Showing posts with label database. Show all posts
Showing posts with label database. Show all posts

Saturday, December 28, 2019

CyberScout shares key cybersecurity predictions for 2020; predicts persistent threats in areas of privacy and cybersecurity

As 2019 comes to an end, cybersecurity experts are preparing for a new year—and a new decade—and all the cyber scams, breaches, attacks and privacy concerns that threaten consumers and businesses. CyberScout continues to strengthen defenses against the constantly evolving cyber threats that will shape the 2020 security landscape, encouraging consumers and business owners to stay informed and aware. 


"While consumers and business leaders are more aware of cybersecurity and privacy than ever before, cybercriminals continue to innovate," said CyberScout founder and chairman Adam Levin. "As defenses improve, the attack vectors become more nuanced and technically impressive. You are your best guardian when it comes to your privacy and personal cybersecurity."  

Levin's has listed the following 20 cybersecurity predictions for 2020:
  1. Cybersecurity workforce shortages. There will be a shortage of experts, adding pressure on CISO's charged with tackling an increasing issue environment. With the demand for cybersecurity professionals far exceeding supply, the market will have to start filling openings with less qualified people. 

  1. The disinformation blob will grow. With the success of weaponized misinformation campaigns in the 2016 and 2018 U.S. elections, expect to see more of them in the private sector, with businesses adopting troll farm tricks to hurt the competition. 

  1. Ransomware will continue to thrive. Phishing attacks will continue to lead to ransomware infecting more and more networks. Businesses, municipalities and other organizations will continue to pay whatever they must in order to regain control of their data and systems, and will also see better backup practices that will help minimize or neutralize the threat of these attacks.  

  1. IoT botnets will make dystopian paranoia seem normal. IoT will continue to grow exponentially. In 2020, there will be somewhere around 20 billion IoT devices in use around the world. Unfortunately, many are not secure because they are protected by nothing more than manufacturer default passwords readily available online. They will be weaponized (like in years' past), but with increasing skill and computing power.


  1. The integrity of the U.S. elections will be questioned—for good reason. There are still voting machines in use that are far from secure and would not pass the simplest of audits. Some states continue to use machines that leave no paper trail. Look forward to questions regarding election security all year.  

  1. Cryptocurrency miners will continue to get rich off stolen electricity. Related to the botnet craze, we will see an increase in computing power theft used to mine cryptocurrency. With bots becoming exponentially more effective as the result of AI and cloud computing, a renaissance of Wild West behavior in the global blockchain digital ledger can be expected. 
  
  1. Zero-trust environments will be talked about. A few may exist. The assumption that one can trust the home team—people within one's organization—has been replaced with zero-trust policies. Zero-trust simply means that no one can be trusted, in or outside the organization. With this assumption foremost, new systems make breaches and compromises harder to happen. 

  1. More people will know what "protect surface" means. Protect surface is part of the zero-trust environment. An organization's attackable surface includes every error-prone human in its employ as well as the mistakes in configuration they may have committed along the way and any number of other issues. The protective surface is much smaller and must be kept out of harm's way. The more the subjects is spoken about, the stronger its cybersecurity is expected to be. 

  1. Cars will be frozen. Driverless cars are going to hit things as well as get hit by hackers. Cars that talk to satellites are toast. It's going to happen. (Or not. But it totally could.) 

  1.  5G will make the cyber smash grab a thing.  5G is going to make everything move fast, as will the new generation USB4 devices. With quicker speed, it will take much less time to transfer data. Coincidentally, criminals appreciate this as much as the rest of us.  

  1. Social media will no longer need to be private. Social media companies will probably become a bit more responsible when it comes to the way they gather, store, crunch, analyze and sell our data to marketing companies and small to medium sized businesses looking to connect directly with consumers. 


  1.  State-sponsored traffic jams will be a thing. Hackers are going to target operational systems with an array of tactics that include ransomware and more DDoS attacks that will snarl things up in ways we've not yet seen. The targets will be financial institutions, the power grid, elections, proprietary business information, city services and infrastructure like traffic lights and much more that can wreak havoc on our day to day lives.

  1.  You're going to have personal cyber insurance. Insurance companies will be writing more comprehensive cyber liability policies for businesses and offering innovative personal cyber coverage for consumers. 

  1.  HR will save money by spending some. More employers will offer their employees identity protection products and services as part of their paid or voluntary benefits programs. An employee who has their identity stolen is not very productive and if, as part of that identity theft, their user ID or passwords are exposed, a thief might have what he or she needs to access an employer's network and sensitive databases. 

  1.  The cloud will leak. The parade of stories about misconfigured cloud clients and data stored without any password protection on cloud services will continue apace, perhaps in part because of the CISO and cybersecurity workforce shortage discussed in the first prediction.  

  1.  AI will gladly take one’s job. AI is here and it's willing to work. The CISO shortage as well as many of the innovations discussed in this list of predictions will be increasingly addressed and powered by Artificial Intelligence. 

"Disinformation efforts, election security and continued attacks on local governments and major metropolitan hubs are escalating concerns of how disruptive and dangerous cybercrimes are becoming," continued Levin. "2020 promises to be an interesting ride. Be smart and stay safe by staying informed and seeking cyber insurance protection for you, your family and your business."  

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Friday, December 20, 2019

Microsoft and Oracle expand interoperability partnership to Canada to help joint customers run their mission-critical workloads

Oracle announced this week continued expansion of its cloud interoperability partnership with Microsoft to help joint customers worldwide run their mission-critical workloads across Oracle Cloud and Microsoft Azure. Its new interconnect location means enterprises can now build workloads that seamlessly interoperate between Microsoft and Oracle cloud regions in Canada. This interconnect builds on an existing partnership announced in June of 2019.

The partnership has received a huge amount of interest, as 80 percent of enterprises use a combination of Microsoft and Oracle software to run their businesses. 


As cloud computing becomes ubiquitous, and businesses rely on multiple cloud providers, the partnership makes managing companies’ most important cloud workloads significantly easier. These workloads include financial planning, inventory, sales applications – and their underlying databases.

The expansion will give more customers direct, fast and highly reliable network connectivity between Microsoft Azure and Oracle Cloud, while providing first-class customer service and support that enterprises have come to expect from the two companies. This multi-cloud solution delivers the performance, easy integration, rigorous service level agreements, and collaborative enterprise support that they need to simplify their operations. 


Simply put, the Oracle-Microsoft partnership means cloud services run by the two providers will interoperate as if they were part of a single cloud, making it easier for customers to run their mission-critical workloads across the two clouds.

“The global demand for running applications and databases in multi-cloud environments continues to accelerate,” said Clay Magouyrk, senior vice president of engineering, Oracle Cloud Infrastructure.  “With the new interconnect, our Canadian customers can now take advantage of a nearly seamless cloud integration between the world's largest enterprise cloud providers, Microsoft and Oracle.”


The two companies are putting customers first by enabling them to run full-stack applications side-by-side across clouds, or one part of a workload within Azure and another part of the same workload within Oracle Cloud. 

For example, using the interconnect makes it possible to connect Azure services like analytics and AI to Oracle Cloud services like Autonomous Database. Together, Azure and Oracle Cloud offer customers a one-stop shop for all the cloud services and applications they need to run their entire business.

From a technical perspective, the interconnect means less latency or delay, which enables better data transfer and application interaction between clouds. It also supports a broader spectrum of workloads, using resources available on both sides. Accenture recently performed testing on the performance of the interconnect and confirmed that the solution offers customers low latency and high ease of use.

Microsoft and Oracle plan to make the direct interconnect available in additional regions, including on the US West Coast, in a US Government specific region, in Asia, and in the European Union. Earlier this year, Oracle and Microsoft created an interconnect in Ashburn (North America), Azure US East, and in London (United Kingdom).

Wednesday, December 11, 2019

Trend Micro reveals that bug in Ryuk ransomware’s decryptor can lead to data loss in certain files

Ryuk’s decryptor tool — provided by the threat actors behind the ransomware to victims who have paid ransom demands — could actually cause data loss instead of reinstating file access to users. According to a blog post from Emsisoft, a bug with how the tool decrypts files could lead to incomplete recoveries, contrary to what the decryptor is actually meant to achieve.

While Ryuk has gained most of its notoriety due to who it targets and how much it tries to extort, the ransomware variant has actually seen a number of evolutions to its capabilities, which includes a revised encryption process. 


To make encryption faster and more efficient, Ryuk will only partially encrypt files that are larger than 57,000,000 bytes (approximately 54.4 megabytes) in 1,000,000 byte blocks — using a formula to compute how many of these blocks it will encrypt.

Traditionally, a file infected by Ryuk will contain a marker that shows whether it has already been previously encrypted with the Hermes ransomware, an earlier malware variant on which Ryuk was based. However, in addition to the Hermes marker, these partially encrypted files will also show a number beside the marker indicating how many of the 1,000,000 byte blocks were encrypted.


Due to a bug in how this number is calculated, the latest versions of Ryuk might accidentally truncate some files, removing a single byte of data from the file it was supposed to restore.

While a single byte might seem like a miniscule amount to get worried about (in most cases, the last byte is actually unused) — some types of files, such as those used in Oracle databases, store information in the last byte. This means that the removal of this single byte can actually result in an incomplete recovery, depending on the file type that was encrypted.

According to Trend Micro’s 2019 midyear security roundup, ransomware detections in the first half of the year increased by 77 percent compared to the second half of operations as threat actors seek to evolve their tools and methods. Ryuk is perhaps the most prevalent of the current ransomware families: It has earned the threat actors behind it millions of dollars from victims — typically, major organizations in both public and private sectors.

Given how widespread ransomware still is, it will benefit both organizations and individual users to regularly practice these recommendations to minimize the chances of a successful ransomware attack.


The simplest and perhaps most effective method to keep important files and data safe is to maintain regular backups — preferably using the 3-2-1 method of keeping three backup copies in at least two separate formats, with one copy offsite. IT administrators should ensure that systems, networks, servers, and applications are consistently updated and patched to prevent threat actors from taking advantage of vulnerable software and systems to deliver ransomware.

Organizations should cover all possible attack surfaces by implementing the principle of least privilege, where employees can only access parts of the system they need. Ransomware victims should also refrain from paying ransomware demands, as this encourages threat actors to continue with their campaigns. Furthermore, paying the ransom doesn’t even guarantee that the encrypted data will be restored, as seen in this scenario.


Organizations without dedicated security teams that want to bolster their security strategy can also look into taking advantage of services such as Trend Micro Managed XDR, which offers a wide scope of visibility and expert security analytics by integrating detection and response functions across networks, endpoints, emails, servers, and cloud workloads. 

The Managed XDR team is no stranger to Ryuk, and has extensive real-world experience investigating and analyzing the ransomware variant — as well as offering remediation advice — to customers.

Saturday, December 7, 2019

Zadara enhances SQL Server database migration to the cloud, removes complexity, hidden risks and expenses

Zadara Storage announced a new solution that enables enterprises to migrate SQL Server database apps to the cloud – in a phased manner. 
High availability (HA) is imperative to a well-architected SQL Server environment and modernizing business-critical applications. 


While Microsoft SQL Server Enterprise Edition provides a mechanism for doing so, it is costly for organizations that only need its HA features. But according to Zadara, it doesn’t have to be this way. Zadara’s hybrid cloud storage platform is available on AWS, Azure and Google Cloud Platform. 

Zadara’s service offering allows users to meet their high-availability requirements using SQL Standard Edition within the AWS environment – providing them with the ability to maintain HA without the cost of SQL Enterprise Edition. In addition, applications can be migrated to AWS without any code changes.


“Our newest offering is the latest example of Zadara’s ability to deliver real business value,” said Oded Kellner, vice president, product management at Zadara. “We are helping customers navigate the hidden risks and unnecessary expenses that have plagued so many SQL Server migrations to public clouds – with greater reliability, faster performance and increased security capabilities.”

Saturday, November 30, 2019

PAC Storage enhances data storage performance with scale-out NAS, latest controllers, and 32Gb FC / 25GbE connectivity

PAC Storage (PAC) has announced three latest enhancements to their existing line of hardware: scale-out NAS systems, next generation controllers, and 32Gb FC and 25GbE host boards. Each enhancement dramatically accelerates system performance, providing tremendous benefits to a variety of industries and applications including database, analytics, virtualization, motion media, file sharing, cloud data integration, data science and AI.

The all-new Scale-Out NAS systems product line supports 100+ Gbps performance and scaling to more than 100 PB capacity. These solutions allow capacity and performance to be increased by horizontally adding another node (array) to the system.


PAC Storage is an enterprise data storage hardware solution. Since 2005, PAC SAN solutions have been data center cornerstones nationwide for primary, secondary, backup, and disaster recovery. In 2017, PAC introduced PS storage solutions which offer SAN and NAS, and include cloud gateway options. Offering the ideal price point, PAC feature-rich solutions are renowned for no single point of failure and scalability to petabytes of on-premise storage.

These scale-out NAS systems are joined by new Next Generation Controllers featuring up to twelve cores of the latest Intel CPU technology. Improvements also include doubling the controller cache to 512GBs, enabling PAC controllers to now boost performance by up to 80 percent, fulfilling the demanding requirements of today’s intensive enterprise data environments. 

Both PAC Storage PS and PAC All Flash product lines will feature the next generation controllers with all flash designed to deliver optimal SSD performance and response times of less than 0.35 milliseconds, as well as up to 900K IOPS and 10,000/5,500 MB/s read/write speed.

PAC Scale-Out NAS supports adding more nodes achieving more performance and capacity via a clustered system with up to 100 plus GBps read/write speed and more then a 100PBs of storage for the needs of future data growth.   


PAC also supports auto-balancing function that supports distribution of data across all nodes in the system. When a large number of users access data simultaneously, the system share the workload through parallel processing, solving the problem of a single node performance limitation and improving the access e­­fficiently.  

To prevent critical data loss and ensure continuous storage services PACs Scale-Out system is designed with the support of multi-layer data protection on hard drives, notes, and cluster levels. If any of the elements fails, neither the data will be lost nor the performance will be affected.  

If a single node failure is detected, PAC initiates self-healing function to recover the data from the faulty node. On a cluster level, users can use the Rsync feature for remote backup of the cluster file to remote cluster or remote NAS.   

Rounding out the new PAC Storage enhancements are 32Gb FC and 25GbE host boards which enable enterprise customers to migrate to the new networking standards for data access acceleration. The 32Gb FC and 25GbE host connectivity more than double system bandwidth via a single lane, making the storage infrastructure more scalable and flexible. 

"With this solution, we’ve truly hit it out of the park,” said PAC CEO Rick Crane. “The new scale-ut version of NAS is an outstanding and innovative alternative for our Isilon customers looking for a scale-out environment that’s simple to administer and easy on their budget. Even better, they can take advantage of the Next Generation technology in this product, as well as in our existing portfolio of SAN/NAS."

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...