#IMOS21: The Critical Role of Culture in DevSecOps

#IMOS21: The Critical Role of Culture in DevSecOps

The approach organizations should take to develop and maintain an effective DevSecOps culture were highlighted by Patrick Debois, director of market strategy at Snyk during a session at the Infosecurity Magazine Online Summit EMEA 2021.

Debois firstly emphasized the importance of an organization’s culture in determining the DevSecOps strategy that should be employed. “The CEO and culture of your company will set the tone on the areas upon which your DevSecOps transformation will address,” he commented. Depending on the context, this may involve greater focus on automation, metrics, empowerment or command and control.

He then outlined the different ‘topologies’ available, which relate to the nature of the relationship between dev and ops teams, with varying degrees of closeness. The type that will work best in a given organization is dependent on the culture that has been developed, he said. These can manifest in five ways:

  1. Dev and ops collaboration
  2. Fully shared ops responsibilities
  3. DevOps with expiry date
  4. DevOps Evangelist
  5. Container-driven collaboration

Debois went on to describe three team interaction modes that need to be considered:

  1. Collaboration: the day-to-day human collaboration
  2. X-as-a-service: the self-servicing automation that a developer can use
  3. Facilitating: a facilitation by the teams to help guide the collaboration

He added: “If you’re constructing how your teams overlap, you also have to look at how they will collaborate.”

Ultimately, in the view of Debois, building and gaining trust between the respective teams is what is most essential. He highlighted four key facets related to this:

  1. Sincerity
  2. Reliability
  3. Competence
  4. Care

Debois noted that competence is not enough on its own. “That’s why I see DevSecOps as the trust building up between both parties,” commented Debois.

Finally, the four areas of DevSecOps were defined as the following:

  1. Secure stack: what is being delivered and is that secure? e.g. code dependencies
  2. Secure delivery: how it’s being delivered and is that secure? e.g. is the integrity of the download secure
  3. Security governance: Where the team hooks into the processes of the security team
  4. Security empowerment: How the team interacts with security, ultimately to acquire security knowledge.

These are all interlinked, and there is an equal focus placed upon each. Debois concluded: “You have to level up in a spiral way on all of these areas.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fired IT Contractor Jailed for Retaliatory Cyber-Attack

Fired IT Contractor Jailed for Retaliatory Cyber-Attack

An IT contractor who carried out a retaliatory cyber-attack after being fired for underperforming has been sent to prison. 

Indian national Deepanshu Kher was hired by an American IT consulting firm in 2017. The firm sent Kher to the headquarters of a company in Carlsbad, California, to assist the business with its migration to a Microsoft Office 365 (MS O365) environment.

The company was unhappy with the standard of Kher’s work and wasted no time in reporting their dissatisfaction to his employer. In January 2018, Kher was removed from the Carlsbad company’s headquarters, and on May 4, he was fired from his position at the IT consulting firm. 

A month after losing his job, Kher moved to Delhi, India, from where he took his revenge. On August 8, 2018, Kher hacked into the server of the Carlsbad company that had complained about his performance and deleted over 1,200 of its 1,500 MS O365 user accounts.  

The cyber-attack affected the majority of the company’s employees. Its impact was so serious that the company was forced to shut down completely for a period of two days. 

Employees could not access their email, contact lists, meeting calendars, documents, corporate directories, video and audio conferences, and the Virtual Teams environment they relied on to perform their jobs. 

Customers, vendors, and consumers couldn’t be reached by company employees, and the employees were not able to inform clients about what was going on or let them know when company operations would be restored.

Following the attack, the Carlsbad company repeatedly suffered IT problems for three months. Employees didn’t receive meeting invites and cancellations, contact lists had to be rebuilt from scratch, and access to folders had to be restored. 

Court documents record the company’s vice president of IT stating: “In my 30-plus years as an IT professional, I have never been a part of a more difficult and trying work situation.”

Kher was arrested when he flew to the United States on January 11, 2021. On March 22, the 32-year-old was sentenced to two years in prison and three years’ supervised released. He was further ordered to pay $567,084 in restitution to the company whose operations he sabotaged.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UPMC and Charles Hilton Sued Over PHI Breach

UPMC and Charles Hilton Sued Over PHI Breach

A Pennsylvania medical center and its legal services provider are facing a class-action lawsuit over a data breach that exposed the protected health information (PHI) of more than 36,000 patients. 

The breach occurred last year when hackers gained access to several email accounts belonging to employees of law firm Charles J. Hilton & Associates P.C. (CJH). An investigation revealed that the attackers had access to the accounts between April 1 and June 25, 2020. 

CJH provides billing-related legal services to the University of Pittsburgh Medical Center (UPMC). In December 2020, CJH notified UPMC of the breach and confirmed that the threat actors may have accessed UPMC patient data. 

Information exposed in the breach included names, dates of birth, Social Security numbers, bank or financial account numbers, driver’s license numbers, state identification card numbers, electronic signatures, medical record numbers, patient account numbers, patient control numbers, visit numbers, and trip numbers.

Furthermore, the threat actors gained unauthorized access to Medicare or Medicaid identification numbers, individual health insurance or subscriber numbers, group health insurance or subscriber numbers, medical benefits and entitlement information, disability access and accommodation, and information related to occupational health, diagnosis, symptoms, treatment, prescriptions or medications, drug tests, billing or claims, and/or disability.

lawsuit, brought by lead plaintiff Vince Ranalli, accuses UPMC and CJH of a number of violations including negligence, invasion of privacy, and failure to secure patients’ PHI. 

In the weeks following the breach, Ranalli said that his bank contacted him to advise him that his name had been used to open an unauthorized account. 

“They opened it with my Social Security number, my driver’s license, my address,” said Ranalli in an interview with Action 4 News. “They pretty much had all of my personal information.” 

Ranalli added that the data breach had also impacted his father, who had received four credit cards that he had not applied for after his data was exposed. 

Filer of the lawsuit, Joshua P. Ward of J.P. Ward & Associates, said: “We’re seeking to curtail the problem, identify all the people affected, recover monies for them to the extent they’re entitled and to protect their information.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IMOS21: AI Analysts May Prove Key to Keeping Organizations Secure

#IMOS21: AI Analysts May Prove Key to Keeping Organizations Secure

Leveraging AI to undertake investigations of suspicious activities could significantly increase security teams’ abilities to protect their organizations from cyber-attacks, according to Andrew Tsonchev, director of technology, Darktrace, speaking during the Infosecurity Magazine Online Summit EMEA 2021.

The development of an ‘AI analyst’ differs from the normal role of threat detection played by this type of technology in cybersecurity. In essence, it looks to “replicate the sort of steps taken by a human analyst in a SOC in a course of an investigation.”

Part of the driver for Darktrace’s work in this area has been the extra pressure placed on security teams as a result of the changing working patterns in the past year. This has led to the growing use of remote endpoints as well as technologies such as SaaS and collaboration tools, expanding the threat landscape.

An additional consideration is the trend of malicious actors utilizing AI from an offensive standpoint, which would allow them to significantly ramp up attacks. Tsonchev noted that “we are in the beginning phases of that at the minute.”

Conversely, giving AI the human traits of investigation can help organizations become aware of, and deal with, threats much more quickly. While typically AI tools are used to detect any unusual patterns and behaviors in an organization’s system by matching it against the usual activities, the next step is enabling it to analyse and interpret any anomalies in the way human security analysts normally would.

“Humans take the initial alert as a jumping-off point to begin an investigative process, which is active and involves discovery, question asking and data gathering and analysis,” explained Tsonchev. He added: “The way this technology works is to train machine learning engines on the way humans do security investigation,” ultimately concluding if that threat poses a risk to the organization.

Such an approach can free up security teams, reducing their initial triage time by up to 92%, according to Tsonchev. The AI analyst can then produce a report which gives the most pertinent information.

He then gave an example of a successful AI investigation relating to attacks from APT41 in March 2020 that exploited a zero-day vulnerability. This led to the threat being quickly identified as the highest priority. Tsonchev commented: “You can detect any and all strange things in the environment but if those alerts are buried amongst a sea of 300 other alerts in a day, then you haven’t really detected it in a meaningful way that really helps your security team.”

He added: “The key value proposition here is not to throw an analyst 50 alerts, but to identify a map to an ongoing threat, to classify the nature of that threat and to understand the type of behavior.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Herjavec to Handle Cybersecurity for Formula 1

Herjavec to Handle Cybersecurity for Formula 1

Canadian cybersecurity firm Herjavec Group has been appointed as the Official Cybersecurity Services Provider to Formula 1

The group’s newest gig was announced yesterday. Herjavec will support the world’s most prestigious motor racing competition and annual sporting series in three critical areas. 

Herjavec’s first role will be to secure the Formula 1 Event Technical Center by providing managed security services that will include threat intelligence and cyber analysis. These services will be deployed to protect Formula 1’s data-rich race operations as the competition travels from country to country.

In 2021, the F1 Event Technical Center will be making pit stops in 22 different countries. Herjavec will be tasked with protecting the real-time racing analysis, security event logs, and threat intelligence information generated at each location.

The new appointee’s second role will focus on providing Formula 1 with round-the-clock threat detection to keep its corporate operations, digital platforms, and mission-critical assets safe. Using its cloud-based remote and geo-redundant Security Operations Center (SOC) infrastructure, Herjavec will provide 24/7 expertise to catch and tackle emerging threats targeting Formula 1’s critical infrastructure. 

Other managed security services that Herjavec has been engaged to provide include managed incident response, phishing tests, vulnerability management, and security engineering.

The company’s third area of focus will be to offer advice and expertise to help Formula 1 enhance its overall security posture. Key cyber initiatives that Herjavec intends to launch will address security planning, PCI compliance, architecture, privacy, emergency planning, and identity and access management. 

Self-confessed racing fanatic Robert Herjavec, Herjavec Group founder and CEO, said: “Racing is in the DNA of Herjavec Group and a clear analogy for the work we do as cybersecurity experts. You’ve got to be laser focused when driving a car 200MPH—because if you look left or right, you’ll lose control.”

Chris Roberts, head of IT infrastructure at Formula 1, said: “We chose to partner with Herjavec Group because they excel in security at scale and we are confident in their ability to support us in protecting our infrastructure as we continue to expand our leadership as the pinnacle of motorsport.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CSA and ISACA Announce First Auditing Credential for Cloud Security Systems

CSA and ISACA Announce First Auditing Credential for Cloud Security Systems

The Cloud Security Alliance (CSA) and ISACA have announced the availability of the first credential for auditing the security of cloud security systems.

The introduction of the Certificate of Cloud Auditing Knowledge (CCAK) comes amid a huge surge in the adoption of the cloud in the past year, as organizations scrambled to facilitate mass remote working.

Developed by the CSA and ISACA, the CCAK credential and training program aims to prepare IT and security professionals to ensure internal requirements are fulfilled and the right controls are in place when assessing cloud systems. It also teaches how to mitigate the risks and costs of audit management, avoid penalties for non-compliance and lead an organization through successful cloud migration while retaining customer trust.

The four topics the CCAK curriculum focuses on are cloud governance, cloud compliance, cloud auditing and cloud assurance, with these areas supported through practical tools.

There are a range of study and exam prep options for industry professionals, including an online, self-paced course and a two-day instructor-led virtual course. The exam consists of 76 multiple-choice questions.

The program builds on the knowledge covered in the CSA’s Certificate of Cloud Security Knowledge (CCSK) as well as complementing ISACA’s ANSI accredited certifications.

CSA chief technology officer, Daniele Catteddu commented: “The historic shift to cloud has created a new technology foundation for our global economy. Trusting this computing infrastructure is one of our most fundamental challenges. The introduction of the CCAK is an important milestone in delivering the necessary expertise to enable professionals to objectively evaluate critical cloud assurance issues. CSA is proud of our collaboration with ISACA to create this high quality credential which will be leveraged by individuals, businesses and regulatory bodies around the world to raise the baseline of security, governance and compliance in cloud computing.”

Paul Phillips, CISA, CISM, CDPSE, technical research manager at ISACA, said: “Cloud, while not an emerging technology, is still new for many organizations. As such, there tends to be lack of internal knowledge and effective auditing among leaders and staff. Enterprises need to understand the hurdles as they attempt to migrate to the cloud to make sure the issues are adequately addressed. CSA and ISACA decided to collaborate to ensure that companies had the right tools and expertise to successfully migrate to the cloud.”

The certification has been developed for the following roles: internal and external assessors and auditors, third party assessors and auditors, CISOs and information security officers, chief privacy officers, data protection officers, security and privacy consultants, compliance managers, vendor/partners program managers and procurement officers.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

MangaDex Site Could Be Offline for Weeks After Attack

MangaDex Site Could Be Offline for Weeks After Attack

Popular manga reader MangaDex has decided to rebuild its website after suffering a major breach which compromised its source code and potentially a customer database.

The “scanlation” site enables fans of certain titles to read them in their own language for free. However, last Wednesday it discovered an unauthorized individual had managed to gain access to an administrator account, after stealing a session token by exploiting a web vulnerability.

The site was brought back online after the MangaDex team patched the vulnerabilities they found but was forced offline again after the attacker accessed the account of one of its developers.

In the meantime, possession of that key allowed the attacker to steal and subsequently post a link to the site’s source code on a git repository. In a game of cat-and-mouse, the attacker posted messages claiming the MangaDex team had fixed two out of three key CVEs.

Instead of playing the game, the admins have decided to keep the site offline while they build a new, more secure version.

“As of writing, we have invited numerous volunteers to assist our developers with identifying the last possible CVE claimed by the attacker in the codebase. Thanks to our volunteers, we have identified a good number of potential security flaws and moved to rectify them. However, at time of writing, we have still yet to identify the last possible CVE claimed by the attacker,” they said.

“With that knowledge in mind, we were confronted with a difficult decision. If we had assumed incorrectly that the web code is now secure, we could end up being compromised again by the attacker. As a result of that, in good conscience, we could not possibly re-open the website to users presently.”

Given the staff of the site consists mainly of volunteers, it could take some time before it is back online.

“As developing and maintaining MangaDex is nobody’s actual job, it is difficult to give an accurate estimate as to when we’ll be back up and running. It should go without saying that every one of us wants it to happen as soon as safely possible,” the note continued.

“That said, if everything goes as smoothly as we dare to hope, we could be looking at a downtime of just a week or two. Or three.”

In the meantime, MangaDex warned users that they should assume their data has been compromised.

“As a user, we will encourage that you would assume that your data has been breached, and take precautions immediately, such as changing the passwords of any accounts that might share the same password as your MangaDex account,” it said. “As a generally good security practice, password managers are highly recommended to keep your online identity secure.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Dark Web #COVID19 Vaccine Ads Surge 350%

Dark Web #COVID19 Vaccine Ads Surge 350%

The black market in coronavirus-related pharmaceuticals and tests continues to grow, with researchers detecting a 350% increase in adverts for supposed ‘vaccines’ over the past three months.

Check Point Research revealed new data today claiming that the number of dark web ads for COVID-19 vaccines has trebled since January, with Johnson & Johnson ($600), AstraZeneca ($500), Sputnik ($600) and SinoPharm ($500) brands all on offer for a few hundreds dollars apiece.

Dark web activity around COVID-19 now also extends to fake vaccination cards from the Centers for Disease Control and Prevention (CDC), selling for $150 each.

Elsewhere, researchers spotted fake negative COVID-19 test documents for sale with a “buy two get the third free” deal. Other vendors are selling DIY versions of a negative COVID-19 test document which can be generated in less than 30 minutes for as little as $25, according to Check Point.

Oded Vanunu, head of product vulnerabilities research at Check Point, said the illicit activity had exploded over the past couple of months, from just a few hundred ads for the Moderna or Pfizer vaccine to over 1000 for numerous brands.

He warned that vaccine-related activity would continue to grow as long as there is strong demand from the global populace.

Attempting to purchase vaccines via these channels is extremely dangerous as, even if they are legitimate, they may have been stored incorrectly and could be hazardous. Fake vaccine certificates are also damaging to public health as they could allow individuals still exposed to the virus and potentially infectious to claim they’re protected.

“It’s imperative for people to understand that attempting to obtain a vaccine, a vaccination card or negative COVID-19 test result by unofficial means is extremely risky, as hackers are more interested in your money, information and identity for exploitation. People who have not been vaccinated and try to use fake COVID test results or vaccine certificates are damaging the fight against the disease,” argued Vanunu. 

“We also strongly urge everyone to not share their vaccination cards or negative COVID-19 tests on social media, as the information on those pictures can make its way onto the darknet in some form.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IMOS21: Overcoming the Defender’s Dilemma

#IMOS21: Overcoming the Defender’s Dilemma

Speaking in the opening keynote session of the Spring Infosecurity Magazine Online Summit, security awareness advocate Javvad Malik explored what he referred to as the “defenders dilemma” – along with outlining strategies for overcoming the issue.

Malik explained that due to various reasons including budget/resourcing challenges, competing business priorities and incomplete data, the defender’s dilemma is that most companies are inefficient defenders.

“There is a perception about security that is built up, but it’s not necessarily aligned with reality,” he said. 

However, Malik said there is “one simple trick” to overcoming the defenders dilemma, which is to “shift our perspectives” towards security.

That revolves around two key elements, Malik added: implementing a data-driven approach along with a marketing-driven approach.

To achieve that, organizations should consider and address three specific areas of security.

The first is assessing and understanding what defenders are up against. Threats are multifaceted and varied, Malik explained, but too often “we see all threats presented as one and we apply defenses equally.” Instead, businesses need to focus on the most important threats to them, gauge their root causes and dedicate efforts to stopping them specifically.

Next, organizations should pay greater attention to human-related experiences, because security has a tendency to overspend on technical strategies and fail to consider the experience of everyday users.

Finally, there is a need to better communicate and market security successes, especially to non-security personnel. “Talk about your successes – it may surprise people and shift their understanding about the good job we do as defenders,” Malik concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Shell Latest to Fall to Accellion FTA Exploits

Shell Latest to Fall to Accellion FTA Exploits

Shell has become the latest big-name firm to reveal it was affected by a data breach targeting vulnerabilities in legacy file transfer software.

In a brief statement that came to light this week, the oil giant admitted it is a customer of Accellion’s File Transfer Appliance (FTA) product.

It said it had addressed the exploited vulnerabilities and begun an investigation into the incident. As per other organizations breached in this way, it claimed that its core IT system was unaffected as FTA is isolated from the rest of its digital infrastructure.

“The ongoing investigation has shown that an unauthorized party gained access to various files during a limited window of time. Some contained personal data and others included data from Shell companies and some of their stakeholders,” the statement noted.

“Shell is in contact with the impacted individuals and stakeholders and we are working with them to address possible risks. We have also been in contact with relevant regulators and authorities and will continue to do so as the investigation continues.”

It’s unclear when Shell discovered the breach and which vulnerabilities were targeted. Accellion patched two zero-day bugs in late December, but attackers managed to compromise Singtel via a third vulnerability in January.

Other organizations known to have been affected include the New Zealand central bank, aircraft maker Bombardier, retail giant Kroger and legal firm Jones Day.

Security vendor FireEye has claimed that the group behind the attacks share similarities with the FIN11 cybercrime gang and the Clop ransomware group, on whose leaks site information stolen from some of the victims of this campaign has been published.

Accellion itself has claimed that “fewer than 100” of the 300 or so corporate users of FTA were affected by the campaign, and “fewer than 25 appear to have suffered significant data theft.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk