#BHEU: Ransomware is The New Terrorism, Contends Cyber Expert

#BHEU: Ransomware is The New Terrorism, Contends Cyber Expert

“The continued survival and future of your organization cannot be based upon negotiations with criminals,” was the stark message given by Tanner Johnson, principal analyst of OMDIA, during his session at Black Hat Europe 2021.

Titled ‘Ransomware: The New Terrorism,’ the session was dedicated to ransomware and covered its history, the evolution of the threat, response challenges, escalation to terrorism and mitigation practices.

History of Ransomware (As We Know It)

Johnson’s analysis of the history of ransomware (as we know it) started on the concept of ransom, one with a long history spanning the globe and coverings thousands of years: “criminals hold an entity hostage to extort money for its release.” Once stolen, “the criminals provide an official request outlining their demands for the release of said items,” explained Johnson. While ransoms have historically been tied to physical items of value, “they demanded physical logistics.” Focusing instead on today, as we have transitioned into an information-driven society, our dependence on access to data has only burgeoned.

Evolution of The Threat

“How, though, has the threat evolved?” pondered Johnson. “The proof of concept shown from the AIDS Trojan illustrated just how viable this criminal tactic was,” remarked Johnson. As encryption technology evolved, adversaries designed their own advanced ransomware toolkits. “The inception of cryptocurrency technology ushered in the modern ransomware challenges we face today.”

As many know, within 20 years of its first use, criminal ransomware campaigns were regularly making international headlines. This is when the advancement of ransomware as a service utilizing premade toolkits “began to take shape.”

Response Challenges

When focusing on ransomware, many question why responding to ransomware appears to be so challenging. “The severity of the problem has been overlooked or dismissed by organizations within every market since its creation,” rued Johnson. He continued that a central problem is visibility, “which is a crucial component to any security strategy.” Worryingly, “many organizations remain blind.”

Because of this challenge, Johnson claimed that it’s incumbent on organizations to take the initiative to “discover, identify and define their own respective ‘crown jewels’” so they can properly draft an effective incident response.

“The inception of cryptocurrency technology ushered in the modern ransomware challenges we face today”Tanner Johnson

The chaos surrounding the COVID-19 pandemic has provided “countless vectors of potential compromise, including hybrid working and an increased attack surface,” commented Johnson, and organizations operating in markets deemed by adversaries as “high value” have become primary targets.

Recent events have also brought the threat of ransomware to the forefront, and most organizations are simply “unprepared.”

Escalation to Terrorism

“Today, ransomware has escalated to the point of being terrorism,” warned Johnson. Indeed, the US Department of Justice (DOJ) recently chose to elevate ransomware to the level of terrorism. This decision has “strong implications”, according to Johnson, since victims will now have greater access to government resources. Furthermore, and a promising sign, the Biden administration has also taken steps to improve the nation’s overall cybersecurity posture.

Even with this new classification, “what practical steps should businesses follow when victims of ransomware attack?” asked Johnson.

Mitigation Practices

Effective data management is “vital” for proper defense, warned Johnson, which “requires implementing comprehensive controls throughout its lifecycle.” Organizations must know that the number of attack vectors available to criminals is growing and “require organizational diligence to address,” said Johnson.

Johnson pointed out that the chaos and panic created by ransomware attacks requires a strategic and orchestrated response, such as a disaster recovery plan. In addition to actions from the White House and the DOJ, “the Cybersecurity and Infrastructure Security Agency (CISA) has provided organizations with guidance.” Part of this guidance includes some general best practices to help organizations harden their defenses. Moreover, CISA recently released a Ransomware Readiness Assessment module for its Cyber Security Evaluation Tool.

Take Away Points for Organizations

Worryingly, until more organizations act on the severity of the threat, “consistent attacks are expected,” warned Johnson. “Whether organizations recognize themselves as targets is meaningless since criminals don’t discriminate.” Crucially, there are immediate steps businesses can take to mitigate the fallout should they become the victim of an attack. This includes using backups and following a cyber incident response plan. Additionally, there are several factors to consider before any organization decides to pay a ransom. “It’s vital to know that it isn’t guaranteed that encrypted or stolen data will be returned.” Johnson concluded that “the continued survival and future of your organization cannot be based upon negotiations with criminals.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#BHEU: Leveraging Behavioral Psychology to Improve Teamwork in Cybersecurity

#BHEU: Leveraging Behavioral Psychology to Improve Teamwork in Cybersecurity

Organizations should utilize behavioral psychology techniques to improve how computer security incident response teams (CSIRTs) operate, according to Mark Orlando, CEO of Bionic, and Daniel Shore, chief research officer of LeTS: Leadership & Effective Teamwork Strategies, during a session at Black Hat Europe 2021.

Orlando began by outlining the most significant teamwork issues seen in CSIRTs. These are:

  • The superhero problem: an overreliance on a few key individuals for thought leadership
  • The teamwork problem: too much focus on technical capabilities at the expense of working together internally and with other teams effectively
  • The firefighting problem: constantly having to adapt and respond to crises, therefore losing time to think strategically
  • The lone wolf problem: this is where personnel are motivated only to do their own work

At the heart of these problems is ‘ego-centrism,’ where attitudes of “I can do this on my own” are prevalent, according to Orlando. This is not the right approach in incident response, where “we are trying to solve some very difficult and complex problems.”

In addition, it is essential for CSIRTs to work with other parts of the organization, such as application teams and the business owner, to find a solution. “We don’t do what we do in a vacuum,” added Orlando.

Shore pointed out that ego-centrism arises from psychology – “as humans, we want to feel validated and that we are valuable,” he stated. However, regarding incident response, “it is no longer an option to work on your own and be most effective in that response.

The two speakers then shared details of research they had undertaken into teamwork within cybersecurity teams worldwide. Shore said they quickly realized that to drive interest in learning about teamwork in incident response, “you have to take a gamified approach to talking about the areas we want to work on.” The curriculum therefore has to be non-cybersecurity to ensure everyone is brought to an equal playing field.

Such an approach promotes “psychological safety,” whereby employees feel empowered to speak up and raise issues with anyone in their organization, regardless of position. This enables those in leadership roles (CISOs, CIOs, etc.) to gain insights and collaborate with the rest of the team more easily.

Orlando and Shore emphasized the need for frameworks to help CSIRTs structure their teamwork. “It’s really important to have a repeatable, structured way to facilitate that teamwork and to measure it in order to make it effective and have the team make the right decisions even when the leadership isn’t around,” explained Orlando.

“It’s really important to have a repeatable, structured way to facilitate that teamwork and to measure it in order to make it effective”Mark Orlando, CEO of Bionic

Another critical aspect is ensuring all members of a CSIRT “find joy in teamwork,” said Shore. In particular, gaining buy-in to the broader scope of goals and tasks of that team. Achieving this requires combining the three pillars – autonomy, belonging and competence – of individual motivation. This is designed to “cultivate that individuality within the team context.”

The speakers then outlined several case studies to tie these concepts into real-world scenarios. One of these came from Orlando’s own experience working in a 24/7 operations team. Here, a team had to be built very quickly while continuing their day-to-day operations. The situation was made especially challenging as the organization “was comprised of experts from all different disciplines,” making it difficult to tell individuals what they can and cannot do.

While there was lots of technical expertise within the team, there was a lack of understanding about who to communicate with in certain areas. Therefore, a framework was needed to demonstrate the situations when team members should engage with each other, when to share knowledge, and how to measure collaboration.

Shore provided an output of a mapping tool used to answer these questions, connecting people’s goals. “From a psychological standpoint, we really want to focus on making sure people have input to the goals that their setting, that they have an understanding of every goal in the eco-system, and also that they get to celebrate,” he outlined. This ensures everyone is connected to what the team is doing and feels they have contributed to successes.

Another mapping tool was used to show the different ways different teams interact during a cyber incident. This enables collaboration to occur most efficiently, ensuring the appropriate teams interact together at the right times. “Teamwork allows for efficiency if our teamwork is structured and intentional,” stated Shore.

Concluding, Shore said: “We’re leveraging the power ego-centrism here; let’s use it to our advantage. What information do I have that’s unique? What information do other team members have that’s unique that I know they have? If we talk about that, we’re making implicit information explicitly communicated.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Class Action Against Google Blocked

Class Action Against Google Blocked

A lawsuit accusing Google of unlawfully collecting iPhone users’ personal data was rejected today by the Supreme Court of the United Kingdom.

The case was brought against Google’s parent company, Alphabet, by Richard Lloyd, former director of consumer rights group Which? Lloyd claimed that Google used cookies to gather data on health, race, ethnicity, sexuality, and finance through Apple’s Safari web browser, regardless of whether users had selected the privacy setting “do not track.”

Lloyd alleged that between 2011 and 2012, Google secretly collected information about more than 5 million iPhone users, then exploited the data for commercial profit. The suit sought $4.3bn in compensation for British iPhone users whose data had allegedly been illegally tracked. 

In his judgement, Lord Leggatt said that Lloyd had sought compensation for millions of people without proof of damage. 

“The claimant seeks damages . . . for each individual member of the represented class without attempting to show that any wrongful use was made by Google of personal data relating to that individual or that the individual suffered any material damage or distress as a result of a breach,” it read.

“Without proof of these matters, a claim for damages cannot succeed.”

However, Leggatt said that Lloyd’s claim had a “real chance of success” if instead of framing it as a representative action, the claimant pursued it as an individual and calculated damages. 

This thin slither of hope didn’t go far in appeasing Lloyd, who said: “We are bitterly disappointed that the Supreme Court has failed to do enough to protect the public from Google and other Big Tech firms who break the law.”

Google said: “This claim was related to events that took place a decade ago and that we addressed at the time. People want to know that they are safe and secure online, which is why for years we’ve focused on building products and infrastructure that respect and protect people’s privacy.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#BHEU: How to Create a Safe and Democratic Digital Infrastructure

#BHEU: How to Create a Safe and Democratic Digital Infrastructure

Liberal nations must act now to ensure the digital ecosystem operates in a way that is conducive to democratic values. This was the message of Marrietje Schaake, international policy director at Stanford University’s Cyber Policy Center, speaking during the opening keynote session on day three of Black Hat Europe 2021.

She noted that most of the digital infrastructure is managed by the private sector, which has consequences from an accountability and freedom standpoint and cybersecurity. “Most digital infrastructure is now in the hands of private companies – it’s created, operated, protected by private companies, and I think that’s a problem,” commented Schaake.

A particularly pertinent example of how democratic norms are being eroded in the digital space is the practice of tech companies selling surveillance tools, such as Pegasus spyware, to authoritarian governments. These are subsequently used to attack fundamental liberal principles like press freedom and the right to assembly.

Currently, liberal governments are doing far too little to prevent this type of activity, and authoritarian nations are taking full advantage to suppress democratic values, according to Schaake. In fact, liberal governments often outsource offensive cyber tools themselves to target suspected criminals or terrorists, “making it harder for democratic states to condemn the use of NSO and other similar systems convincingly.” This is because they are “fostering the same businesses’ capacities and market share.”

Additionally, Western companies are often providing these types of technology to nefarious actors. Schaake expressed frustration at the “watering down” of the recently enacted EU Export Control Regulation, which partly aims to regulate the export of cyber-surveillance technologies.

As a result of these trends, “digitization is blurring the lines between authoritarian states and democratic ones.”

“Digitization is blurring the lines between authoritarian states and democratic ones”Marrietje Schaake

She pointed out that regarding physical warfare, there is democratic oversight in liberal nations; for example, a vote in a legislature to sanction military action. This at least ensures there is accountability for what occurs. However, no such process is in place regarding offensive cyber capabilities, such as spyware, as private companies operate it.

This is becoming an increasing problem, with digital technology and software spreading “to almost every part of our lives and economies.” As well as the democratic issues this raises, it also makes society more vulnerable to cyber-attacks, in Schaake’s view. This is because companies are not made accountable for vulnerabilities and other cybersecurity failings that lead to cyber-incidents.

She gave the example of the Colonial Pipeline ransomware attack earlier this year, which arose from an employee’s VPN credentials being compromised. She pointed out that the FBI actually assisted the company in making the ransom payment, which was even tax-deductible! This removes accountability and the incentives required to improve cybersecurity. In respect of Colonial Pipeline, Schaake said: “The public may never know what actually happened and how the attack could take place.”

To ensure the digital ecosystem is both more secure and adheres to democratic principles, Schaake outlined seven steps she would like liberal nations to adopt:

  1. Develop stronger transparency requirements – for example, showing which companies are selling offensive cyber tools to authoritarian nations and developing better information sharing between governments, intelligence agencies and tech companies.
  2. Ban the most harmful systems – Schaake advocated a ban on companies selling “invasive and harmful tools to the highest bidder,” such as Pegasus.
  3. Create better incentives to build safer products – Schaake said software companies are not properly incentivized to build safer software “because they don’t pay the cost of breaches.” There should be precise requirements for how to develop safer systems “and liability consequences when there is negligence.”
  4. Update requirements for critical organizations – Critical public sector organizations, like universities, schools and hospitals, “are often behind in terms of keeping their software and operating systems up to date,” according to Schaake. This provides numerous opportunities for exploitation for cyber-villains. Therefore, “we have to help public organizations to make the right decisions and be equipped to do so.”
  5. Enhance procurement rules – Schaake would like to see the stringent requirements placed on the financial sector regarding software procurement applied to other important industries. In other sectors, too often, we see that “vendors sell untested blueprints or hyped versions of their products, and that leaves the unaware customer too vulnerable for potential misuse.”
  6. Incentivize tech talent to join the public sector – Schaake noted that tech students generally seek jobs with big tech firms rather than government organizations due to the more significant opportunities in this path. As such, “we need specialized programs by governments and universities to help support and emphasize the importance of public interest technology,” as well as offer more attractive incentives to work in this area.
  7. 7. Democracies need to collaborate – Finally, Schaake highlighted the importance of democratic companies taking the lead and forging a framework “to create new rules and guidelines for independent oversight” of the digital space. 

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

#BHEU: Zero Trust Protects Against Ransomware, Claims Engineer

#BHEU: Zero Trust Protects Against Ransomware, Claims Engineer

“A zero trust architecture can protect against ransomware” was the resounding claim made by Ben Jenkins, senior solutions engineer at ThreatLocker, during a session at Black Hat Europe 2021.  

The session titled ‘Moving Beyond Threat Detection – A Look at The Future of Cybersecurity with Zero Trust,’ focused on the state of cybersecurity and how to protect against ransomware with a zero trust architecture.

The session began with a thorough exposition of software – the tagline being that its possibilities are “endless.” Additionally, “there is good software and bad software,” stressed Jenkins, and “yes, malware is just software.” Yet, malware is having a “devastating” impact on all sectors. “560,000 malware infections are found each day, attackers hit 1-4 businesses each day and there are over one billion pieces of malware in existence,” warned Jenkins. “The malicious possibilities are endless.”

Continuing his exposition, Jenkins highlighted early types of malicious software. “AIDS Trojan is one of the first documented versions of malware,” remarked Jenkins, which dates back to 1989. Floppy-disc-based, victims were forced to pay $189 to release their encrypted data.

“If we fast forward to today, malware looks very different,” rued Jenkins. He highlighted the WannaCry Attack, which has an estimated cost of £92m and resulted in 200 NHS hospitals being “severely affected,” going on to cripple one third of NHS trusts overall. “Another is the Conti Attack,” which occurred in May this year and resulted in significant disruption to the Irish health service provider, “with an estimated cost of €500m.” By September, 95% of services were back up and running. Worryingly, 5% of services are still down.

As of October 2021, businesses with 11-100 employees comprise 32% of ransomware victims, while businesses with 101 to 1500 comprise 30% of ransomware victims. “Ransomware attack vectors shift as new software vulnerability exploits abound.”

“Threat actors are innovating how they deliver malware,” stressed Jenkins. Examples listed include SolarWinds, Kaseya, rubber ducky attacks and exploiting vulnerabilities.

With all of this, “how can we solve the problem?” asked Jenkins. “There are solutions,” he continued, which focus on the human side, control side and detection side of a security stack. “Zero trust is that solution,” commented Jenkins, which is “primarily about least privilege.” Crucial constituents of a zero trust approach include application whitelisting, elevation control and storage control.

Overall, “the only way to offer a proper defense,” remarked Jenkins, is to “change the paradigm of endpoint security.”

Ransomware Facts:

  • The average ransomware payout is now £170,000
  • 77% of ransomware attacks involved the threat to leak exfiltrated data
  • The data will not be credibly destroyed
  • Ransomware attacks still disproportionally affect small businesses
  • Average 23 days of downtime

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Microsoft: Patch Zoho Bug Now to Stop Chinese Hackers

Microsoft: Patch Zoho Bug Now to Stop Chinese Hackers

Microsoft has warned that Chinese actors are actively exploiting a known Zoho vulnerability to target defense, education, consulting and IT sector organizations.

CVE-2021-40539 is found in Zoho ManageEngine ADSelfService Plus — a self-service password management and single sign-on solution from the online productivity vendor.

It’s a critical REST API authentication bypass which results in remote code execution, potentially allowing attackers to access and hijack victim organizations’ Active Directory and cloud accounts for advanced cyber-espionage and other ends.

“Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to DEV-0322, a group operating out of China, based on observed infrastructure, victimology, tactics, and procedures,” Microsoft explained in a blog post.

“MSTIC previously highlighted DEV-0322 activity related to attacks targeting the SolarWinds Serv-U software with 0-day exploit.”

It’s not thought to be the same state-sponsored campaign as the one which the Cybersecurity and Infrastructure Security Agency (CISA) warned about in a September 16 alert.

In fact, Microsoft first discovered the campaign on September 22, at around the same time as Palo Alto Networks, which claimed it had compromised at least nine organizations including some in the energy sector.

Following initial compromise, the threat actors installed either a Godzilla webshell or a new backdoor dubbed NGLite to run commands and move laterally while exfiltrating files of interest, the vendor claimed.

“Following initial exploitation of CVE-2021-40539 on a targeted system, DEV-0322 performed several activities including credential dumping, installing custom binaries, and dropping malware to maintain persistence and move laterally within the network,” Microsoft explained.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Over 80% of CNI Firms Have Been Breached in Past 36 Months

Over 80% of CNI Firms Have Been Breached in Past 36 Months

Most IT and security leaders in critical infrastructure (CNI) organizations are underestimating the scale of the cyber-threat, despite having suffered breaches over the past three years, according to Skybox Security.

Cybersecurity vendor, Skybox Security, polled 179 operational technology (OT) security decision-makers in the US, UK, Germany, and Australia with most hailing from companies with $1bn or more in revenue from the manufacturing, energy, and utility industries.

The study found that 73% of CIOs and CISOs are “highly confident” their organizations will not suffer an OT breach next year, despite 83% having suffered such an incident over the past 36 months.

Tellingly, just 37% of hands-on plant managers were similarly confident, highlighting the disconnect between perception and reality at a senior decision-making level.

A third (34%) of respondents also appeared to be over-relying on insurance as a security ‘strategy,’ claiming it is a sufficient solution.

However, some did recognize escalating cyber-threats. Two-fifths (40%) noted that supply chain/third-party network access is one of their top three security risks, but less than half (46%) said their organization has a third-party access policy applicable to OT. 

Silos and tech complexity also weighed heavily on respondents: 78% said multi-vendor environments make it more challenging to secure their organization and half (48%) complained of disjointed architecture across OT and IT environments.

A further 40% said IT-OT convergence was a top-three risk. As legacy OT technology is enhanced with connectivity, it becomes exposed to internet-based threats capable of exploiting unpatched systems. Patching can be problematic on OT kit as much of it is mission critical and there are compatibility issues with legacy apps and operating systems.

Skybox Security Research Lab threat intelligence lead, Sivan Nir, argued that new OT vulnerabilities were up 46% compared to the first half of 2020.  

“Despite the rise in vulnerabilities and recent attacks, many security teams do not make OT security a corporate priority. Why? One of the surprising findings is that some security team personnel deny they are vulnerable yet admit to being breached,” he added.

“The belief that their infrastructure is safe — despite evidence to the contrary — has led to inadequate OT security measures.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Europol Practices Post-Terror Incident Response

Europol Practices Post-Terror Incident Response

Global law enforcers, governments and the tech industry came together last week to practice their response to the hypothetical viral spread of terrorist content online following a serious attack.

The tabletop exercise, revealed this week, was organized by the European Commission and Europol, and featured global police, online service providers, the Global Internet Forum to Counter Terrorism (GIFCT), the Christchurch Call, the Aqaba Process and policy makers from across the globe.

It was designed to test the efficacy of the EU Crisis Protocol, created in 2019, to allow member states and online providers to respond in a rapid but coordinated way to dissemination of terrorist content, following a real-world attack.

It was formed in response to the aftermath of the Christchurch attack in 2019, which prompted a “Christchurch Call for Action.”

“Terrorist attacks in Christchurch, Halle and Conflans-Sainte-Honorine serve as strong reminders that the online dimension can be an integral part of a terrorist attack, with the aim of further spreading the messages and objectives of terrorists,” said Yolanda Gallego-Casilda Grau, EU Commission representative and head of the prevention of radicalisation unit.

“Our partnerships with tech companies facilitate the rapid assessment of the online impact of terrorist attacks and the secure and timely sharing of critical information necessary for effective crisis response.”

The exercise was hosted by Europol, with an added dimension being the need for stakeholders to respond rapidly without undermining civil liberties including individual data protection rights.

More broadly speaking, tabletop exercises are seen as a crucial component of any well-tested incident response plan.

“GIFCT’s Incident Response Framework streamlines how our tech company members can communicate and share situational awareness as an incident unfolds in order to identify any online dimension to an offline attack,” said GIFCT director of technology, Tom Thorley.

“In this inherently dynamic space, it’s critical to continue refining our efforts and how we engage with our partners, including through tabletop exercises like this one.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains