SASE, Cloud Threats and MITRE

As you know, McAfee Enterprise’s MVISION Unified Cloud Edge (UCE) was the was the first of all the SASE vendors to implement the MITRE ATT&CK Framework for Cloud last year. An important aspect of Gartner’s SASE Framework (link) is the ability for effective Threat Protection and Resolution in the Cloud. MVISION UCE takes this to the next level – the product takes a multi-layered approach to cloud threat investigation that can speed your time to detect adversary activity in your cloud services, identify gaps, and implement targeted changes to your policy and configuration.

As a quick refresher, the MITRE Att&CK Matrix represents the relationship between attacker Tactics and Techniques:

  • Tactics. A tactic describes the objective, or why the adversaries are performing the attack. In the ATT&CK Matrix, the table header represents tactics.
  • Technique. A technique describes how adversaries achieve their tactical objectives. For example, what are the various technical ways performed by attackers to achieve the goal? In the ATT&CK Matrix, the table cell represents techniques.

This Dashboard is available within the MVISION Cloud console by accessing the Dashboards > MITRE Dashboard link

Ever since the launch of this truly differentiated product offering, we have seen a tremendous amount of interest and adoption of this feature within our existing customers. Over the past few months, we have continued to make significant enhancements as part of our MITRE Dashboard.

In this post, I shall summarize some of the significant highlights that we have introduced in the past few releases:

Executive Summary Section

The Executive Summary displays an at-a-glance view of the current count of Threats, Anomalies, Incidents, types of incidents, and Detected Techniques with severity.

Flexible Filters

To suit the needs of the different teams that would be using the MVISION Dashboard, we now have the ability to filter the MITRE Dashboard by using a variety of facets:

  • Service Name. The name of the cloud service.
  • Threat Type. The name of the threat type.
  • Status. The MITRE Threat statuses available are:

    • Executed Threat. Threats that caused risk to your cloud service security.
    • Potential Threat. Threats that have the potential to cause risk to your cloud service security. It is recommended to look into the Potential Threats to reduce the impending risk.
  • Top 20 Users. Top 20 users who are impacted by the attacks.

Detected Techniques – Risk and Drilldown

When an incident is detected for a technique in MVISION Cloud, a severity is computed. The detected techniques are categorized based on the severity of the incidents. Each detected technique is interactive and leads to more detailed explanations.

To view the details of the detected techniques:

  1. Click any technique on the ATT&CK Matrix table to view the Technique Cloud Card. For example, you can click one of the techniques under the Initial Access category such as Trusted Relationship to learn how an attacker gained access to an organization’s third-party partners’ account and shows the details of compromised Connected Apps.
  2. Next, click the Connected Apps Mini Card to view an extended cloud card that displays the restricted details of Connected Apps.
  3. Then click the link to the specific restricted Connected App to see an extended view of the compromised Connected Apps incident.
  4. Info severity details allow you to investigate and apply a remediation action. As a remediation action, select and assign the Owner and Status from the menu.

With McAfee Enterprise, threat investigation isn’t just for one environment – it is for all of your environments, from cloud to endpoint to your analytics platforms. With MVISION CloudMVISION EDR, and MVISION Insights, your enterprise has an extended detection and response (XDR) platform for the heterogenous attacks you face today.

 

MITRE ATT&CK® as a Framework for Cloud Threat Investigation

Want to learn more about how you can leverage MITRE ATT&CK to extend your detection and response capabilities to the cloud?

Download Now

The post SASE, Cloud Threats and MITRE appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Rights Group Advises Afghans to Delete Data

Rights Group Advises Afghans to Delete Data

A human rights group based in the United States is encouraging Afghans to delete their data to prevent the Taliban from using it against them.

The Deobandi Islamist religious-political movement and military organization seized control of Afghanistan on August 15, two decades after they were removed from power by US-led forces.

With the official American mission to evacuate US citizens and Afghan allies from Afghanistan set to end tomorrow, Human Rights First is advising Afghans who remain in the country to erase their digital footprints.

The group published a Farsi-language version of its guide on how to delete digital history – produced last year to aid activists in Hong Kong – and shared advice on how to evade biometrics.

Welton Chang, chief technology officer at Human Rights First, told Reuters that in the most “dire circumstance,” the Taliban could use Afghans’ data to target those who had worked with the previous government, its security forces, and its foreign allies.

“We understand that the Taliban is now likely to have access to various biometric databases and equipment in Afghanistan,” the group wrote on Twitter on Monday.

“This technology is likely to include access to a database with fingerprints and iris scans and include facial recognition technology.”

On August 25, civil society groups, including Access Now, the Commonwealth Human Rights Initiative, Unwanted Witness and Electronic Frontier Foundation, issued an open statement calling for “an urgent safeguard of digital identity and biometric databases created in Afghanistan by development assistance missions, foreign governments previously aiding Afghan authorities, humanitarian actors, aid agencies, and the private sector vendors whose tools have been deployed to ensure they are not misused against people.”

According to the statement there are at minimum three digital identity systems known to have been in use recently in Afghanistan, including the e-Tazkira electronic national identity card system, and an Afghanistan Automated Biometric Identification System maintained by the Afghan Ministry of the Interior with support from the US government.

The third – the US military “Handheld Interagency Identity Detection Equipment” – were seized by the Taliban earlier this month along with the biometric data it stores.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Cyber-thieves Hit DeFi Platform Again

Cyber-thieves Hit DeFi Platform Again

A lending-focused decentralized finance platform has lost millions of dollars’ worth of AMP tokens and crypto-currency after falling victim to a second flash loan attack.

In a flash loan attack, a cyber-thief takes out a loan that requires no collateral – a flash loan – and uses it to manipulate and exploit the markets for financial gain. The criminal uses the capital that they’ve borrowed and pays it back in the same transaction.  

Cyber-thieves drained DeFi protocols Cream Finance and Alpha Finance of funds totaling $37.5m back in February. Now Cream Finance has lost millions of AMP tokens and more than a thousand ether worth over $25m in a similar smart-contract exploit. 

The latest flash loan attack was first reported by PeckShield on social media on Monday. Researchers at the blockchain security firm became suspicious when they came across Ethereum (ETH) records revealing that at least $6m had been drained at 5:44 UTC.

The theft was confirmed by Cream Finance on Monday via a Tweet that read: “C.R.E.A.M. v1 market on Ethereum has suffered an exploit, resulting in a loss of 418,311,571 in AMP and 1,308.09 in ETH, by way of reentrancy on the AMP token contract.”

The platform went on to say that they had “stopped the exploit by pausing supply and borrow on AMP” and that “no other markets were affected.”

According to Coinspeaker, the flash loan attack occurred in the early morning of August 30. It may have involved two cyber-thieves and a total of seventeen transactions.

In May, DeFi yield farming aggregator and optimizer for Binance Smart Chan (BSC) and ETH, Pancakebunny, lost close to $3m in a flash loan attack. 

Announcing the attack on Twitter, the company said: “Attention Bunny Fam. Our project has suffered a flash loan attack from an outside exploiter. We will be posting a postmortem, in-depth analysis, but for the time being, we would like to update the community as to how this happened.”

Around a week later, a flash loan attack on Binance Smart Chain DeFi project Bogged Finance saw $3m exploited.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US DOJ Announces Cyber Fellowships

US DOJ Announces Cyber Fellowships

New positions are being created at the United States Department of Justice (DOJ) with the intention of helping prosecutors and attorneys handle emerging national security threats.

The positions are part of a new Cyber Fellowship program, announced by Deputy Attorney General Lisa Monaco on Friday. The fellowship program will be coordinated by the Criminal Division’s Computer Crime and Intellectual Property Section.

In May, Monaco ordered a comprehensive cyber review of the Department of Justice with the purpose of developing actionable recommendations to improve and increase the department’s efforts against digital threats.

The suggestion to create a Cyber Fellowship program is one of the actionable recommendations to have emerged so far from this ongoing 120-day review.

Monaco said attorneys and prosecutors needed to have training if they were to stand a chance against future threat actors. 

“As we have witnessed this past year, cyber threats pose a significant and increasing risk to our national security, our economic security, and our personal security,” said Monaco. 

“We need to develop the next generation of prosecutors with the training and experience necessary to combat the next generation of cyber threats. This Fellowship gives attorneys a unique opportunity to gain the well-rounded experience they need to tackle the full range of those threats.”

Applications to the three-year Cyber Fellowship will be accepted through the Justice Department’s Honors Program application portal. To be accepted into the program, applicants must be able to secure a Top Secret security clearance.

The training will take place in the Washington, DC, area, with fellows’ being given the chance to handle a broad range of cyber cases taken on by the department so they can develop a deep understanding of how the DOJ responds to both critical and emerging threats.

In a statement released Friday, the DOJ said: “Fellows can expect to investigate and prosecute state-sponsored cyber threats; transnational criminal groups; infrastructure and ransomware attacks; and the use of cryptocurrency and money laundering to finance and profit from cyber-based crimes.”

Fellows will rotate through multiple department components, including the Criminal Division, the National Security Division and the US Attorneys’ Offices, while completing their training.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

The Underground Economy: Recon, Weaponization & Delivery for Account Takeovers

In part one of a two-part series, Akamai’s director of security technology and strategy, Tony Lauro, lays out what orgs need to know to defend against account takeover attacks.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains