#InfosecurityOnline: Prepare for the Worst-Case Scenario to Build Resiliency

#InfosecurityOnline: Prepare for the Worst-Case Scenario to Build Resiliency

Speaking in the opening keynote session of day two of the Infosecurity Online event Lee Howard, head of IT security, risk and shared services at N Brown Group, discussed the current cyber-threat landscape and explained, in a world of unpredictable cyber-risks, organizations must be prepared for the worst-case scenario in order to be resilient.

“We can’t possibly know every single threat that’s going to affect us – it’s unpredictable. Therefore, we need to go through a mindset change; instead of trying to identify each and every threat methodically, we should be prepared for all threats, whenever they throw themselves at us.”

Most importantly, organizations must be prepared for the worst-case scenario from a cyber-threat perspective, Lee said.

If we can’t assess all the threats and we don’t know the frequency of threats, then organizations must take a “prescribed preparation” approach to the worst-case cyber-scenario.

“Being able to prepare allows you then to absorb the impact of a situation as it unfolds. Preparing for the worst-case scenario makes you really think about what’s valuable. What we do a lot in cybersecurity is focus on certain technologies, areas, initiatives, programs and projects to get things over the line. The reality is, we sometimes forget that we’ve been put in these positions to preserve operations, asses a situation and make ourselves as resilient as possible.”

We are moving into a new phase of technology now and a new era, and the likelihood of an event occurring is very high.

“We’re getting to a point in time where, in having a cyber-incident, we’re not measured in did it or did it not happen,” we’re measured in how we respond and how well the business is able to maintain operations as the incident unfolds.

“That’s the mindset we need to get to; to accept incidents are going to happen,” and respond effectively, Lee concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

NSA: Patch These 25 CVEs Exploited by Chinese Attackers

NSA: Patch These 25 CVEs Exploited by Chinese Attackers

The NSA has published a list of the top 25 vulnerabilities currently being exploited by Chinese state-backed hackers to target US organizations.

These attackers work as most cybercrime groups typically would: by identifying and gathering information on a target, identifying any vulnerabilities and then launching an exploitation operation using homegrown or reused exploits, the NSA explained.

The advisory urged organizations to apply publicly available patches as soon as possible to mitigate the threats.

“This advisory provides Common Vulnerabilities and Exposures (CVEs) known to be recently leveraged, or scanned-for, by Chinese state-sponsored cyber actors to enable successful hacking operations against a multitude of victim networks,” it noted.

“Most of the vulnerabilities listed below can be exploited to gain initial access to victim networks using products that are directly accessible from the internet and act as gateways to internal networks. The majority of the products are either for remote access (T1133) or for external web services (T1190), and should be prioritized for immediate patching.”

Some of the most widely publicized CVEs in the list include Zerologon (CVE-2020-1472), Bluekeep (CVE-2019-0708), SIGRed (CVE-2020-1350), and flaws in Pulse Secure VPNS (CVE-2019-11510) and Citrix ADC and Gateway systems (CVE-2019-19781, CVE-2020-8193, CVE-2020-8195, CVE-2020-8196).

Jake Moore, cybersecurity specialist at ESET, argued that some organizations find it operationally difficult to patch immediately, which might store up problems for later.

“This year’s increase in remote working has also brought additional difficulties with updating machines, highlighting certain problems that were not previously apparent,” he added.

“It is always worth patching at your earliest convenience to help protect each device. Although administrators now have a tougher task in protecting their devices, this list from the NSA could be used to highlight to directors just how important a proactive approach to cybersecurity is.”

The shift to mass remote working has indeed created new opportunities for cyber-atatckers to exploit. In research from Tanium earlier this year 43% of IT ops leaders reported patching problems on users’ personal devices.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#InfosecurityOnline: Beware of Malicious URLs and Rogue Redirects

#InfosecurityOnline: Beware of Malicious URLs and Rogue Redirects

Attackers are using techniques to alter URLs and send victims to rogue and potentially malicious domains.

Speaking at the Infosecurity Online event, Javvad Malik, security advocate at KnowBe4 recommended listeners to look for rogue URLs and “lookalike domains” in phishing messages as it is all too common for a URL to be changed.

Malik said: “A URL can be represented not in how we see it, but use IP addresses and special characters to hide what the real domain name is.” This can include percent encoding, and the URL can be directed elsewhere.

“One technique attackers use is to use a very long URL as people open on their phone and even if they try to expand it, they won’t expand whole thing and click on it anyway,” he said.

Some of the common tactics in phishing include a fake file attachment that is actually an image, which contains a URL, as well as open redirect URL attacks where you think you’re going to one site, “and it could be chain of redirects and it is quite scary.”

If you do need to open a URL, Malik recommended opening it in a safe virtual machine, or turn it over to a forensic expert who will have the right equipment and tools to do so. He also suggested researching the lifespan of the domain, as if it is younger it can be more risky. “Also see if it is on a blacklist,” he said, admitting that most bad domains have short lifespans as attackers remove them when they are detected as being bad.

Malik recommended the best defense for this issue as education, as if a user “hovers” over URLs they can see what the URL is. For business defenses, he also recommended the following:

  • Stay Patched
  • Don’t Knowingly Allow Code to Execute
  • Don’t Download Unexpected Files
  • Investigate or Ignore Suspicious URLs
  • Execute Suspicious URLs in a Virtual Machine
  • Submit to a Malware Inspection Service

Meanwhile for business defenses, he recommended the following:

  • Anti-Malware Defenses
  • Content Filtering
  • Reputation Services
  • Make sure Defenses Decode Encoding Before Inspecting
  • Make sure Defenses Expand Short URLs
  • Keep up to date on the Latest Malicious URL Trends

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Pfizer Exposes Data on Hundreds of Prescription Drug Users

Pfizer Exposes Data on Hundreds of Prescription Drug Users

Pharma giant Pfizer exposed the personal information of hundreds of prescription drug takers for over two months due to a cloud misconfiguration, according to new research from vpnMentor.

A team led by Noam Rotem and Ran Locar discovered the Google Cloud Storage bucket containing the data as part of an ongoing web mapping project. It was completely unsecured and unencrypted when found on July 9, 2020.

The bucket apparently contained transcripts between users of Pfizer drugs and the firm’s interactive voice response (IVR) customer support software, as well as “escalations” to support agents.

Each transcript included full names, home and email addresses, phone numbers and partial health and medical status. The drugs in question included anti-cancer treatments, medication for epilepsy and hormone therapy, treatment for nicotine addiction and Viagra.

VpnMentor argued that any cyber-criminals able to get hold of this data could have used it to craft highly convincing phishing campaigns with victims referencing the call transcripts. Some customers were calling for prescription refills, which could have provided an opportunity for scammers to request credit card details, for example.

“At the time of the data breach, Coronavirus was still surging across the US,” vpnMentor added. “If cyber-criminals had successfully robbed from or defrauded someone taking medication for anxiety in any way, the potential impact on their mental health is immeasurable.”

Unfortunately, the pharmaceutical giant’s response to the findings wasn’t great. It apparently took over two months to respond, and then only with the following: “From the URL you gave, I failed to see how it is important Pfizer data (or even an important data at all).”

The researchers were then forced to share a file with a sample of customers’ personally identifiable information (PII) for the firm to take action, on September 23—although it never responded to them again.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk