Misconfigs and Unpatched Bugs Top Cloud Native Security Incidents

Misconfigs and Unpatched Bugs Top Cloud Native Security Incidents

Over half of organizations have suffered a security incident due to misconfiguration or a known vulnerability in their cloud native applications, according to new research from Snyk.

The open source security firm’s first ever State of Cloud Native Application Security Report revealed that adoption of cloud native techniques is soaring, with over 78% of production workloads now deployed as containers or serverless applications.

However, this comes with its own risks: 60% of developers have had increased security concerns since going cloud native, the report claimed.

Misconfiguration (45%) and known unpatched bugs (38%) were the most commonly experienced security incidents, with misconfiguration (58%) and insecure APIs (52%) topping the list of respondents’ concerns.

“Cloud native platforms utilizing automated tooling rely on credentials such as secrets and API tokens in order to operate, necessitating a more decentralized approach to managing such access,” the report noted. “The need for effective management of these kinds of artifacts is a key differentiator from the more centralized pre-cloud era, and a major area of concern for operations teams transforming their infrastructure.”

On the plus side, Snyk also revealed that developers are becoming increasingly invested in matters of cybersecurity.

Although less than 10% of respondents in security roles said they thought developers were responsible for the security of their cloud native environment and applications, over 36% of developers claimed that they were.

Automation is the key to improving security during the development lifecycle, the report also found.

With fully automated pipelines in place, regular security testing appears to become easier. Respondents with high levels of deployment automation were more than twice as likely to have adopted security testing at all points throughout the software development lifecycle as those with no automation.

Plus, nearly 70% of these respondents with high levels of deployment automation were able to test their security daily or more frequently. That’s 17 times more than respondents who had no deployment automation, according to Snyk.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Phishing Campaign Drops New Malware Trio

Global Phishing Campaign Drops New Malware Trio

Security researchers have uncovered a sophisticated global phishing campaign featuring three new malware families, which landed back in December last year.

Mandiant observed two waves of the campaign, beginning December 2, targeting nearly 50 organizations around the world. It tracked the financially motivated threat group as UNC2529.

“Based on the considerable infrastructure employed, tailored phishing lures and the professionally coded sophistication of the malware, this threat actor appears experienced and well resourced,” the security vendor noted.

The group appears to have taken time to craft its emails so they appeared legitimate to individual recipients, and used scores of domains to support its efforts.

The three new malware strains identified by Mandiant have been named “Doubledrag,” “Doubledrop” and “Doubleback.” UNC2529 apparently deployed heavy obfuscation and fileless malware techniques to keep them hidden.

Doubledrag is a heavily obfuscated JavaScript downloader. Doubledrop is a second-stage memory-only dropper containing a heavily obfuscated PowerShell script that launches a backdoor into memory. This backdoor is Doubleback.

The campaign itself targeted mainly US organizations — accounting for 74% of victims in the first phase and 68% in the second — but a number of targets in EMEA and APAC were also on the hit list.

Unfortunately, Doubleback was judged by Mandiant to be a “work in progress” and one likely to be used again in future campaigns by UNC2529.

“Almost 50 domains supported various phases of the effort, targets were researched, and a legitimate third-party domain was compromised,” the security firm concluded.

“The threat actor made extensive use of obfuscation and fileless malware to complicate detection to deliver a well-coded and extensible backdoor. UNC2529 is assessed as capable, professional and well-resourced. The identified wide-ranging targets, across geography and industry suggests a financial crime motive.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Shoppers Choose Guest Checkouts Over Security Fears

Shoppers Choose Guest Checkouts Over Security Fears

A quarter (22%) of shoppers use guest checkouts because they’re concerned about handing more personal data over to e-commerce providers, according to a new study.

E-commerce search specialist Empathy.co commissioned Censuswide to poll a representative sample of 4000 British consumers to better understand their online preferences.

It revealed widespread mistrust of online stores and a desire to gain more control over personal data.

Only 13% said they’re not concerned about how their data is used at all, while over two-fifths (42%) claimed that they’re extra careful when providing personal data and accepting legal notices.

A further two-fifths (40%) agreed that they don’t like being asked for unnecessary or sensitive data.

They’re right to be concerned. Although there are strict GDPR rules around what organizations can do with data subjects’ information and how they must protect it, online retailers remain a popular target for fraudsters.

A common tactic is account takeover (ATO), where scammers use credential stuffing or other efforts to crack open customers’ online accounts and raid them of personal data stored within or try to make purchases with stored cards.

A survey from April by fraud prevention specialist Ravelin revealed that 45% of global retailers have seen a spike in ATO of late. In October 2020, Akamai claimed  60% of credential stuffing attacks detected over the previous two years were targeted at retail, hospitality and travel businesses, with most of these (90%+) affecting retailers.

Empathy’s research also revealed 28% of consumers would like to take back information from brands they don’t like or trust, while 37% want more control of the data businesses have on them.

These sentiments may be a sign that consumers still aren’t aware of their rights under the GDPR, which has provisions for data subjects to have their information deleted under the “right to erasure” principle.

There are also parts of the law that make it easier for consumers to object to how their data is being processed and/or whether or not their consent for processing was informed and freely given.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Spectre-Like Attacks

There’s new research that demonstrates security vulnerabilities in all of the AMD and Intel chips with micro-op caches, including the ones that were specifically engineered to be resistant to the Spectre/Meltdown attacks of three years ago.

Details:

The new line of attacks exploits the micro-op cache: an on-chip structure that speeds up computing by storing simple commands and allowing the processor to fetch them quickly and early in the speculative execution process, as the team explains in a writeup from the University of Virginia. Even though the processor quickly realizes its mistake and does a U-turn to go down the right path, attackers can get at the private data while the processor is still heading in the wrong direction.

It seems really difficult to exploit these vulnerabilities. We’ll need some more analysis before we understand what we have to patch and how.

More news.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk