Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Portshift syncs Kubernetes policies to container vulnerabilities in CI/CD pipelines for remediation

Portshift announces its new capability that delivers runtime policies for vulnerability remediation, allowing more secure workload communications. Portshift’s risk mitigation engine  connects Kubernetes network policies with discovered vulnerabilities in production workloads, allowing to mitigate the risk potential of vulnerable containers till its replacement with new version that remove the vulnerable component.


With Portshift, the company has taken DevSecOps to the next level with a platform that connects identified vulnerabilities with the identity of the workload, providing a measured balance that prevents workload communications based on the risk level and the potential threat to certain applications.


The technology has the ability to block traffic based on the vulnerability level discovered, providing a single picture for complete visualization of these processes during runtime. This provides protection that is matched to the DevOps applications in production.

According to a 2019 Gartner report, “Security can’t be an afterthought. It needs to be embedded in the DevOps process, which Gartner refers to as “DevSecOps…Integrate an image-scanning process to prevent vulnerabilities as part of an enterprise’s continuous integration/continuous delivery (CI/CD) process, where applications are scanned during the build and run phases of the software development life cycle.”


Portshift mitigates vulnerabilities with greater sophistication. Available as part of the company’s identity-based cloud native workload security and risk management platform, the technology ensures that Kubernetes environments are protected from development to runtime. With Portshift, app security is simplified and speeded-up by replacing multiple fragmented firewalls, security groups, and ACLs with automated identity-based workload security that is decoupled from the network infrastructure.


When unknown, and possibly malicious workloads are detected, they are quickly identified and rapidly removed using Portshift’s innovative DevOps security platform. The company’s workload management processes offer an alternative to the use of IP addresses, ports and firewalls to secure the network perimeter as it addresses the unique security requirements of cloud-native microservices running in containers both inside and outside of the network perimeter.


“With the availability of this identity-based approach, we are actively collaborating with industry leading vulnerability scanning providers including Twistlock, Aqua and Clair to move the industry forward,“ said Zohar Kaufman, co-founder and VP, R&D for Portshift. “Having Portshift’s information-rich view of containers in real time will be exceedingly important in 2020 as more determined hackers continue their efforts to attack earlier in the development process in order to exploit vulnerabilities before they are addressed by DevSecOps.“

Deloitte and Google Cloud unveil plans to collaborate on next-generation security offerings

Building on their existing global alliance, Deloitte and Google Cloud announces that they will jointly leverage the strength of their portfolios in cyber and cloud solutions to provide customers with end-to-end secure cloud transformation services and solutions in support of their digital transformation journeys and to better combat cyber threats.

As organizations move more of their businesses to the cloud, better control over data and activities in the cloud, as well as preventing privilege misuse, becomes critically important. Migrating a single application to cloud can seem straightforward, but more often, that application's function is tied to multiple business processes. Deloitte employs complex logic, data-driven analysis, and automated tools to rapidly map your applications and infrastructure to Google Cloud Platform (GCP), helping to increase speed, quality and savings.


Deloitte has received Google Cloud’s Cloud Migration and Infrastructure specializations, demonstrating success in architecting and building GCP infrastructure and workflows, and migrating customer workloads to GCP.

Google Cloud’s infrastructure is designed, built and operated with rigorous attention to security. Deloitte has spent decades helping clients protect their businesses from security threats, and can help move securely to the cloud.

As clients increasingly leverage cloud native services to modernize their existing application portfolios and build new and innovative products and services for their customers, they turn to us to help drive increased value through Google Cloud. Its functional knowledge of client businesses and products, combined with the capability of Google Cloud services, helps clients reduce technology operating costs, accelerate innovation, and increase business agility and security.

Through its alliance with SAP, Deloitte and Google have the people, knowledge and experience to help capture the transformative potential of SAP running on Google’s fast, reliable, and global platform. Its integrated SAP offering can help leverage the power of SAP S/4 HANA and Deloitte’s preconfigured solutions to devise a comprehensive cloud strategy.

As a recognized global leader in business analytics and business strategy, Deloitte and Google are able to help harness the power of Google Cloud’s array of big data processing and analytics tools to enable data-driven insights at speeds and volumes that were previously unimaginable. Combined with its cognitive computing practices, Deloitte uses Google Cloud’s machine learning engine to provide next-generation machine learning offerings that help solve tough business challenges.

Deloitte provides dedicated, active, scalable cloud management as a service to help you set the pace of change in your industry. We leverage our secure platform and worldwide network of specialists to understand every dimension of your challenges and how they impact your requirements. Deloitte’s business insight, coupled with turnkey, on-demand cloud management offerings on Google Cloud, make it possible to accelerate the path to cloud.


"The increasing integration, interconnectedness, and data exchange of our businesses and lives create shared vulnerabilities where a problem in one area can quickly cascade into another. By building security into these environments, organizations can better protect their data, privacy, and operations," said Deborah Golden, U.S. cyber leader, Deloitte Risk & Financial Advisory, and principal in Deloitte & Touche LLP. "Together with Google, we are supporting secure transformative change for our clients, something that all organizations should prioritize, and can enable them to be better secured in their critical cyber and cloud needs."

"For enterprise customers moving to the cloud, security isn't an afterthought, it's at the top of every CIO's list, and in general is a board level topic," said Sunil Potti, vice president engineering at Google Cloud Security. "Building in the right security processes and controls from the beginning of the cloud journey can significantly reduce risks and costs for customers, and so we are delighted to be collaborating with Deloitte to help deliver end-to-end security services and solutions to our joint-customers."

As a Google Cloud Security Premier Partner, Deloitte offers cloud security services to its clients globally and helps assist Google Cloud Platform customers address security, privacy and compliance related risks as they migrate and transform their business in the cloud. 

As part of growing the alliance, Deloitte will offer Google Cloud customers cloud security solutions in the areas of security monitoring and threat response, zero trust, identity and access management (IAM) and data security. 

The alliance will also provide next-generation capabilities that can help organizations proactively detect, continuously monitor and respond to unauthorized activity before it can adversely affect networks, and establish and operationalize a zero trust architecture and program to continuously monitor and authenticate users — constantly determining their level of risk based on who they are, what they access, and when and where they do it from. 

The companies will also enhance a digital transformation strategy and lay the foundation to leverage new data-driven identity models as they evolve, and provide a suite of services designed to help organizations address data risk management challenges and help them understand the value of their data and privacy considerations, as well as to operationalize their data risk governance program. 

CloudJumper launches distribution agreement with Crayon to improve access to cloud workspace for Azure

CloudJumper announces alliance with Crayon that combines the power of CloudJumper’s Cloud Workspace Management Suite (CWMS) for VDI and RDS workloads with the expertise of Crayon’s managed services and independent 'cloud economics' consulting practice.

CloudJumper and Crayon’s partnership bring new possibilities for customers and MSPs who want the flexibility of choice for management, security options and the ability to build their own value-add services suite leveraging WVD. 


Microsoft’s Windows Virtual Desktop (WVD) brings new choices for customers who want more control of the managed services running on top of desktop and application virtualization solutions. Legacy VDI providers have historically served as a gatekeepers controlling the workstation management plane. CloudJumper brings to Azure WVD what the legacy vendors will not – the flexibility of controlling managed services on top of managed desktops.

The utility of Windows Virtual Desktop (WVD) is further enhanced through CloudJumper's Cloud Workspace Management Suite (CWMS). CWMS is an automation, orchestration workflow and policy solution to deploy, configure and manage WVD in real-time and at cloud scale. CWMS will instantly, and continually, optimize the customer’s Azure investment.


WVD is a complex collection of Azure services. CloudJumper simply funnels the hundreds of WVD setup options into a few key questions and then orchestrates and deploys a customized environment. With CloudJumper, the customer is just minutes away from deploying thousands of new WVD VMs– something that is not available in a native Azure user interface (UI).

To provide additional support for this distribution partnership, CloudJumper's product development team has been working closely with Microsoft's WVD product team for over two years. As a result, CloudJumper is proud to be recognized as a Microsoft Preferred Solution Provider for WVD.

Microsoft Azure WVD provides customers with unique licensing options and operating system flexibility for Windows 10 and Windows 7 desktop virtualization. Windows 7 desktops can now be migrated to Azure WVD and receive up to three years extended security updates at no additional costs. 

New Windows 10 multi-session OS options are only offered in Azure. These OS choices along with the many complementary Azure PaaS management and security offerings can be securely delivered directly into the Azure tenant. Native Azure Management, supported by CWMS, means no redirection and no third party vendor lock-in. This allows customers to leverage current Microsoft licensing instead of buying overlapping third party tools.

The partnership with Crayon combines the strengths and expertise of CloudJumper and Crayon to deliver the next generation of cloud DaaS and WaaS VDI and RDS desktop and application virtualization solutions.


Headquartered in Oslo, Norway, Crayon is in over 35 countries, providing more than 8,000 customers with strategic advice, consulting and managed services, and support with complex IT estates. Crayon has been the preeminent IT infrastructure consulting business in the Nordic region for more than 12 years, and has expanded its footprint in the US in the last two years.

“Crayon’s deep experience in all aspects of the digitalization journey helps ensure the success of the new partnership. We are pleased to combine CloudJumper’s advanced platform with Crayon’s unique SAM to Cloud Consultancy Services as companies take the next step in digital transformation with their move to Windows Virtual Desktop,” said Alex Picchietti, global director of cloud services for Crayon. “The wealth of expertise from both companies will support organizations making this important move to improve productivity and operational efficiency.”

“The advent of WVD and the partnership with a respected industry leader like Crayon extends the reach of our combined solutions globally,” said JD Helms, president of CloudJumper. “Customers are demanding choice and flexibility in their managed workspace providers and CloudJumper is uniquely positioned to do just that.”

Saturday, December 21, 2019

Veritone, Evolphin team to provide advanced, AI-driven media asset management offering for Inter Milan football club

Veritone and Evolphin Software announced that the Football Club Internazionale Milano (Inter Milan) is leveraging a robust, AI-driven media asset management system based on Veritone aiWARE and the Evolphin Zoom MAM platform. 

The combination of aiWARE and Evolphin Zoom gives Inter Milan a next-generation solution for indexing, managing, and monetizing its massive library of archived and current content. As a result, Inter Milan is able to give its stakeholders around the globe faster and more efficient access to tailored content.


The Evolphin Zoom MAM ingests and transcodes the content from Inter Milan, and sends media for analysis to Veritone’s aiWARE platform. Veritone’s aiWARE uses advanced AI techniques to generate descriptive information about the content, such as spoken words, faces, logos, or advertiser names mentioned, making the content indexed and searchable.

In this manner, aiWARE helps Inter Milan tag and identify key assets within the library, enabling video editors, journalists, and designers to find particular content they need quickly and deliver their work faster than ever.


Once aiWARE has analyzed the team’s assets and generated the necessary metadata, the information is programmatically sent back to the Evolphin Zoom MAM platform. Zoom acts as the orchestrator of Inter Milan’s new digital content production pipeline, providing out-of-the-box media management capabilities, including enterprise-grade security and versioning of assets, rich plugins to Adobe apps, powerful tagging and searching, and automated distribution of content to any destination. 

 “At Evolphin, we are proud to begin this journey with Inter Milan and Veritone,” said Brian Ahearn, CEO of Evolphin. “The technologies we are applying here are incredibly innovative and unlike anything available on the market today.”


“In partnership with Evolphin, we look forward to helping Inter Milan leverage our aiWARE platform to get maximum benefit out of its tremendously valuable content library and better serve all of its key stakeholders, from fans and viewers to sponsors and editors,” said Veritone president Ryan Steelberg.

Friday, December 20, 2019

Kaspersky sees a sky-rise of droppers with phishing and malware attacks surface amid premiere of famous space saga

According to research from Kaspersky, the latest and final film of the trilogy has drawn the attention of attackers even before the premiere, with fraudulent websites and malicious files of the yet-to-be-released film flooding the web. Popular films are often used by cybercriminals as bait to distribute malware, and the latest movie saga from ‘a galaxy far, far away’ is no exception. 

Films are one of the main forms of entertainment users seek to access for free, which creates fertile soil for cyberattacks. Online streaming, torrents and other methods of digital distribution often infringe upon content copyright, and yet they remain popular as a source of free content. 


Torrent-trackers and illegal streaming platforms pose a threat to users’ cyber-safety, since they can host malicious files, masked behind the name of movie files. Given this tendency, Kaspersky studied how the sci-fi franchise’s name is being abused by cybercriminals in order to fool fans.

Public attention on “Star Wars: The Rise of Skywalker,” which premieres Dec. 19, is already attracting cybercriminals. Kaspersky researchers found over 30 fraudulent websites and social media profiles disguised as official movie accounts (the actual number of these sites may be much higher) that supposedly distribute free copies of the latest film in the franchise. These websites collect unwary users’ credit card data, under the pretense of necessary registration on the portal.


The domains of websites used for gathering personal data and spreading malicious files usually copy the official name of the film and provide thorough descriptions and supporting content, thereby fooling users into believing that the website is, in some way, connected to the official film. 

Such practice is called “black SEO,” which enables criminals to promote phishing websites high up in search engine results (such results often show up for search terms such as ‘name-of-the-film watch free’).

To further support the promotion of fraudulent websites, cybercriminals also set up Twitter and other social media accounts, where they distribute links to the content. Coupled with malicious files shared on torrents, this brings the criminals results. So far, 83 users have already been affected by 65 malicious files disguised as copies of the upcoming movie.

Phishing is not the only way cybercriminals tend to utilize popular film franchises. Just as with TV shows, they often disguise malicious programs as yet another episode of the story. In 2019, Kaspersky detected 285,103 attempts to infect 37,772 users seeking to watch movies of the renowned space-opera series, a 10 percent rise compared to last year. The number of unique files used to target the users amounted to 11,499, a 30 percent drop from last year.

“It is typical for fraudsters and cybercriminals to try to capitalize on popular topics, and ‘Star Wars’ is a good example of such a theme this month,” said Tatiana Sidorina, security researcher at Kaspersky. “As attackers manage to push malicious websites and content up in the search results, fans need to remain cautious at all times. We advise users to not fall for such scams and instead enjoy the end of the saga on the big screen.”


Users have been advised to take the following steps by paying attention to the official movie release dates in theaters, on streaming services, TV, DVD, or other sources; avoid clicking on suspicious links, such as those promising an early view of a new film; and paying special attention to the downloaded file extension. The file should have an .avi, .mkv or .mp4 extension, among other video formats, and not the suspicious .exe extension.

Consumers must check the website’s authenticity, and avoid visiting websites to watch a movie until they are sure that they are legitimate and start with ‘https.’ Confirm that the website is genuine by double-checking the format of the URL or the spelling of the company name, reading reviews about it and checking the domains’ registration data before starting downloads. It also uses reliable security solution, such as Kaspersky Security Cloud, for comprehensive protection from a range of threats.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...