Showing posts with label cloud workload. Show all posts
Showing posts with label cloud workload. Show all posts

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Monday, December 2, 2019

TrueFort Fortress XDR delivers application detection and response platform to secure applications and cloud workloads

TrueFort announced on Monday TrueFort Fortress XDR, its latest approach to data center and cloud workload protection that replaces the traditional code and infrastructure view of application security in enterprise runtime environments. 

Fortress XDR detects and protects against elusive threats by analyzing and profiling business application logic and unifying telemetry from AppSec, infrastructure security and operational data sources in a single console. This enables organizations to more completely visualize their applications with both static and dynamic information, and constantly identify and adapt to new risks using a whitelist approach with tunable, auto-generated policies.


To enable organizations to achieve full, 360-degree visibility into the application context with immediate value while maximizing investments in already deployed security products, TrueFort also announced the TrueFort Fortified open ecosystem, which opens access for customers, providers and third-party security vendors to the Fortress XDR REST-APIs for bi-directional integration. It also allows customers to use the TrueFort agent or opt to “bring-their-own-agent” for substantial time and cost savings at organizations that have successful investments in platforms like CrowdStrike Falcon.

“As an inaugural vendor and Partner-of-the-Year in our CrowdStrike Store, the integrated TrueFort solution aligns well with our unique platform approach and is already generating a lot of interest from large enterprises,” said Mike Carpenter, CrowdStrike President, Global Sales & Field Operations. “A number of our customers using and evaluating the solution have added comprehensive application-layer visibility, policy automation and monitoring to tens of thousands of Falcon-protected workloads within just days.”

To extend visibility and security into containerized applications, Fortress XDR now supports Kubernetes and the Istio standard, and deploys as a daemon set within nodes rather than as a privileged container. This enables customers to secure applications running in practically any environment.

For threat hunting, incident response and investigations, the platform’s new Reporter module provides on-demand playback of both real-time and historical data that can span minutes, months or even years – down to the process, network, identity and time levels. These capabilities improve time-to-detection, response and compliance.

“Until now, application security has been a one-dimensional discipline,” said Sameer Malhotra, founder and chief executive officer of TrueFort. “With Fortress XDR, organizations have the end-to-end visibility into application behaviors, in context and in real-time, needed to detect anomalies and block malicious execution events.”

TrueFort Fortress XDR is offered as a subscription and available immediately from TrueFort and its business partners worldwide, including the CrowdStrike Store. TrueFort customers receive 24x7 support and have automatic access to the platform APIs, while interested vendors, resellers and providers may contact TrueFort to request access via the company website.

Wednesday, October 30, 2019

Druva extends platform with comprehensive protection and automation for cloud workloads; provides support for Slack and Microsoft teams

Druva Inc. announced new capabilities providing coverage for cloud workloads, strategic integrations and automated functionality, to accelerate any enterprises’ journey to the cloud. The updates include support for Slack and Microsoft Teams, new advanced backup, recovery and global policy capabilities for AWS workloads, as well as integrations with ServiceNow, Splunk and Okta. 

The latest enhancements ensure greater control and protection of data residing across these new cloud workloads, while also making it accessible for critical business insights and analytics.


Druva is bringing enterprises a comprehensive and scalable way to seamlessly protect and utilize data in the same place it’s being created. These new features and support continue Druva’s promise to deliver leading technology for protecting and managing data, no matter where it resides - endpoints, data center or cloud workloads.

Customers can now preserve the integrity of communication / conversations on the platform for e-discovery, compliance and legal hold requirements. Added to Druva’s support for Microsoft Office 365, delivers data protection for Teams workloads and enabling admins to seamlessly and quickly recover from scenarios where data gets deleted due to accidental deletion/rogue user or in the event of a ransomware attack.

The new platform offers automated disaster recovery that simplifies setup of disaster recovery (DR) plans within AWS environments with the ability to create cross-account DR plans as well as cross-region support. Additionally, Amazon Relational Database Service (RDS) resources can also now be included as part of DR plans, and users can also automate the creation of production-like environments for Dev/QA purposes with a single click.


Splunk users can integrate with Druva’s protected data and enable a complete visibility, security and analysis across all enterprise and IoT data assets. This is also available via Splunk’s native application. A RESTful API-based integration (or via ServiceNow’s native application) helps reduce IT operational overhead by enabling ServiceNow users to report on IT tickets originating from Druva and get end-to-end visibility across all enterprise data assets.

The offering also assists automated user on-boarding and off-boarding without the need for any on-premises components and mitigate configuration needs with Druva’s pre-configured app on Okta Integration Network. Druva is now also part of the Okta Identity Network.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...