US and Israel Agree Anti-Ransomware Coalition

US and Israel Agree Anti-Ransomware Coalition

The US and Israel yesterday announced a new bilateral partnership designed to tackle ransomware.

The move comes as part of the new US-Israeli Task Force launched on Sunday slated to cover Fintech Innovation and Cybersecurity more broadly.

Its participants are currently working on a Memorandum of Understanding (MoU) to support joint activities, including information sharing in threat intelligence, security guidance and regulations.

Also mooted are staff training, study visits and cross-border competency-building initiatives such as cybersecurity exercises linked to finance and investment flows.

The task force will launch a series of technical exchanges on policy, regulation and outreach to ensure robust cybersecurity is built into fintech innovation early. It will also work on advancing compliance with anti-money laundering, counter-terrorist financing and nuclear proliferation financing.

There were very few details on how the two countries plan to tackle ransomware specifically, even though the Treasury trumpeted this as the headline aspect of the new bilateral agreement.

“Harnessing both the power of international cooperation and of technology innovation will position us to support economic competitiveness, prosperity and to combat global threats including ransomware,” said deputy secretary of the Treasury, Wally Adeyemo.

“As the global economy recovers and ransomware and other illicit finance threats present a grave challenge to Israel and the US, increased information exchanges, joint work and collaboration on policy, regulation, and enforcement are critical to our economic and national security objectives.”

The deal comes just weeks after a virtual Counter-Ransomware Initiative hosted by the White House last month and attended by representatives from the EU and 30 other countries, including Israel.

While the US is regularly touted as the number one target for ransomware actors, Israel is coming under increasing fire from its rivals in the Middle East.

In May, multiple companies were hit by suspected Iranian group ‘Networm,’ while earlier this month, another Tehran-backed outfit, BlackShadow, leaked sensitive data from hundreds of thousands of medical patients and members of an online LGBTQ collective.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

CISA: Patch These ICS Flaws Across Multiple Vendors

CISA: Patch These ICS Flaws Across Multiple Vendors

The US authorities have released a new industrial control systems (ICS) alert urging impacted organizations to patch key middleware or risk denial of service and remote code execution attacks.

The Cybersecurity and Infrastructure Security Agency (CISA) pointed to a series of vulnerabilities impacting open-source and proprietary implementations of the Object Management Group (OMG) Data-Distribution Service (DDS).

The bugs are found in multiple vendors’ equipment: CycloneDDS, FastDDS, GurumDDS, OpenDDS, Connext DDS Professional, Connext DDS Secure, Connext DDS Micro, and CoreDX DDS.

“CISA is issuing this advisory to provide early notice of the reported vulnerabilities and identify baseline mitigations for reducing risks to these and other cybersecurity attacks,” it said. “Successful exploitation of these vulnerabilities could result in denial-of-service or buffer-overflow conditions, which may lead to remote code execution or information exposure.”

While the affected products have been updated by most of the vendors, CISA warned that it had not yet received a response from Korean firm Gurum Networks, and urged impacted customers to contact it directly.

As well as apply the relevant patches, organizations were also told to air-gap ICS devices and systems, or at least to isolate them from business networks and place them behind a firewall. VPNs were also recommended for secure remote access.

CISA’s readiness to alert ICS customers about security flaws can be linked to the Biden administration’s focus on enhancing critical national infrastructure security across the US.

The risk to such systems has increased as they’ve acquired connectivity. This is increasingly important from an operational perspective, especially with many employees working remotely, but also opens the door to remote attackers.

Patching can also be problematic in these industrial environments as control systems are business-critical and therefore difficult to take offline while updates are tested.

Among the OMG DDS vulnerabilities highlighted by CISA were stack- and heap-based buffer overflow, amplification, write-what-where condition, and improper handling of syntactically invalid structure/length parameter inconsistency.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

FBI Fixes Misconfigured Server After Hoax Email Alert

FBI Fixes Misconfigured Server After Hoax Email Alert

The FBI has fixed a misconfigured web portal that allowed hacktivists to send thousands of fake emails to recipients.

News emerged over the weekend that individuals were receiving emails purporting to come from the Department of Homeland Security (DHS) Network and Analysis Group, but which had been sent from a @ic.fbi.gov account.

According to screenshots shared on Twitter, they warned of “exfiltration of several of your virtualized clusters in a sophisticated chain attack” — blaming a noted security researcher for the ‘attack.’

In an update on Sunday, the Feds claimed a software configuration error allowed the actor to temporarily hijack the agency’s Law Enforcement Enterprise Portal (LEEP) to send the emails.

“LEEP is FBI IT infrastructure used to communicate with our state and local law enforcement partners. While the illegitimate email originated from an FBI-operated server, that server was dedicated to pushing notifications for LEEP and was not part of the FBI’s corporate email service,” it explained.

“No actor was able to access or compromise any data or PII on the FBI’s network. Once we learned of the incident, we quickly remediated the software vulnerability, warned partners to disregard the fake emails, and confirmed the integrity of our networks.”

The scam spam run appears to have been an attempt to troll security researcher Vinny Troia, claiming that he was responsible for the non-existent attacks and colluded with extortion gang TheDarkOverlord.

Troia shared screenshots indicating that the weekend spam run was likely the work of an individual linked to the @pompompur_in Twitter account. 

In one exchange of messages he shared, the Twitter user expressed dismay that Troia’s account had accrued more followers because of the incident.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Book Sale: Click Here to Kill Everybody and Data and Goliath

For a limited time, I am selling signed copies of Click Here to Kill Everybody and Data and Goliath, both in paperback, for just $6 each plus shipping.

I have 500 copies of each book available. When they’re gone, the sale is over and the price will revert to normal.

Order here and here.

Please be patient on delivery. It’s a lot of work to sign and mail hundreds of books. And the pandemic is causing mail slowdowns all over the world. I’ll send them out as quickly as I can, but I can’t guarantee any particular delivery date. Also, signed but not personalized books will arrive faster.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cloud API Services, Apps and Containers Will Be Targeted in 2022

McAfee Enterprise and FireEye recently teamed to release their 2022 Threat Predictions. In this blog, we take a deeper dive into cloud security topics from these predictions focusing on the targeting of API services and apps exploitation of containers in 2022.

5G and IoT Traffic Between API Services and Apps Will Make Them Increasingly Lucrative Targets

Recent statistics suggest that more than 80% of all internet traffic belongs to API-based services. It’s the type of increased usage that grabs the attention of threat developers hunting for rewarding targets.

Feature-rich APIs have moved from being just a middleware to applications and have evolved to become the backbone of most modern applications that we consume today. Examples include:

  • 5G mobile applications – 5G connectivity and deployment of IoT endpoints have increased dramatically providing higher capacity for broader connectivity needs.
  • Internet of Things – More than 30.9 billion IoT devices are expected to be in use worldwide by 2025. The industrial IoT market was predicted to reach $124 billion in 2021
  • Dynamic web-based productivity suites – Global cloud-based office productivity software market is expected to reach $50.7 billion by 2026

In most cases, attacks targeting APIs go undetected as they are generally considered as trusted paths and lack the same level of governance and security controls.

The following are some of the key risks that we see evolving in the future:

  1. Misconfiguration of APIs resulting in unwanted exposure of information.
  2. Exploitation of modern authentication mechanisms such as Oauth/Golden SAML to obtain access to APIs and persist within targeted environments.
  3. Evolution of traditional malware attacks to use more of the cloud APIs, such as the Microsoft Graph API, to land and expand. We have already seen evidence of this in the SolarWinds attack as well as other threat actors such as APT40/ GADOLINIUM.
  4. Potential misuse of the APIs to launch attacks on enterprise data, such as ransomware on cloud storage services like OneDrive, etc.
  5. The usage of APIs for software-defined infrastructure also means potential misuse leading to complete infrastructure takeover or shadow infrastructure being created for malicious purposes.

Gaining visibility into application usage with the ability to look at consumed APIs should be a priority for organizations, with the goal of ultimately having a risk-based inventory of accessed APIs and a governance policy to control access to such services. Having visibility of non-user-based entities within the infrastructure such as service accounts and application principles that integrate APIs with the wider enterprise eco-system is also critical.

For developers, developing an effective threat model for their APIs and having a Zero Trust access control mechanism should be a priority alongside effective security logging and telemetry for better incident response and detection of malicious misuse.

Expanded Exploitation of Containers Will Lead to Endpoint Resource Takeovers

Containers have become the de facto platform of modern cloud applications. Organizations see benefits such as portability, efficiency and speed which can decrease time to deploy and manage applications that power innovation for the business. However, the accelerated use of containers increases the attack surface for an organization. Which techniques should you look out for, and which container risk groups will be targeted? Exploitation of public-facing applications (MITRE T1190) is a technique often used by APT and Ransomware groups. MITRE T1190 has become a common entry vector given that cyber criminals are often avid consumers of security news and are always on the lookout for a good exploit. There are numerous past examples in which vulnerabilities concerning remote access software, webservers, network edge equipment and firewalls have been used as an entry point.

The Cloud Security Alliance (CSA) identified multiple container risk groups including:

  • Image risks
    • vulnerabilities
    • configuration defects
    • embedded malware
    • embedded clear text secrets
    • use of untrusted secrets
  • Orchestrator
    • unbounded administrative access
    • unauthorized access
    • poorly separated inter-container network traffic
    • mixing of workload sensitivity levels
    • orchestrator node trust
  • Registry
    • insecure connections to registries
    • stale images in registries
    • insufficient authentication and authorization restrictions
  • Container
    • vulnerabilities within the runtime software
    • unbounded network access from containers
    • insecure container runtime configurations
    • app vulnerabilities
    • rogue containers
  • Host OS Component
    • large attack surface
    • shared kernel
    • improper user access rights
    • host file system tampering
  • Hardware

How do you protect yourself? Recommended mitigations include bringing security into the DevOps process through continuous posture assessment for misconfigurations, checks for integrity of images, and controlling administrative privileges. Use the Mitre ATT&CK Matrix for Containers to identify gaps in your cloud security architecture.

The post Cloud API Services, Apps and Containers Will Be Targeted in 2022 appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains