McAfee Enterprise & FireEye 2022 Threat Predictions

What cyber security threats should enterprises look out for in 2022?

Ransomware, nation states, social media and the shifting reliance on a remote workforce made headlines in 2021. Bad actors will learn from this year’s successful tactics, retool, and pivot them into next year’s campaigns wielding the potential to wreak more havoc in all our lives.

Skilled engineers and security architects from McAfee Enterprise and FireEye offer a preview of how the threatscape might look in 2022 and how these new or evolving threats could potentially impact the security of enterprises, countries, and civilians.

“Over this past year, we have seen cybercriminals get smarter and quicker at retooling their tactics to follow new bad actor schemes – from ransomware to nation states – and we don’t anticipate that changing in 2022,” said Raj Samani, fellow and chief scientist of the combined company. “With the evolving threat landscape and continued impact of the global pandemic, it is crucial that enterprises stay aware of the cybersecurity trends so that they can be proactive and actionable in protecting their information.”

Lazarus Wants to Add You as a Friend

Nation States will weaponize social media to target more enterprise professionals

By Raj Samani

We love our social media. From beefs between popstars and professional pundits, to an open channel to the best jobs in the industry.

But guess what?

The threat actors know this, and our appetite toward accepting connections from people we have never met are all part of our relentless pursuit of the next 1,000 followers.

A result of this has seen the targeting of executives with promises of job offers from specific threat groups; and why not? After all, it is the most efficient method to bypass traditional security controls and directly communicate with targets at companies that are of interest to threat groups. Equally, direct messages have been used by groups to take control over influencer accounts to promote messaging of their own.

While this approach is not new, it is nearly as ubiquitous as alternate channels. After all, it does demand a level of research to “hook” the target into interactions and establishing fake profiles are more work than simply finding an open relay somewhere on the internet. That being said, targeting individuals has proven a very successful channel, and we predict the use of this vector could grow not only through espionage groups, but other threat actors looking to infiltrate organizations for their own criminal gain.

Help Wanted: Bad Guys with Benefits

Nation states will increase their offensive operations by leveraging cybercriminals

By Christiaan Beek

With a focus on strategic intelligence, our team is not only monitoring activity, but also investigating and monitoring open-source-intelligence from a diversity of sources to gain more insights into threat-activities around the globe – and these include an increase in the blending of cybercrime and nation-state operations.

In many cases, a start-up company is formed, and a web of front companies or existing “technology” companies are involved in operations that are directed and controlled by the countries’ intelligence ministries.

In May 2021 for example, the U.S. government charged four Chinese nationals who were working for state-owned front companies. The front-companies facilitated hackers to create malware, attack targets of interest to gain business intelligence, trade-secrets, and information about sensitive technologies.

Not only China but also other nations such as Russia, North Korea, and Iran have applied these tactics. Hire hackers for operations, do not ask questions about their other operations if they do not harm the interests of their own country.
Where in the past specific malware families were tied to nation-state groups, the blurring starts to happen when hackers are hired to write code and conduct these operations.

The initial breach with tactics and tools could be similar as “regular” cybercrime operations, however it is important to monitor what is happening next and act fast. With the predicted increase of blurring between cybercrime and nation-state actors in 2022, companies should audit their visibility and learn from tactics and operations conducted by actors targeting their sector.

Game of Ransomware Thrones

Self-reliant cybercrime groups will shift the balance of power within the RaaS eco-kingdom

By John Fokker

For several years, ransomware attacks have dominated the headlines as arguably the most impactful cyber threats. The Ransomware-as-a-Service (RaaS) model at the time opened the cybercrime career path to lesser skilled criminals which eventually led to more breaches and higher criminal profits.

For a long time, RaaS admins and developers were prioritized as the top targets, often neglecting the affiliates since they were perceived as less skilled. This, combined with the lack of disruptions in the RaaS ecosystem, created an atmosphere where those lesser-skilled affiliates could thrive and grow into very competent cybercriminals, eventually with a mind of their own.

In a response to the Colonial Pipeline attack, the popular cybercrime forums have banned ransomware actors from advertising. Now, the RaaS groups no longer have a third-party platform on which to actively recruit, show their seniority, offer escrow, have their binaries tested by moderators, or settle disputes. The lack of visibility has made it harder for RaaS groups to establish or maintain credibility and will make it harder for RaaS developers to maintain their current top tier position in the underground.

These events undermine their trusted position. Ransomware has generated billions of dollars in recent years and it’s only a matter of time before some individuals who believe they aren’t getting their fair share become unhappy.

The first signs of this happening are already visible as described in our blog on the Groove Gang, a cyber-criminal gang that branched off from classic RaaS to specialize in computer network exploitation (CNE), exfiltrate sensitive data and, if lucrative, partner with a ransomware team to encrypt the organization’s network.

In 2022, expect more self-reliant cybercrime groups to rise and shift the balance of power within the RaaS eco-climate from those who control the ransomware to those who control the victim’s networks.

Ransomware For Dummies

Less-skilled operators won’t have to bend the knee in RaaS model power shift

By Raj Samani

The Ransomware-as-a-Service eco system has evolved with the use of affiliates, the middlemen and women that work with the developers for a share of the profits. While this structure was honed during the growth of GandCrab, we are witnessing potential chasms in what is becoming a not-so-perfect union.

Historically, the ransomware developers, held the cards, thanks to their ability to selectively determine the affiliates in their operations, even holding “job interviews” to establish technical expertise. As more ransomware players have entered the market, we suspect that the most talented affiliates are now able to auction their services for a bigger part of the profits, and maybe demand a broader say in operations. For example, the introduction of Active Directory enumeration within DarkSide ransomware could be intended to remove the dependency on the technical expertise of affiliates. These shifts signal a potential migration back to the early days of ransomware, with less-skilled operators increasing in demand using the expertise encoded by the ransomware developers.

Will this work? Frankly, it will be challenging to replicate the technical expertise of a skilled penetration tester, and maybe – just maybe – the impact will not be as severe as recent cases.

Keep A Close Eye on API

5G and IoT traffic between API services and apps will make them increasingly lucrative targets

By Arnab Roy

Threat actors pay attention to enterprise statistics and trends, identifying services and applications offering increased risk potential. Cloud applications, irrespective of their flavor (SaaS, PaaS, or IaaS), have transformed how APIs are designed, consumed, and leveraged by software developers, be it a B2B scenario or B2C scenario. The reach and popularity of some of these cloud applications, as well as, the treasure trove of business-critical data and capabilities that typically lie behind these APIs, make them a lucrative target for threat actors. The connected nature of APIs potentially also introduces additional risks to businesses as they become an entry vector for wider supply chain attacks.

The following are some of the key risks that we see evolving in the future:

1. Misconfiguration of APIs
2. Exploitation of modern authentication mechanisms
3. Evolution of traditional malware attacks to use more of the cloud APIs
4. Potential misuse of the APIs to launch attacks on enterprise data
5. The usage of APIs for software-defined infrastructure also means potential misuse.

For developers, developing an effective threat model for their APIs and having a Zero Trust access control mechanism should be a priority alongside effective security logging and telemetry for better incident response and detection of malicious misuse.

Hijackers Will Target Your Application Containers

Expanded exploitation of containers will lead to endpoint resource takeovers

By Mo Cashman

Containers have become the de facto platform of modern cloud applications. Organizations see benefits such as portability, efficiency and speed which can decrease time to deploy and manage applications that power innovation for the business. However, the accelerated use of containers increases the attack surface for an organization. Which techniques should you look out for, and which container risk groups will be targeted? Exploitation of public-facing applications (MITRE T1190) is a technique often used by APT and Ransomware groups. The Cloud Security Alliance (CSA) identified multiple container risk groups including Image, Orchestrator, Registry, Container, Host OS and Hardware.

The following are some of the key risks groups we anticipate will be targeted for expanded exploitation in the future:

1. Orchestrator Risks: Increasing attacks on the orchestration layer, such as Kubernetes and associated API mainly driven by misconfigurations.
2. Image or Registry Risk: Increasing use of malicious or backdoored images through insufficient vulnerability checks.
3. Container Risks: Increasing attacks targeting vulnerable applications.

Expanded exploitation of the above vulnerabilities in 2022 could lead to endpoint resource hijacking through crypto-mining malware, spinning up other resources, data theft, attacker persistence, and container-escape to host systems.

Zero Cares About Zero-days

The time to repurpose vulnerabilities into working exploits will be measured in hours and there’s nothing you can do about it… except patch

By Fred House

2021 is already being touted as one of the worst years on record with respect to the volume of zero-day vulnerabilities exploited in the wild. The scope of these exploitations, the diversity of targeted applications, and ultimately the consequences to organizations were all notable. As we look to 2022, we expect these factors to drive an increase in the speed at which organizations respond.

When we first learned in 2020 that roughly 17,000 SolarWinds customers were compromised and an estimated 40 were subsequently targeted, many reacted in shock at the pure scope of the compromise. Unfortunately, 2021 brought its own notable increase in volume along with uninspiring response times by organizations. Case in point: two weeks after Microsoft patched ProxyLogon they reported that 30K Exchange servers were still vulnerable (less conservative estimates had the number at 60K).

ProxyShell later arrived as Exchange’s second major event of the year. In August, a Blackhat presentation detailing Exchange Server vulnerabilities was followed the next day by the release of an exploit POC, all of which had been patched by Microsoft months earlier in April/May. This analysis of data captured by Shodan one week after the exploit POC was released concluded that over 30K Exchange servers were still vulnerable, noting that the data may have underrepresented the full scope (i.e., Shodan hadn’t had time to scan the full Internet). In summary: patched in the Spring, exploited in the Fall.

So, what can we take away from all of this? Well, attackers and security researchers alike will continue to hone their craft until weaponized exploits and POCs are expected within hours of vulnerability disclosure. In turn however, and largely driven by the increased consequences of compromise, we can also expect renewed diligence around asset and patch management. From identifying public facing assets to quickly deploying patches despite potential business disruption, companies will have a renewed focus on reducing their “time to patch.” While we will inevitably continue to see high-impact exploitations, the scope of these exploitations will be reduced as more organizations get back to the basics.

The post McAfee Enterprise & FireEye 2022 Threat Predictions appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Study Coordinator Falsified Clinical Trial Data

Study Coordinator Falsified Clinical Trial Data

A man from Colorado is facing a maximum prison sentence of 20 years after admitting to falsifying clinical trial data.

Duniel Tejeda, formerly of Miami, Florida, acted outside the law while employed as both a project manager and a study coordinator for clinical drug trials at Tellus Clinical Research, a medical clinic based in Miami.

On Tuesday, the 35-year-old Canon City, Colorado, resident pleaded guilty before United States District Judge Robert Scola Jr. of the Southern District of Florida to conspiracy to commit mail and wire fraud. 

As part of his plea agreement, Tejeda admitted that he entered into an arrangement with co-conspirators to deliberately distort data in medical records. The records that were manipulated by Tejeda were connected with clinical trials intended to evaluate a range of different medical conditions, including opioid dependency, irritable bowel syndrome and diabetic nephropathy. 

In a statement released October 26, the Department of Justice’s Office of Public Affairs said: “Among other things, Tejeda falsified data to make it appear as though subjects were participating in the trials when, in truth, they were not.”

United States Attorney Juan Antonio Gonzalez for the Southern District of Florida said that Tejeda’s actions had put consumers at risk.

“The public relies on the accuracy and honesty of clinical trial data,” said Gonzalez. “Falsifying clinical data not only violates the public’s trust, it also endangers the safety of consumers.”

Catherine Hermsen, assistant commissioner for criminal investigations at the Food and Drug Administration’s (FDA) Office of Criminal Investigations, emphasized the importance of accurate clinical trial data. 

“FDA’s evaluation of a new drug begins with an analysis of reliable and accurate data from clinical trials,” said Hermsen. “Compromised clinical trial data could impact the agency’s decisions about the safety and effectiveness of the drug under review.”

Acting Assistant Attorney General Brian Boynton’s comments on the case imply that Tejeda’s actions were motivated by financial greed.

“The defendant’s conduct put profits before public health,” said Boynton. “The Justice Department will continue to work with its partners at the Food and Drug Administration to investigate and prosecute anyone who engages in this conduct.”

A sentencing hearing for Tejeda has been scheduled for January 20, 2022.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Almost All US Organizations Experienced a Cyber Event in the Past Year

Almost All US Organizations Experienced a Cyber Event in the Past Year

Almost all (98%) US-based organizations experienced at least one cyber event in the past year, according to Deloitte’s 2021 Future of Cyber Survey. This compares to 86% of non-US organizations.

The study, which surveyed 577 C-suite executives worldwide on their organization’s cybersecurity programs, also found that a huge proportion (86%) of US companies faced increased cyber-threats due to COVID-19. Interestingly, a significantly lower proportion (63%) of non-US executives reported experiencing an increased rate of attacks during the pandemic.

US executives also revealed a wide range of business impacts arising from cyber incidents or breaches in the past year. These included operational disruption (28%), share price drop (24%), leadership change (23%), intellectual property theft (22%) and loss of consumer trust (22%).

Despite this, 14% of US executives admitted their organization has no cyber-threat defense plans, which compares to just 6% of non-US executives.

According to the survey, the three biggest barriers to US organizations’ cybersecurity management programs were increases in data management, perimeter and complexities (38%), inability to match rapid technological changes (35%) and a need for better prioritization of cyber-risk across the enterprise (31%).

Another major security challenge for US companies is recruitment, with 31% of US executives stating they cannot attract or retain cyber talent. This compares to just 16% of non-US companies.

Surprisingly, the respondents considered the unintended actions of well-meaning employees (28%) to be the biggest cyber threat to US organizations. This was ranked above phishing, malware or ransomware (27%). Yet, despite this, 15% of US executives admitted their organization has no way to detect or mitigate employee cyber risk indicators.

The report also revealed that cybersecurity is a bigger boardroom issue at US firms compared to their non-US counterparts. For example, nearly all (96%) of US executives said cybersecurity is on the board’s agenda more than once a year, which compares to 88% for non-US executives.

Commenting on the findings, Deborah Golden, US Cyber & Strategic Risk leader for Deloitte Risk & Financial Advisory, said: “No CISO or CSO ever wants to tell organizational stakeholders that efforts to manage cyber risk aren’t keeping up with the speed of digital transformations made, or bad actors’ improving tactics.

“Aggressive organizational digital transformations and continued remote work for some seem to be shining more of a spotlight on the human side of cyber events – both the cyber talent gap and the potential risk well-meaning employees can pose. We see leading organizations turning to advanced technologies to help bridge those gaps.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Global Security Skills Shortage Falls to 2.7 Million Workers

Global Security Skills Shortage Falls to 2.7 Million Workers

The global cybersecurity skills shortage has fallen for the second consecutive year, but the size of the workforce is still 65% below what it needs to be, according to the latest figures from (ISC)2.

The non-profit accreditations body’s 2021 (ISC)2 Cybersecurity Workforce Study was compiled from interviews with 4,753 cybersecurity professionals and IT workers who dedicate at least 25% of their time to security tasks.

It revealed the shortfall of skilled workers in the industry had sunk from 3.12 million last year to 2.72 million. That’s down in part to 700,000 new entrants joining the sector since 2020 and lower demand for workers from APAC, where a slower economic recovery impacts small businesses and those in the IT services sector.

However, despite the global workforce growing to nearly 4.2 million, there are several persistent causes for concern.

APAC has the most significant regional workforce gap despite faltering demand, at 1.42 million, while the workforce gap in every other region increased since last year. It’s now around 402,000 in North America and 199,000 in Europe, including 33,000 in the UK.

This can have a real impact on cyber-risk levels in organizations. According to respondents, staff shortages can mean more chance of misconfigured systems, patching delays, process oversights, rushed deployments, sub-par threat detection and response, and less time for proper risk assessments.

A quick look at the areas where industry professionals seek qualifications shows where demand is strongest. Some 40% cited cloud computing security, nearly double most of the other areas of competence.

Fortunately, organizations are taking some steps to alleviate the impact of shortages. These include training (36%), provision of more flexible working (33%) and investing in diversity, equity and inclusion (DEI) initiatives (29%). Others cited the use of cloud service providers (38%), automation of manual tasks (37%) and getting staff involved earlier in third-party relationships (32%).

However, it’s still not enough, according to Clar Rosso, CEO of (ISC)².

“Any increase in the global supply of cybersecurity professionals is encouraging, but let’s be realistic about what we still need and the urgency of the task before us,” she argued.

“The study tells us where talent is needed most and that traditional hiring practices are insufficient. We must put people before technology, invest in their development and embrace remote work as an opportunity. And perhaps most importantly, organizations must adopt meaningful diversity, equity and inclusion practices to meet employee expectations and close the gap.”

A record 77% of respondents reported they are satisfied or extremely satisfied with their jobs – and well they might be, given that average salaries continue to climb. In the US, the pre-tax figure is $90,900 – up from $83,000 in 2020.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

GCHQ Boss: Ransomware Has Doubled in a Year

GCHQ Boss: Ransomware Has Doubled in a Year

The volume of ransomware attacks on UK organizations has doubled over the past year, a British spy chief has warned.

Director of GCHQ, Jeremy Fleming, reportedly made the remarks at the Cipher Brief annual threat conference yesterday.

“I think that the reason [ransomware] is proliferating — we’ve seen twice as many attacks this year as last year in the UK — is because it works. It just pays. Criminals are making very good money from it and are often feeling that that’s largely uncontested,” he said, according to The Guardian.

“In the shorter term we’ve got to sort out ransomware, and that is no mean feat in itself. We have to be clear on the red lines and behaviors that we want to see, we’ve got to go after those links between criminal actors and state actors.”

Fleming’s words echo those of his counterpart in GCHQ spin-off the National Cyber Security Centre (NCSC), Lindy Cameron.

She has warned UK organizations that ransomware represents their biggest immediate threat on multiple occasions.

The country has not suffered a major incident on the scale of the Colonial Pipeline or Kaseya ransomware breaches, which both had large-scale repercussions across society, since WannaCry struck in 2017.

However, there have been countless smaller victims, with those in the education sector and local government particularly severely hit.

Tony Pepper, CEO of Egress, argued that organizations of all sizes could become victims of ransomware.

“With ransomware incidents against UK businesses doubling in the space of a year, now is the time for organizations to ramp up their defenses,” he added.

“Over 90% of malware, including ransomware, is delivered via email — so it’s vital that organizations are aware of the threat posed by phishing in facilitating these attacks.”

Security vendor Emsisoft claims to have found vulnerabilities in around a dozen ransomware variants, enabling the firm to help victims recover their files without paying their attackers. However, this will first require notifying the authorities, which some organizations are still reluctant to do.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

BEC Costs UK Firms £140M Over Past Year

BEC Costs UK Firms £140M Over Past Year

Reported business email compromise (BEC) incidents have hit 4600 cases over the past 12 months, costing individuals and businesses £138m in losses, according to new figures from the UK’s National Economic Crime Centre (NECC).

The government body is working with the National Crime Agency (NCA), City of London Police, banking group UK Finance and fraud prevention non-profit Cifas on a new campaign to raise awareness of the crime, also dubbed “mandate fraud” or “payment diversion fraud.”

It claimed that the average amount lost over those 4600 cases was £30,000, with criminals typically impersonating others and creating or amending invoices to trick victims into diverting money to accounts under their control.

Often, legitimate email accounts are hijacked via phishing or impersonated using techniques like typosquatting to add legitimacy to the money transfer request.

The NECC claimed that spikes in fraud usually occur in March and November, to coincide with financial year-ends.

“Payment diversion fraud is increasing, and it is vital that people are alive to the threat. Small and medium-sized businesses are most at risk due to less comprehensive IT security, but these criminals will also target home-buyers due to the scale of the transactions,” said NECC fraud threat lead, Jon Shilland.

“Whenever you are making a payment to a supplier or your solicitor in the case of a house purchase, you should be highly suspicious of any change in account details or new instructions. Always check with a trusted known contact, and if you have any doubt do not transfer the money.”

BEC has been the highest-earning cybercrime type for the past two years, according to the FBI.

According to the Feds’ annual Internet Crime Report, victims lost almost $1.9bn last year off the back of around 19,300 reported incidents. That amounts to nearly half the $4.2bn total lost to cybercrime during the period.

Tell-tale signs of BEC to look out for include an urgent request to transfer money, new payment details for a supplier, and spelling mistakes or inconsistent language used in the sender’s email.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

SquirrelWaffle Loader Malspams, Packing Qakbot, Cobalt Strike

Say hello to what could be the next big spam player: SquirrelWaffle, which is spreading with increasing frequency via spam campaigns and infecting systems with a new malware loader.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Public Clouds & Shared Responsibility: Lessons from Vulnerability Disclosure

Much is made of shared responsibility for cloud security. But Oliver Tavakoli, CTO at Vectra AI, notes there’s no guarantee that Azure or AWS are delivering services in a hardened and secure manner.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains