NCIJTF Releases New Ransomware Fact Sheet

NCIJTF Releases New Ransomware Fact Sheet

America’s National Cyber Investigative Joint Task Force (NCIJTF) has released a new joint-seal fact sheet in a bid to raise public awareness about ransomware.

The sheet was created to publicize both the current threat posed by this particular type of malware and detail the United States government’s response. In addition, the document describes common infection vectors, tools for attack prevention, and who to contact in the event of a ransomware attack.

To produce the sheet, the NCIJTF pulled together an interagency group of subject-matter experts from over 15 different government agencies.

The group’s advice on the best way to minimize ransomware risks was to “backup your data, system images, and configurations, test your backups, and keep the backups offline.” 

Use of multi-factor authentication was advised along with updating and patching systems and making sure security solutions are up to date. The group also recommended having an incident-response plan and reviewing and exercising it.

According to the NCIJTF, an estimated minimum of $144.35m in Bitcoin has been paid out as ransomware ransom between 2013 and 2019.

“While fact sheets such as this may not be particularly helpful, it’s certainly good to see the government becoming increasingly proactive in relation to the ransomware problem. Every little bit helps,” Emsisoft’s Brett Callow told Infosecurity Magazine.

“It’s also good to see direct action against cybercrime groups enjoying some success with the recent disruptions of Emotet and NetWalker. Combatting threats requires action on multiple fronts–education, enforcement, policy–and, in combination, these measures may eventually see a reduction in cybercrime.”

In a statement released today, the FBI said that the federal government was particularly concerned about ransomware attacks on the networks of police and fire departments; state, local, tribal, and territorial governments; municipalities; hospitals; and other critical infrastructure.

The Bureau said: “These types of attacks can delay first responders in responding to emergencies or prevent a hospital from accessing lifesaving equipment. It is imperative these organization be prepared in the face of the ransomware threat.”

The FBI advises those hit by ransomware not to pay up as doing so will not guarantee the recovery of those files encrypted by the criminals. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Study Finds Delays in Revoking System Access

Study Finds Delays in Revoking System Access

Organizations in the United States are impacting their security by dilly-dallying when it comes to granting and revoking system access, according to new research. 

A study published today by the Identity Defined Security Alliance (IDSA) uncovered significant delays in giving and rescinding access to corporate systems, impacting operations and increasing potential risk to the organization.

The non-profit’s report, “Identity and Access Management: The Stakeholder Perspective,” found that for the majority of companies (72%) it takes one week or longer for a typical employee to obtain access to required systems. 

After a worker leaves, it takes half of organizations three days or longer to revoke the former employee’s system access, creating regulatory compliance issues and prolonging the risk of data theft. 

Only 23% said system access enablement is automated, while 35% report revoking system access is automated. 

The majority of organizations (83%) reported that the migration to remote work and other Covid-19-related factors have made managing access to corporate systems more difficult.

The report is based on an independent online survey of 313 qualified HR, sales, and help-desk professionals working at companies in the United States with at least 1,000 employees where a typical employee requires access to multiple systems. 

All survey participants had direct responsibility for adding or removing access to corporate systems, but 62% said that they would be hesitant to cut worker access in the face of concerning behavior. 

Only two in five (38%) reported that they would immediately block access for a worker who was accessing systems or data inappropriately.

Worryingly, 69% of access stakeholders admitted behaving in a risky way, including using the same username and password for both work and personal accounts, using an unauthorized device for work, or sharing credentials with non-workers. For the majority (68%), it was more important to get a job done than to carry it out in a secure way.

“Though the report findings are unsettling, they reflect the realities of today’s complex work-from-home environment and hybrid landscape of cloud and on-premises applications,” Greenlight president Kevin Dunne told Infosecurity Magazine.  

“Typically, IT security teams rely on a hodgepodge of point solutions for each application with little visibility across the enterprise landscape. Fortunately, many new advancements have been made in the area of just-in-time provisioning, which can automate much of the access governance process and shave provisioning and deprovisioning time from days down to seconds.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Automated Tools Increasingly Used to Launch Cyber-Attacks

Automated Tools Increasingly Used to Launch Cyber-Attacks

Cyber-criminals are increasingly making use of automation and bots to launch attacks, according to a new analysis by Barracuda Networks.

In its new report, Threat Spotlight: Automated attacks on web applications, the cybersecurity firm revealed that over half (54%) of all cyber-attacks it blocked in November and December were web application attacks which involved the use of automated tools.

The most prevalent form was fuzzing attacks, making up around one in five (19.5%). This uses automation to detect and exploit the points at which applications break. This was followed by injection attacks (12%), in which cyber-criminals make use of automation tools such as sqlmap to gain access to applications.

Fake bots also represented 12% of the total number of attacks blocked by Barracuda. These are automated attacks that pretend to be a Google bot or similar. Making up the top five web application attacks were application DDoS (9%) and bots blocked by site admins (2%).

While bot traffic is growing, the researchers noted that more traditional web app attacks, such as injection attacks and cross site scripting (1%), remained prevalent.

Tushar Richabadas, senior product marketing manager at Barracuda Networks, commented: “Automated attacks can overwhelm or infiltrate web applications, and defending against all the varieties of automated attacks can be daunting.

“The good news is that multi-purpose solutions are consolidating into Web Application Firewall and WAF-as-a-Service solutions, also known as Web Application and API Protection services (WAAP). Thus, organizations looking to bolster their defenses against this growing threat should look for a WAAP solution that includes bot mitigation, DDoS protection, API security and credential stuffing protection, as a minimum, and also make sure it is properly configured.

“It is also important to stay informed about current threats and how they are evolving, so that your business can be defended against them. Over the coming year, we can expect automated bot attacks, attacks against APIs and attacks against software supply chains to develop in quantity and sophistication, especially as these newer attacks have fewer protections and defenses blocking them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

IBM Announces Cybersecurity Grants for US Schools

IBM Announces Cybersecurity Grants for US Schools

American technology company IBM announced today that it will be making $3m available to US public schools in the form of cybersecurity grants.

Grants in the form of in-kind services will be awarded to six school districts to sponsor “teams of IBMers” from the company’s Service Corps Program who will help schools proactively prepare for cyber-attacks and learn how to mitigate them. 

The announcement comes after an IBM-sponsored study revealed that nearly 60% of school staff are unprepared to face cybersecurity threats and more than half said their school would be more secure if it had more money.

The study itself was prompted by an alert issued by the FBI in December 2020 that warned that out of all the reported ransomware incidents that took place between August and September 2020, nearly 60% involved K–12 schools, an increase of 29% from the two months prior.

Completed by Morning Consult, the study surveyed 1,000 US educators and administrators in K–12 schools and colleges to gauge the level of cybersecurity awareness, preparedness, and training within schools during the widespread adoption of remote learning.

Among the key findings of the survey are the while 78% of educators reported that they are currently using some form of online schooling, nearly 60% of educators and administrators said they aren’t sure or haven’t received new cybersecurity initiatives or remote learning training.

More than half of educators and administrators have not received cybersecurity training, and, despite widespread media coverage of Zoom-bombing attacks, nearly 50% of educators said that they aren’t familiar with video-bombing. 

Most administrators (83%) were confident in the ability of their school to handle a cyber-attack, yet more than 60% didn’t know whether their school had any cyber-insurance.

Six grants, valued at $500k each, will be awarded in 2021 to school districts that apply via IBM.org. Application is open now until March 1.  

“Ransomware attacks on schools have become the new snow day for students,” said Christopher Scott, director of security innovation, office of the CISO, IBM. “And with budgets focused on new ways of learning, many schools are in need of additional resources and technology to change the dynamic and lower the financial ROI for the bad guys targeting them.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Disclosed ICS Vulnerabilities Surged During Second Half of 2020

Disclosed ICS Vulnerabilities Surged During Second Half of 2020

A substantial rise in industrial control system (ICS) vulnerabilities were detected in the second half of 2020, according to Claroty’s second Biannual ICS Risk & Vulnerability Report.

The research revealed that there had been a 25% year-on-year rise in ICS vulnerabilities disclosed in this period, and a 33% increase compared to H1 of 2020. Throughout the six-months, a total of 449 vulnerabilities affecting ICS products from 59 vendors were highlighted, 70% of which were assigned high or critical Common Vulnerability Scoring System (CVSS) scores. Around three-quarters (76%) do not require authentication for exploitation.

A major factor for this increase has been the shift to digital across all industries, creating an expanded potential attack surface. Worryingly, more than two-thirds of disclosed vulnerabilities were remotely exploitable through network attack vectors.

The sectors that experienced the biggest rises in ICS vulnerabilities compared to the second half of 2019 were critical manufacturing (15%), energy (8%), water and wastewater (54%) and commercial facilities (14%).

An encouraging finding from the report was that third party researchers were responsible for 61% of discoveries, which indicates a growing focus on including ICS alongside IT security research. This increased focus on identifying ICS vulnerabilities partly explains the surge in detections disclosed.

Amir Preminger, vice-president of research at Claroty, commented: “The accelerated convergence of IT and OT networks due to digital transformation enhances the efficiency of ICS processes, but also increases the attack surface available to adversaries.

“Nation state actors are clearly looking at many aspects of the network perimeter to exploit, and cyber-criminals are also focusing specifically on ICS processes, which emphasizes the need for security technologies such as network-based detection and secure remote access in industrial environments. It is heartening to see a growing interest in ICS within the security research community, as we must shine a brighter light on these vulnerabilities in order to keep threats at arm’s length.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

London Orgs: Increased Risk Due to Remote Working to Persist for 12-18 months

London Orgs: Increased Risk Due to Remote Working to Persist for 12-18 months

Three in five (60%) organizations in London and the South East of England have seen an increased level of risk to their IT infrastructure due to remote working, with 88% expecting this risk to persist for the next 12-18 months.

That’s according to a survey of 400 senior decision makers by international law firm Bird & Bird exploring how changes to the way businesses operate as a result of the COVID-19 pandemic have created challenges regarding the IT infrastructure they rely on.

Just under half of those polled (46%) noted an increase in the number of cyber-attacks they have experienced since March 2020, with that figure rising to 57% for those in financial services businesses.

What’s more, 55% of respondents said there has been a significant increase in the number of customers targeted by online or remote scammers since the start of the pandemic, increasing to nearly 70% amongst technology and communications businesses.

The findings serve as a stark reminder of what’s at stake for organizations in the UK’s capital as they continue to adapt to the ongoing health crisis.

Bird & Bird’s cybersecurity expert and partner, Simon Shooter, said: “Cyber-criminals are seeing a more target-rich environment because of people working from home, using systems which may be significantly more vulnerable than those in their offices.

“Companies need to make sure they have a holistic approach to security; you’re only as secure as your leakiest point. In terms of cybersecurity legislation, it’s inevitable that there will be changes. Compliance teams should keep an eye on this and aim to bring compliance in early. It’s always harder and more expensive to do so when you’ve got the gun of a regulatory deadline against your head.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three More Vulnerabilities Found in SolarWinds Products

Three More Vulnerabilities Found in SolarWinds Products

Security researchers have discovered three more vulnerabilities in SolarWinds products, including a critical remote code execution bug.

The IT management software provider has been in the news regularly over recent weeks after its Orion product was targeted by alleged Russian state hackers, in a major supply chain attack aimed at the US government.

A vulnerability patched in December was at the center of a new report this week claiming that Chinese state-sponsored threat actors exploited it as part of a cyber-espionage attack on a US federal payroll agency.

Now Trustwave is urging customers to address three “severe” flaws it found in SolarWinds products. The vendor fixed the issues promptly and there have been no reports of “in the wild” exploitation, but prompt patching is recommended.

Two of the software flaws are found in the SolarWinds Orion User Device Tracker and one is in the firm’s Serv-U FTP product.

The most critical vulnerability, CVE-2021-25274, is found in the former. It relates to the legacy Microsoft Message Queue (MSMQ) technology which is set up on installation, and could allow any remote unprivileged user to execute any arbitrary code with the highest privileges.

The second bug, CVE-2021-25275, affects the same product. Trustwave claimed that SolarWinds credentials are stored in an insecure manner which could allow local users to take complete control over the SOLARWINDS_ORION database. In so doing, they could steal data or add a new admin-level user inside SolarWinds Orion products, it said.

Finally, there’s CVE-2021-2527, in the SolarWinds Serv-U FTP for Windows product.

“Any local user, regardless of privilege, can create a file that can define a new Serv-U FTP admin account with full access to the C: drive. This account can then be used to login via FTP and read or replace any file on the drive,” explained Trustwave.

The security vendor said it is giving customers an extra week to patch before it releases proof-of-concept code.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Shipping Giant Loses $7.5m in Ransomware Attack

US Shipping Giant Loses $7.5m in Ransomware Attack

A leading US transportation business has become the latest corporate victim to lose millions in a ransomware attack, according to a regulatory filing.

Tennessee-headquartered Forward Air describes itself as the leading provider of ground transportation and logistics for North American air freight and less-than-truckload (LTL) shipping.

Its 8-K filing with the Securities and Exchange Commission (SEC) yesterday revealed the attack was first detected by the firm on December 15 last year.

“While the company’s systems recovery efforts are completed and the company’s operations are fully functional, the incident did result in a loss of revenue as well as incremental costs for the month of December which will adversely impact the company’s fourth quarter 2020 results,” it noted.

In fact, it lost an estimated $7.5m in LTL revenue in the quarter, “primarily because of the company’s need to temporarily suspend its electronic data interfaces with its customers.”

Although the loss doesn’t seem to have had a major impact on Forward Air’s year-on-year fourth quarter growth, the news highlights again the potentially major financial repercussions of ransomware attacks.

As well as lost sales and operational losses, victim organizations typically spend big on additional IT support and third-party investigation and forensics contracts, and must also absorb the hit to staff productivity.

Many organizations have taken out cyber insurance policies in order to cover themselves in such cases. However, some experts have argued that these may encourage firms to simply pay the ransom, thereby perpetuating the problem as cyber-criminals see there is easy money to be made.

It doesn’t appear that Forward Air had such a policy.

In fact, the average ransom payment dropped 34% from Q3 2020 to the final quarter of last year, according to Coveware. The vendor claimed this could be due to reports of ransomware groups breaking their promise to delete stolen data taken from victim organizations on payment.

“The trust that stolen data will be deleted is eroding; defaults are becoming more frequent when exfiltrated data is made public despite the victim paying,” it argued. “As a result, fewer companies are giving in to cyber-extortion when they are able to recover from backups.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Google: Incomplete Patches Caused Quarter of Zero-Days in 2020

Google: Incomplete Patches Caused Quarter of Zero-Days in 2020

A quarter of zero-day exploits discovered last year could have been avoided if vendors had taken a more methodical and comprehensive approach to patching, according to Google.

Project Zero security researcher, Maddie Stone, argued in a blog post yesterday that 25% of zero-days spotted in 2020 were closely related to previously publicly disclosed vulnerabilities.

This means that incomplete patches issued by vendors are effectively allowing attackers to craft follow-up zero-days more easily, in some cases simply by changing a line or two of code.

“A correct patch is one that fixes a bug with complete accuracy, meaning the patch no longer allows any exploitation of the vulnerability. A comprehensive patch applies that fix everywhere that it needs to be applied, covering all of the variants. We consider a patch to be complete only when it is both correct and comprehensive,” Stone explained.

“When exploiting a single vulnerability or bug, there are often multiple ways to trigger the vulnerability, or multiple paths to access it. Many times we’re seeing vendors block only the path that is shown in the proof-of-concept or exploit sample, rather than fixing the vulnerability as a whole, which would block all of the paths. Similarly, security researchers are often reporting bugs without following up on how the patch works and exploring related attacks.”

She detailed six of the 24 zero-day, browser-based exploits detected last year which were closely related to previous publicly disclosed bugs, and a further three vulnerabilities from 2020 and 2019 which were exploited in the wild but not properly fixed.

To improve the situation, vendors will need to focus on investment, prioritization and planning, Stone argued.

“Exactly what investments are likely required depends on each unique situation, but we see some common themes around staffing/resourcing, incentive structures, process maturity, automation/testing and partnerships,” she noted.

“While the idea that incomplete patches are making it easier for attackers to exploit zero-days may be uncomfortable, the converse of this conclusion can give us hope. If more vulnerabilities are patched correctly and comprehensively, it will be harder for attackers to exploit zero-days.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk