provide digital services, as a first step in considering whether we need updated guidance or strengthened rules.”

Supply chain security has come into sharper focus in recent months following the damaging SolarWinds attacks at the end of 2020.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cisco Snaps Up Kenna Security for Vulnerability Management

Cisco Snaps Up Kenna Security for Vulnerability Management

Cisco is set to acquire privately held Kenna Security in a deal designed to expand its SecureX platform with vulnerability management capabilities.

Santa Clara-based Kenna Security provides risk-based vulnerability management capabilities alongside vulnerability intelligence to help organizations rapidly identify, prioritize and remediate cyber-risks.

Cisco claimed the technology is increasingly important to organizations as work-from-anywhere policies expand the attack surface and increase security complexity.

“Hybrid work is here to stay, and the increasing complexity of cybersecurity is our customers’ biggest challenge. We must radically simplify security to stay ahead of the evolving threat landscape,” said Jeetu Patel, senior vice president and general manager, Cisco Security and Collaboration.

“Our goal is to unify all critical control points into a single platform. With the addition of Kenna Security, we will fundamentally strengthen our platform experience by giving customers the ability to prioritize vulnerabilities based on a robust risk methodology that is tuned to their unique needs.”

Specifically, with the support of Kenna Security technology, SecureX will be able to help customers discover and prioritize assets, accelerate decision-making with vulnerability intelligence, proactively orchestrate patch management and virtual patching, and easily generate compliance reports, Cisco said.

The tools should also help IT and security teams collaborate closer to reduce risk for their organization.

Karim Toubba, CEO of Kenna Security, said the two firms had a unique opportunity to change the way organizations manage risk at scale.

“As malicious actors continue to evolve their methods, we need to make it easier than ever for customers to predict, detect, prioritize and respond to the security threats that matter,” he added.

“The breadth and scale of Cisco coupled with Kenna Security’s mastery of machine-learning and data science will reshape how the entire industry addresses cyber risk.”

The deal is expected to close in Cisco’s fourth quarter of fiscal 2021.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybercrime Forum Bans Ransomware Activity

Cybercrime Forum Bans Ransomware Activity

A popular cybercrime forum claims to have banned all ransomware activity due to ideological differences and concerns over the amount of publicity that high-profile incidents are generating.

Russian language forum XSS has contributed to the success of Ransomware as a Service (RaaS) groups like Netfilim, REvil, DarkSide and Babuk, by providing a platform to recruit new affiliates, according to Flashpoint.

However, an administrator post late last week claimed that all sales of ransomware and affiliate activity would be prohibited from the site, the threat intelligence vendor reported.

The activity of groups like DarkSide, which recently caused a furore after disrupting fuel supplies on the US East Coast, are generating “too much PR,” escalating geopolitical and law enforcement risk and building a “critical mass of nonsense, hype, and noise,” according to the post.

The geopolitical aspect appears significant: the post apparently argues that when President Putin’s press secretary has to deny Kremlin involvement in attacks, “this is a bit too much.”

Russian cyber-criminals have always been sheltered by the state on the unwritten proviso that attacks are aimed at the country’s strategic foes, such as European and North American countries.

XSS’s decision would seem to suggest some in the community are becoming anxious at the level of scrutiny from the US and other governments that such attacks are drawing.

Flashpoint also claimed that DarkSide released a now-deleted statement claiming that its data leak blog, payment server and DOS servers have been blocked and funds from the payment servers were “withdrawn to an unknown address.”

However, according to a statement from Digital Shadows, forum members have questioned the authenticity of the post.

In the meantime, it’s unlikely that XSS’s decision will impact the ransomware industry.

“Flashpoint assesses with moderate confidence that well-established ransomware collectives — including REvil, LockBit, Avaddon, and Conti — will continue to operate in private mode,” the vendor said.

“Additionally, ransomware collectives will likely begin to advertise recruitment for new affiliates via their own leak sites since many cyber-criminal forums, like XSS, and other similar platforms used for ransomware advertisements will now likely refuse to host their activities.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Toshiba Business Reportedly Hit by DarkSide Ransomware

Toshiba Business Reportedly Hit by DarkSide Ransomware

A subsidiary of Japanese tech giant Toshiba has admitted suffering a cybersecurity breach reportedly caused by the DarkSide ransomware gang.

Toshiba Tec Corporation — which makes printing, scanning and other office equipment — revealed the incident in a statement on Friday.

Although the update did not confirm whether any customer data was taken in the incident, Toshiba admitted that “it is possible that some information and data may have been leaked by the criminal gang.”

The firm has contacted the relevant authorities in Europe, where the attackers struck, and is working with third-party cyber experts to find out exactly what happened.

“The group also took actions to stop the networks and systems operating between Japan and Europe, as well as those operating among European subsidiaries, with the aim of preventing the spread of damage while deploying recovery measures sequentially once effective data backup has been completed,” it added.

“In addition, the group is proceeding to identify the content and extent of the possible damage through conducting investigations by the outside specialized organization.”

Although not mentioned by name in the statement, the infamous DarkSide ransomware group linked to the recent Colonial Pipeline attack, was flagged by a representative from Toshiba’s French subsidiary, according to Reuters.

The newswire quoted a senior malware analyst from Mitsui Bussan Secure Directions who appears to be working on incident response, as saying: “There are around 30 groups within DarkSide that are attempting to hack companies all the time, and they succeeded this time with Toshiba.”

The report claimed over 740GB of data had been stolen, including passport scans and other personal information.

However, efforts to confirm the involvement of the group have been complicated by disruption to its operations. Reports suggest DarkSide’s TOR site has been closed down and servers seized, although it’s unclear whether this is a law enforcement operation or simply a tactic from the group itself designed to take the heat off after its widely publicized raid on the East Coast fuel pipeline.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk