Showing posts with label data loss. Show all posts
Showing posts with label data loss. Show all posts

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Cohesity and HPE assist TEC Eurolab to maximize data security and resiliency, improve customer service

Cohesity announced Tuesday that TEC Eurolab has doubled its productivity and increased its revenues, after deploying a disruptive data management solution provided by Cohesity and HPE.

TEC Eurolab has seen major cost and efficiency benefits by using the joint Cohesity-HPE solution to enable intelligent file share services and enhance data security and resiliency. The solution, delivered by local systems integrator NETMIND, is now helping the company effectively serve customers across a multitude of sectors including aerospace and defense, automotive and motor racing, manufacturing, and biomedical industries.


The Cohesity-HPE joint solution for TEC Eurolab offers zero data loss and improved security, compliance and data integrity; 50 percent reduction in data retrieval time compared to previous solution; 100 percent improved production output across the Tomographic Center; 30 percent operating expense savings in reduced personnel time spent on data management; 20 percent capital expenses savings due to reduced burden on workstations; and offers quick and easy file search and recovery across multiple workstations with a single UI.

Founded in 1990, TEC Eurolab is a private corporation based in the province of Modena, Italy. TEC Eurolab is a prominent center of technical expertise and laboratory testing with the mission of improving the reliability of chemical, mechanical, and structural properties of products for its global customers, and providing specialised support and knowledge of materials, processes, and industry standards.


“The center can now double the number of analyses it performs each week and is able to deliver results to our customers faster with no performance bottlenecks,” said Marco Moscatti, board member and production director, TEC Eurolab.

Industrial tomography scanners deal with large, high-resolution 3D images, resulting in the center’s data growth of 50 percent per year. However, it has been challenged by legacy technology that couldn’t keep up with the increasing data volumes. The existing environment failed to efficiently and reliably process massive volumes of data.

The Tomographic Center used numerous workstations for file acquisition, 3D reconstruction and analysis. These workstations were processing many copies of the same data separately, slowing down operations and causing data loss, legal risks, and missed service level agreements. 

TEC Eurolab had a number of requirements, including a secure, central data store to ensure data integrity and predictable recovery, efficient file sharing, secure and reliable target storage for backup, non-disruptive scalability, and a seamless integration with its existing HPE environment.


Outstanding performance results from a pilot test driven by the software-defined data center specialist NETMIND led TEC Eurolab to choose Cohesity DataPlatform software on certified HPE Apollo r2200 Gen 10 servers as their preferred file share and scale-out target storage for backups.

With the new solution in place, data from all three types of workstations is written to the Cohesity cluster that acts as a central repository for acquisition, 3D reconstruction, and analysis data. All data resides on a Cohesity file share, powered by Cohesity SmartFiles —  intelligent file services built into the Cohesity DataPlatform — resulting in more efficient file sharing and faster recovery, all from a central management user interface (UI).

Additionally, with robust security and data resiliency provided by Cohesity DataPlatform, TEC Eurolab greatly reduced the risk of data being lost or compromised, and enhanced its ability to meet regulatory compliance.

“We have reduced staff operational time by 30 percent and significantly improved data resiliency with Cohesity. Best of all, we have doubled our production capacity and are able to meet customer SLAs without compromising security and compliance, which contributed in part to an increase in Tomographic Center revenues. We are now looking to further maximize these benefits across the organization by expanding Cohesity to other use cases such as integrated backup, recovery, and analytics,” said Moscatti.

“With the Cohesity-HPE joint solution, TEC Eurolab is getting the best of both worlds,” said Giovanni Golinelli, pre-sales manager and systems and storage architect, NETMIND. “They are now able to adhere to their customers’ strict security needs and industry regulatory requirements. They have an enterprise-grade solution that combines the security-first approach of Cohesity software with built-in silicon-level firmware protection, encryption, and breach detection of HPE Apollo Gen 10 servers.”

TEC Eurolab is already considering Cohesity for additional use cases across the organization. In the next phase of deployment, TEC Eurolab is considering Cohesity for integrated backup and recovery of all data across the organization as well as using Cohesity MarketPlace apps for anti-virus, in-place analytics, and vulnerability assessment. 

The combination of self-monitoring infrastructure with HPE InfoSight for servers and unified visibility from Cohesity Helios, global SaaS-based management for data and applications, will allow the company to gain predictive insights from their data and further optimize operations.

“We see a lot of potential at TEC Eurolab for further expansion of the joint solution from Cohesity and HPE. TEC Eurolab has already realized tremendous efficiency in their operations by using Cohesity for file shares and as a scale-out backup target and will elevate it to the next level by using Cohesity for integrated backup and recovery,” adds Giovanni Golinelli, Pre-Sales Manager, Systems and Storage Architect at NETMIND. “Future native integration of Cohesity with HPE primary storage portfolio including HPE Nimble Storage and HPE SimpliVity will help accelerate this and make Cohesity their data management platform of choice.”

Tuesday, December 10, 2019

McAfee aligns with Amazon Web Services to bring MVISION Cloud support to Amazon Detective

McAfee has announced that McAfee MVISION Cloud for Amazon Web Services (AWS) now includes support for Amazon Detective, providing customers with seamless incident detection and remediation. Through the integration of MVISION Cloud with Amazon Detective, customers have the ability to react to security issues quickly and confidently while leveraging the appropriate tools for incident investigation. 


Amazon Detective is a security service that is designed to easily analyze, investigate, and quickly identify the root cause of security findings or suspicious activities. Amazon Detective automatically collects log data from AWS resources and uses machine learning, statistical analysis, and graph theory to help customers visualize and conduct faster and more efficient security investigations. 

With McAfee MVISION Cloud, AWS customers can leverage a trusted cloud platform that has achieved AWS Security Competency status as well as AWS Well-Architected Partner designation for its Cloud Access Security Broker (CASB) technology to help locate issues and threats, and move without friction into the analysis phase to resolve the risk.


The capabilities in McAfee MVISION Cloud for AWS include integration with Amazon Detective to detect configuration issues or other cloud risks using McAfee MVISION Cloud and move seamlessly into the investigation phase with Amazon Detective.


The offering comes with architectural freedom of choice that includes Configuration Audit / Cloud Security Posture Management (CSPM) for diverse cloud workloads. Incidents can be detected for a wide array of virtual machine (Amazon Elastic Compute Cloud (Amazon EC2)) or container-based workloads (Amazon Elastic Container Service (Amazon ECS), and Amazon Elastic Kubernetes Service (Amazon EKS) including storage services needed to support the target applications.

Its rich, multifaceted incident data provides integrated CASB-derived functionality such as DLP / Malware detection and user behavior and threat analytics that go beyond detecting basic configuration issues. Identify threats and prioritize remediation, for a frictionless move into Amazon Detective to resolve risks quickly and efficiently.

“We worked closely with AWS to integrate a solution that our mutual customers can use to get total visibility and control over their applications and workloads on AWS,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Amazon Detective’s capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to seamlessly enforce data loss prevention, avoid unauthorized sharing of data, address threats from insiders and compromised accounts, prevent misconfiguration drift, audit all user activity and secure corporate data as organizations leverage the cloud to accelerate their business.”


“McAfee’s market-leading Cloud Security Platform provides a uniform approach to protecting data and stopping threats in the cloud through comprehensive and consistent policies,” said Nemi George, vice president, information security officer, Pacific Dental Services. “The new Amazon Detective integration will give us the added investigation capabilities to improve our compliance and reduce the risk within our cloud infrastructure.”

“We’re delighted that McAfee MVISON Cloud on AWS now supports Amazon Detective, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Dan Plastina, vice president of ESS Security Services, Amazon Web Services. “Customers using Amazon Detective will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

Thursday, November 7, 2019

McAfee MVISION Cloud offers “Shift Left” with security to boost compliance and reduce risk on Microsoft Azure

McAfee announced updates to McAfee MVISION Cloud for Microsoft Azure that will help customers “Shift Left” with security to preemptively help to address compliance and risk within their cloud infrastructure. 

With McAfee MVISION Cloud, security is pushed earlier into the DevOps process so that security professionals can catch risky configurations before they become a threat in production. This gives organizations the ability to deploy applications in the cloud with greater speed and efficiency. 


While Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) environments provide customers with choice and flexibility, if not configured correctly, they also potentially increase the organization’s surface area for security risks. 




McAfee detects compromised account activity in Azure based on brute force login attempts, logins from new and untrusted locations for a specific user, and consecutive login attempts from two locations in a time period that implies impossible travel – even if the two logins occur across multiple cloud services – to support immediate remediation and limit exposure.


McAfee automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and group to identify activity indicative of insider threat. Privileged user analytics identifies risk from inactive administrator accounts, excessive permissions, and unwarranted escalation of privileges and user provisioning.


McAfee MVISION Cloud for Azure enforces DLP policies across data at rest and in motion to ensure compliance with regulations and internal policies. McAfee supports DLP rules based on keywords, data identifiers, user groups, and regular expressions. Enforcement actions include coach users, notify administrator, block, quarantine, and delete. Leverage pre-built industry templates, create custom policies in McAfee, or leverage policies in an existing on-premises DLP solution.



With the new features in McAfee MVISION Cloud for Azure, security groups can integrate policy natively into DevOps processes and toolsets to discover security issues before systems are deployed to accelerate business in the cloud. 


New capabilities include security scans for Azure Resource Manager templates that allow users to discover risky configuration issues or violations in Azure Resource Manager Templates prior to deploying resources. Its inline integration with the tools developers use: security checks inside the DevOps pipeline through API integration with tools including Microsoft Git, Github, and Azure DevOps. Security Feedback is natively integrated into the build process saving time, effort, and frustration.



The offering also offers unified cloud security for Azure ecosystem to allows developers to leverage Azure services knowing security will be built-in by design (IaaS/PaaS/Container services) aligning closely to the Cloud Security Posture Management (CSPM) best practices. Its preemptive risk avoidance improves compliance with regulatory frameworks and reduces the likelihood of data loss, abuse or fines associated with improper security controls by highlighting security findings before they become security incidents.


The new “Shift Left” capabilities in McAfee MVISION Cloud for Microsoft Azure are available now.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...