Showing posts with label data privacy. Show all posts
Showing posts with label data privacy. Show all posts

Friday, December 20, 2019

Anomali, Trend Micro identify credential harvesting campaign targeting government procurement sites

Multiple government procurement services were targeted by a credential harvesting campaign that uses bogus pages to steal login credentials. Cybersecurity company Anomali uncovered a campaign that used 62 domains and around 122 phishing sites in its operations and targeted 12 countries, including the United States, Canada, Japan, and Poland.

The Anomali Threat Research Team identified a credential harvesting campaign designed to steal login details from multiple government procurement services. The procurement services are used by many public and private sector organisations to match buyers and suppliers. 


In this campaign, attackers spoofed sites for multiple international government departments, email services and two courier services. Lure documents sent via phishing emails were found to contain links to spoof phishing sites masquerading as legitimate login pages relevant to the spoofed government agencies. Victims duped into following the phishing email link would then be invited to login. Anyone who fell victim to the adversaries would have provided them with their credentials.

This credential harvesting campaign has been primarily targeting government bidding and procurement services. The focus on these services suggests the threat actor(s) are interested in potential contractor(s) and/or supplier(s) for those governments targeted. The purpose of this insight could be a financial incentive to out compete a rival bidder, or more long term insight regarding the trust relationship between the potential supplier and the government in question. 


Campaigns like these are difficult to protect against because unless the domains hosting the phishing pages are known as malicious, an organisations firewall will not know to block it. Legitimate sites were also hosting the phishing pages, and were likely compromised as part of the campaign. At the time of writing none of the sites in this campaign were active, Anomali researchers consider it likely that the actors will continue to target these services in the future.

The use of bogus login pages continues to be a popular method for credential harvesting campaigns. The Trend Micro Cloud App Security solution blocked 2.4 million attacks of this type in the first half of this year — a 59 percent increase from 1.5 million in the second half of last year.

Organizations should look into adopting advanced technologies such as the Trend Micro Cloud App Security solution. It combines artificial intelligence (AI) and computer vision in order to help detect and block attempts at credential harvesting in real time. 

After suspected phishing emails go through sender, content, and URL reputation analyses, computer vision technology and AI will examine the remaining URLs to check if a legitimate login page’s branded elements, login form, and other website components are being spoofed.

For this campaign, threat actors used phishing emails carrying documents written in the language of the country being targeted. The phishing emails were also found with URLs to fake but legitimate-looking login pages. If the recipient of the phishing email clicks on the malicious URL, they will be redirected to a login page that is an imitation of a legitimate website the campaign is spoofing. A login attempt will then lead to the theft of the user’s credentials.


Aside from the websites of international government departments, those belonging to email services and two courier services were also spoofed by the threat actors. The U.S. Department of Energy, Canada’s Government eProcurement service, China’s SF-Express courier service, and Australia’s Government eProcurement Portal were some of the target organizations.

Email users should always be aware of the latest phishing tactics in order to avoid falling victim to credential harvesting attacks. After all, such attacks are becoming highly deceptive; in fact, it has become relatively easy for cybercriminals to obtain a .gov domain that they can use to further disguise their schemes.

To minimize the chance of becoming a victim, users can be cautious of emails from individuals or organizations that ask for personal information. Most companies will not ask for sensitive data from its customers, especially with stricter data privacy laws; look out for grammatical errors and spelling mistakes in suspicious emails. Emails from legitimate companies are often proofread to ensure that the materials they send out are error-free. 

Emails that call on a sense of urgency or have an alarmist tone should not be hastily acted on. If in doubt, recipients should verify the status of their accounts with their company’s system administrator or service provider.

Optiv Security expects election hacking, ‘hybrid threat actors’ to top the list of 2020 cyber threats

Optiv Security announced its cybersecurity industry predictions for 2020 and beyond. A focus on privacy, evolving threat actors, pervasive deepfake videos, and increased election interference are among the issues Optiv sees taking on greater importance in the New Year.


Optiv expects the most common issues that the industry may face in 2020 include hybrid threat actors may become more commonplace. Optiv’s 2019 Cyber Threat Intelligence Estimate (CTIE) found a growing number of “hybrid threat actors.” These are attackers who impersonate one type of adversary to disguise their true intentions (for example, a nation state imitating a generic hacker targeting a customer database, when its true aim is to steal intellectual property). 

Optiv believes a possible increase in the number of adversaries to adopt this technique and launch “imposter” attacks to obfuscate their true intentions, adding yet another layer of complexity to threat hunting and incident response.


Apple’s “privacy as a human right” campaign should cause others to follow. As the world’s foremost technology organization going all-in on privacy will shift the competitive landscape, security and privacy could become a competitive differentiator for companies that follow Apple’s lead and grab “first mover” status in their markets. Laggards may risk meeting the unseemly fate of past organizations that failed to embrace important technology paradigms such as internet, cloud, and mobile computing.

Election misinformation campaigns could proliferate. The effectiveness of the Russian misinformation campaign of 2016 increases the possibility of increased copycat attacks for the 2020 election. These attacks could come from nation states as well as domestic groups supporting rival U.S. politicians. This activity threatens to trigger a major public/private response to the online misinformation problem.


Optive expects to see the first cases of deepfakes used to manipulate stock prices. There has been much publicity around the potential to impact elections using deepfakes (AI-doctored videos that enable individuals to make it appear people said things they never said). However, not enough attention has been paid to how cybercriminals can make money using deepfakes against businesses. 

This might change in 2020, as it’s possible we will see the first deepfake attacks designed to impact stock prices, by having CEOs, financial analysts, Federal Reserve leaders or other powerful economic figures make phony statements that will cause stock market movements. Cybercriminals would use these videos to make quick fortunes in the market.

There should be widespread realignment of IT and security organizations. As boards view cybersecurity as a peer-level risk to traditional enterprise risks, such as lawsuits and product recalls, more CISOs should become peers of CIOs and other executives, rather than direct or indirect reports. This would cause a realignment of the IT and security organizations to eliminate conflicts and encourage collaboration. 


The most critical of these will be the continued expansion of DevSecOps, in which security is fully integrated into the application development process; and patch management, which will move from being divided between security and IT (security finds vulnerabilities, IT patches them), to becoming a unified process with a single point of accountability.

Cybersecurity basics may continue to vex consumers and enterprise organizations.Whether insufficient passwords, lack of education and training around phising attacks, or simple upkeep and compliance, the tiny details of cybersecurity will continue to be the cause of a vast portion of compromises if left unaccounted for. Simple passwords (those without special characters or are extremely obvious, such as “password123”) only take minutes to crack by professional hackers and can be done inexpensively.

“As we look beyond 2019 and into 2020, we have a solid idea of what threats the industry is facing, and not just ransomware and phishing attacks, but new, hard-to-combat threats,” said Anthony Diaz, Division Vice President, Emerging Services at Optiv. “As is always the case, us ‘good guys’ are forced to play catch up with bad actors, who constantly remain a step ahead. There is much IT and business leaders must be aware of when it comes to cybersecurity, as the pace of change is quite high. That is why we recommend cybersecurity programs focus on proactive risk mitigation and build out from there. This ensures your organization is actively looking for, combating, and identifying threats before they can cause damage.”

Friday, December 13, 2019

Trend Micro warns Android users on malicious Christmas-themed shopping, game and chat apps that lure users with deals

Security researchers from Trend Micro have cautioned Android users when downloading apps for shopping, games, and Santa video chats as they found hundreds of malicious apps likely leveraging the season to defraud unwitting victims. 

A scan of thousands of apps revealed seven with malicious routines such as replacing the legitimate apps with a version downloaded from a command and control (C&C) server. They also found 35 apps containing adware with more invasive behaviors than standard in-app advertisements, and 165 apps enabling “excessive or dangerous combinations of permissions,” such as camera, microphone, contacts and text messages. 


Researchers from Barracuda Networks recommend that users examine the apps they download to their phones, especially as online shopping and banking are expected to reach new heights this year.

Invasive adware were reportedly related to DIY gift projects and used suspicious ad networks by displaying catchy deals and coupons. Cybercriminals can go after banking, email, and access credentials by replacing legitimate website forms, or by using malware or injected skimmers

The researchers noted the excessive permissions that users may grant apps can be used to steal stored information from the devices such as contacts for phishing and spam campaigns, as well as banking authentication tokens via SMS messages when shoppers finalize their purchases online.

When downloading apps and shopping online, users must check app reviews on reputable websites; review access permissions being requested by the app and evaluate if they are necessary for the functions of the app; directly type the retailers’ websites, and avoid clicking on URLs found in emails and text messages, especially from unknown senders; limit the amount of personal information provided to websites and apps; and regularly update devices’ operating systems and apps.


Users and enterprises can take advantage of multilayered mobile security such as the Trend Micro Mobile Security for Android solution. Trend Micro Mobile Security for Enterprise provides device, compliance and application management, data protection, and configuration provisioning, as well as protects devices from attacks that exploit vulnerabilities, prevents malicious and unauthorized access to apps, and detects and blocks malware and fraudulent websites. 

Trend Micro’s Mobile App Reputation Service (MARS) covers Android threats using leading sandbox and machine learning technologies, protecting devices against malware, zero-day and known exploits, malicious apps, privacy leaks, and application vulnerabilities.

Thursday, December 12, 2019

Intel Research recognizes digital skills gap slowing Industry 4.0 in the manufacturing sector

Intel released Thursday results of a new study “Accelerate Industrial,” which represents comprehensive view of Industry 4.0, the digital transformation of the manufacturing sector. The research uncovered a serious skills gap that most Western industrial production training programs and government investment initiatives fail to address.

The study found that current leaders need to create tomorrow’s future-ready workforce. This requires the collaboration of universities, government and industry – including initiatives that focus on worker training for the transforming manufacturing sector.



Accelerate Industrial” was conducted and authored by Dr. Faith McCreary, a principal engineer, experience architect and researcher at Intel, in tandem with Dr. Irene Petrick, senior director of Industrial Innovation for Intel’s Industrial Solutions Division. The study encompasses mobile ethnographies and interviews with over 400 manufacturers and the ecosystem technologists that support them. The work is being released as a series of reports.

A recent Deloitte/Manufacturing Institute study suggests that industries are entering a period of acute long-term labor shortages, with a shortfall in manufacturing expected to be 2.4 million job openings unfilled by 2028, resulting in a $2.5 trillion negative impact on the U.S. economy. Germany and Japan, two other developed economies, are expected to fare even worse in terms of this projected labor shortage.


With the increasing proliferation of data, connectivity and processing power at the edge, the industrial internet of things is becoming more accessible. However, successful adoption remains out of reach for many: two of three companies piloting digital manufacturing solutions fail to move into large-scale rollout.

The study uncovered the top five challenges cited by respondents that have the potential to derail investments in smart solutions in the future, with 36 percent citing “technical skill gaps” that prevent them from benefiting from their investment; 27 percent expect “data sensitivity” from increasing concerns over data and IP privacy, ownership and management; 23 percent found that they lack interoperability between protocols, components, products and systems; 22 percent citing security threats, both in terms of current and emerging vulnerabilities in the factory; and 18 percent reference handling data growth in amount and velocity, as well as sense-making.


Accelerate Industrial” points to the rising importance of the digital skills required to navigate and succeed in this new landscape.

The research found that while there is a big appetite for digital transformation – 83 percent of companies plan to make investments in smart factory technologies – the most important skills and characteristics cited for that transformation are not ones that are typically emphasized by most industry job training programs or relevant policymakers.

Future skills cited by respondents point to the need to go beyond the basics of programming to embrace a deep understanding of digital tools, from data collection to analytics and real-time feedback directly to the operating environment. 

The top five future skills required to support digital transformation in manufacturing are “Deep understanding” of modern programming or software engineering techniques; “digital dexterity,” or the ability to leverage existing and emerging technologies for practical business outcomes; data science; connectivity, and cybersecurity.

Saturday, December 7, 2019

Odaseva increases its compliance automation apps to data privacy regulations, adds Salesforce Marketing Cloud support

Odaseva announced this week enhancements to its platform including increased compliance automation applications as well as support for the Salesforce Marketing Cloud and Ultra High Availability for Salesforce.

For the past few years, Odaseva has offered users the ability to automate their data compliance and privacy activities for the General Data Protection Regulation (GDPR). This has allowed organizations to reduce financial, regulatory and reputational risk by automating their compliance activities – utilizing such Odaseva tools as Sandbox Anonymization and Production Data Lifecycle. 


Now, Odaseva has increased its compliance automation offerings for a number of industries and regions including the Health Insurance Portability and Accountability Act (HIPAA) as well as the California Consumer Privacy Act (CCPA).

Customers with large datasets in the cloud may now backup files from the Salesforce Marketing Cloud to the Odaseva platform. These files include emails, social or online marketing files, among others. Benefits of the application include automated backup on a regular basis, managed backup services and data loss prevention. Additionally, the application complies with strict data privacy laws and security policies to ensure data is secure.

For many organizations, 99.9 percent uptime is not enough. In these cases, Odaseva offers Ultra-High Availability for any user who wants to continue working on Salesforce – even when Salesforce is temporarily offline. Ultra-High Availability mode ensures users never have to work in a “read-only” mode on Salesforce and instead, continue their work on the Odaseva platform. Once Salesforce is back online, their work is immediately synched and updated with the Salesforce platform.


“In today’s digital age, ensuring proper data governance, even in cloud platforms such as Salesforce, is more critical than ever,” says Sovan Bin, CEO and founder of Odaseva. “Data integrity and availability for cloud mission-critical applications must be protected by both Backup and Disaster Recovery as a Service. In addition, with the influx of new data privacy and governance laws such as CCPA, which goes into regulation January 1, 2020, businesses must automate consumer rights like the Right of Access or Erasure and minimize risks by anonymizing data and implementing data lifecycles.”

Trend Micro reveals that Magecart group sets sights on Smith & Wesson, other high-profile stores

Trend Micro announced this week that the infamous credit card-skimming group Magecart has struck again. After incidents in the past few months that saw the threat actor go after customers of online shops and hotel chains, the group has set its sights on a new set of targets: high-profile stores, including firearms vendor Smith & Wesson (S&W).


According to security researcher, Willem de Groot of Sanguine Security, threat actors took advantage of the Black Friday rush by injecting credit card skimmers into the sites of a number of high-profile stores such as S&W. The group behind the attack injected the skimmer into S&W’s website on Nov. 27 — a couple of days before Black Friday, most likely in anticipation of the high volume of traffic going to the website. Note that the skimmer has been removed from the S&W store as of the time of writing.

The skimmer features an impressive list of capabilities, such as reverse engineering, a three-stage loader, and multiple layers of JavaScript obfuscation to hide its tracks. When a user visits the compromised website, the command-and-control (C&C) server initially sends harmless code — up until the actual payment process, when the skimmer begins its malicious routine. 


To make the skimming attack look more legitimate, a fake payment confirmation code is presented to the user. Behind the scenes, however, malicious code is already running, sneakily exfiltrating customer data such as payment information to the C&C server.

Sanguine Security notes that these attacks only worked for users which met various criteria, including using U.S.-based IP addresses, using non-Linux-based browsers, and not using the AWS platform.

The rise of Magecart highlights the need for vendors and other organizations to properly secure their websites and applications. Data theft via an attack such as the ones regularly performed by Magecart can mean monetary losses, not only for customers but also for the company whose website or application was compromised, especially given the potentially steep fines meted out to violators of data privacy laws such as the General Data Protection Regulation (GDPR).  


Organizations can minimize the chances of compromise by consistently applying the newest patches and updates to the software they use and by shoring up the authentication mechanisms provided to customers. Furthermore, it is recommended that IT and security teams proactively monitor their websites for any sign of malicious activities, such as unauthorized access or data exfiltration.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...