Showing posts with label security threat. Show all posts
Showing posts with label security threat. Show all posts

Friday, December 20, 2019

Optiv Security expects election hacking, ‘hybrid threat actors’ to top the list of 2020 cyber threats

Optiv Security announced its cybersecurity industry predictions for 2020 and beyond. A focus on privacy, evolving threat actors, pervasive deepfake videos, and increased election interference are among the issues Optiv sees taking on greater importance in the New Year.


Optiv expects the most common issues that the industry may face in 2020 include hybrid threat actors may become more commonplace. Optiv’s 2019 Cyber Threat Intelligence Estimate (CTIE) found a growing number of “hybrid threat actors.” These are attackers who impersonate one type of adversary to disguise their true intentions (for example, a nation state imitating a generic hacker targeting a customer database, when its true aim is to steal intellectual property). 

Optiv believes a possible increase in the number of adversaries to adopt this technique and launch “imposter” attacks to obfuscate their true intentions, adding yet another layer of complexity to threat hunting and incident response.


Apple’s “privacy as a human right” campaign should cause others to follow. As the world’s foremost technology organization going all-in on privacy will shift the competitive landscape, security and privacy could become a competitive differentiator for companies that follow Apple’s lead and grab “first mover” status in their markets. Laggards may risk meeting the unseemly fate of past organizations that failed to embrace important technology paradigms such as internet, cloud, and mobile computing.

Election misinformation campaigns could proliferate. The effectiveness of the Russian misinformation campaign of 2016 increases the possibility of increased copycat attacks for the 2020 election. These attacks could come from nation states as well as domestic groups supporting rival U.S. politicians. This activity threatens to trigger a major public/private response to the online misinformation problem.


Optive expects to see the first cases of deepfakes used to manipulate stock prices. There has been much publicity around the potential to impact elections using deepfakes (AI-doctored videos that enable individuals to make it appear people said things they never said). However, not enough attention has been paid to how cybercriminals can make money using deepfakes against businesses. 

This might change in 2020, as it’s possible we will see the first deepfake attacks designed to impact stock prices, by having CEOs, financial analysts, Federal Reserve leaders or other powerful economic figures make phony statements that will cause stock market movements. Cybercriminals would use these videos to make quick fortunes in the market.

There should be widespread realignment of IT and security organizations. As boards view cybersecurity as a peer-level risk to traditional enterprise risks, such as lawsuits and product recalls, more CISOs should become peers of CIOs and other executives, rather than direct or indirect reports. This would cause a realignment of the IT and security organizations to eliminate conflicts and encourage collaboration. 


The most critical of these will be the continued expansion of DevSecOps, in which security is fully integrated into the application development process; and patch management, which will move from being divided between security and IT (security finds vulnerabilities, IT patches them), to becoming a unified process with a single point of accountability.

Cybersecurity basics may continue to vex consumers and enterprise organizations.Whether insufficient passwords, lack of education and training around phising attacks, or simple upkeep and compliance, the tiny details of cybersecurity will continue to be the cause of a vast portion of compromises if left unaccounted for. Simple passwords (those without special characters or are extremely obvious, such as “password123”) only take minutes to crack by professional hackers and can be done inexpensively.

“As we look beyond 2019 and into 2020, we have a solid idea of what threats the industry is facing, and not just ransomware and phishing attacks, but new, hard-to-combat threats,” said Anthony Diaz, Division Vice President, Emerging Services at Optiv. “As is always the case, us ‘good guys’ are forced to play catch up with bad actors, who constantly remain a step ahead. There is much IT and business leaders must be aware of when it comes to cybersecurity, as the pace of change is quite high. That is why we recommend cybersecurity programs focus on proactive risk mitigation and build out from there. This ensures your organization is actively looking for, combating, and identifying threats before they can cause damage.”

Wednesday, December 4, 2019

F5 enters into alliance with AWS to enable users to innovate faster in the cloud

F5 Networks announced a multi-year global Strategic Collaboration Agreement (SCA) with Amazon Web Services (AWS) to allow customers to use F5 for new cloud-native application workloads and extend their existing F5 investments on AWS.


F5’s application services ensure the performance and security of millions of applications for global enterprises. The SCA will enhance companies’ ability to leverage the full suite of F5 Software-as-a-Service (SaaS) and cloud-native application services to migrate, build, secure, and operate their applications on AWS. 


The structured framework of this engagement will allow customers to have a consistent and scalable operating model for their application assets on AWS, while exploring future innovations that enhance migration and operation of applications to the cloud. 


Customers can use advanced F5 solutions to standardize, scale, and optimize application services for AWS environments, from lift-and-shift and re-platforming, to full application development and modernization.

“F5 has collaborated closely with AWS for years, most recently on our SaaS offering, F5 Cloud Services. Together with AWS, we are providing a set of solutions that help enterprises deploy apps quickly and securely, while ensuring they are performant and comply with policy,” said Chad Whalen, Executive Vice President, Worldwide Sales at F5. “This aligns with our strategy of supporting modern DevOps practices and serving engineering teams with capabilities that create the most efficient path from code to customer.”


Enterprises are adopting the cloud to speed innovation cycles and create efficiencies, but today many companies must maintain separate data center and cloud environments, which drive up their operational costs, add complexity, and increase risk. These customers need a hybrid cloud solution that allows their applications to run with consistent performance and security regardless of the location. 

The work F5 and AWS do together addresses this need, allowing organizations to use F5 application services across all environments. Additionally, F5 solutions will make it easier for DevOps teams and application developers to provision, configure, and manage services via APIs or the web portal, without the need for deep networking or security expertise.

“The ability to deploy and run applications on AWS using F5 services is an important requirement for many customers that have standardized on F5 for application delivery and security,” said Mike Clayville, vice president, worldwide commercial sales and business development at AWS. “This Strategic Collaboration Agreement elevates our historic relationship with F5 to a higher level. It will be a great asset for customers as they build new cloud-native applications on AWS and move an increasing number of mission-critical workloads such as SAP and Windows to AWS.”

As part of the collaboration, F5 and AWS will work to allow customers to upgrade to F5’s application services, including F5 Cloud Services using cloud-native, SaaS-based application performance and security services; BIG-IP Virtual Edition with software-based, full-featured Layer 4–7 application delivery and security services; NGINX is a lightweight, highly scalable, and highly performant API management, and full-service proxy software built atop the open source web server; Silverline, its cloud-based managed services platform for application threat protection; and Aspen Mesh, an enterprise-ready, fully supported service mesh built on Istio.

“StockCharts.com is benefiting tremendously from the close collaboration between F5 and AWS,” said Chip Anderson, Founder and President of StockCharts.com. “By leveraging F5’s cloud solutions on AWS, our new cloud strategy is allowing us to provide our customers with a faster, more reliable, secure, and scalable set of web applications. We are now providing more insight and data, faster than ever before.”

Thursday, November 21, 2019

Kaspersky Sandbox automates protection from advanced threats, combats advanced threats

Kaspersky launched its new Kaspersky Sandbox designed to help organizations combat advanced threats intended to evade detection by endpoint protection platforms (EPP). 

The Kaspersky Sandbox solution is ideal for companies with no dedicated security team, where the IT security role is assigned to the IT department; small businesses that don’t want to incur additional IT security resources; large organizations with a geographically distributed infrastructure and without on-site IT security specialists; and companies who need to ensure that their full-time IT security analysts are fully focused on critical tasks.


The solution automatically analyzes new suspicious files and sends the results to the installed EPP. As a result, organizations are able to strengthen their protection from previously unknown threats, even if they lack teams of experienced threat analysts or have limited resources.


Unlike many threat intelligence services targeted at experienced security analysts, Kaspersky Sandbox does not require manual operations to examine the impact of suspicious files. When endpoint protection solutions detect a suspicious object that cannot be categorized as malicious without deeply analyzing its behavior, they automatically send it to run in Kaspersky Sandbox.

To detect the malicious intent of an object, Kaspersky Sandbox carries out behavioral analysis as well as collects and analyses all artefacts. In addition, if the object performs malicious actions such as encrypting or downloading a malicious payload using a zero-day exploit, the Sandbox recognizes it as malware and reports it to the endpoint protection solution for further actions.


Kaspersky Sandbox also stores the decision on whether or not the object is a threat in the operational cache located on the Kaspersky Sandbox server. With this feature in place, if the analysis of the file that has already been run in the Sandbox is requested by another endpoint within the managed network, the EPP gets the decision from this shared knowledge base without having to re-scan the file, speeding up the response and reducing the workload on servers of virtual machines.


According to a Kaspersky survey of IT decision-makers, 47 percent of SMBs and 51 percent of enterprises say it is becoming more challenging to differentiate between generic and advanced attacks. This means that security analysts have to spend more time evaluating numerous suspicious files instead of focusing on investigating and responding to the most critical threats.  

Saturday, November 9, 2019

McAfee MVISION Cloud is now a certified Data Loss Prevention provider for Microsoft Teams

McAfee announced that its cloud access security broker (CASB) technology is now Certified for Microsoft Teams. McAfee MVISION Cloud is now Certified for Microsoft Teams to serve the needs of partners and customers with a unified, cloud-native security platform that consistently protects their data and defends against threats in the cloud.

Teams is a chat-based workspace in Office 365 that brings together people, conversations and content—along with the tools that teams need—so they can easily collaborate to achieve more. It’s integrated with the familiar Office applications and is built from the ground up on Office 365. Since its debut on the market just a little over two years ago, Teams has quickly took a hold on the market with over 13 million active daily users. 


With McAfee MVISION Cloud for Microsoft Teams, companies can answer employees’ requests for a collaboration platform, while enforcing the security capabilities they need to keep data safe.

With McAfee MVISION Cloud, organizations can enforce sensitive data policies: prevent sensitive data that cannot be stored in the cloud from being uploaded to Teams; build sharing and collaboration guardrails: prevent sharing of sensitive or regulated data with unauthorized parties in Teams; and limit activities for users on unmanaged devices and untrusted networks: gain control over user access to Teams by enforcing context-specific policies limiting end-user actions.


The platform can also perform forensic investigations with full context: capture a complete audit trail of all user activity enriched with threat intelligence to facilitate post- incident forensic investigations. It can detect and correct user threats and malware: detect threats from compromised accounts, insider threats, privileged access misuse, and malware infection.

Teams is the hub for teamwork in Microsoft 365 that brings together people, conversations and content—along with the tools that teams need—so they can easily collaborate to achieve more. It’s integrated with the familiar Microsoft Office 365 applications and is built from the ground up on the Office 365, secure cloud. 

With McAfee MVISION Cloud for Microsoft Teams, companies can answer employees’ requests for a collaboration platform, while enforcing the security capabilities they need to keep data safe.

The offering will leverage McAfee’s content analytics engine to discover sensitive data uploaded to Microsoft Teams based on keywords and phrases indicative of sensitive or regulated information; pre-defined alpha-numeric patterns with validation such as credit card numbers; regular expressions to detect custom alpha-numeric patterns like part numbers; file metadata such as file name, size, and file type; fingerprints of unstructured files with exact and partial or derivative match; fingerprints of structured databases or other structured data files; and keyword dictionaries of industry-specific terms such as stock symbols.


“We worked to develop a solution that our customers can use to get visibility and control over their data and user activity in Microsoft Teams,” said Rajiv Gupta, senior vice president of Cloud Security, McAfee. “McAfee MVISION Cloud complements Microsoft Teams’ capabilities by using a frictionless, API-based, cloud-native approach that allows security professionals to provide data loss prevention, collaboration control, and contextual access control policies, address threats from insiders and compromised accounts, audit all user activity and secure corporate data as users collaborate in the cloud.”

“We’re pleased to see McAfee’s commitment to supporting and securing this ever-increasing demand,” said Levon Esibov, Partner PM Director, Information Protection, Microsoft Teams at Microsoft said. “McAfee MVISION Cloud integrates with Microsoft Teams APIs—ensuring our joint customers can successfully meet key security and compliance requirements.”

Thursday, November 7, 2019

Optiv Security debuts services for Microsoft Azure Sentinel to help enterprises simplify cyber operations

In an ever-evolving digital landscape, global organizations are increasingly migrating their business applications and workloads into cloud platforms, like Microsoft Azure. To assist global organizations transitioning to Microsoft Azure, Optiv Security offers progressive solution offerings around Microsoft Azure Sentinel that integrate cloud and security strategies with innovative expertise.

Optiv’s Advanced Fusion Center with Microsoft Azure Sentinel provides clients with fully tailored consumption models. Optiv’s services are tailored to individual organizational needs. First, Optiv takes a holistic view of a client’s cybersecurity operation and then provides flexible solutions, optimizing the client’s environment. 


Optiv offers co-sourced, managed and as-a-Service models that provide clients with options to power their current staffing, process and technology needs. Optiv’s services are built to scale and grow with clients as they evolve from a traditional SOC to components of a fully mature Advanced Fusion Center.

Optiv provides visualization, key performance indicators (KPIs), key risk indicators (KRIs) and reporting, allowing stakeholders to see the value and performance of their cybersecurity programs. It works with clients to replace the reactive Problem/Response approach with its inside-out approach, starting with risk mitigation and building out from there to create a more proactive, predictable, measurable and effective cybersecurity program. 


Optiv’s automation/orchestration technology is backed by the right people and processes, and is intended to drive and transform the functionality of cyber operations. This helps clients reduce repetitive manual tasks to speed up response times and increase efficiency.

Optiv brings cybersecurity to pace with modern business by leveraging many of the same core innovations already digitally transforming clients’ operations by fusing controls, data analytics, orchestration and automation with skilled cybersecurity experts to address threats with an integrated and more agile and proactive approach to radically change how cybersecurity is consumed and delivered. 

Optiv also provides actionable performance indicators, such as KPIs and key risk indicators (KRIs), allowing stakeholders to realize the value of their cybersecurity programs.


“The cybersecurity industry has historically been one based on problem and response, where external threats drive security spend and strategy,” said Chad Holmes, chief services and operations officer, Optiv. “When we combine our Advanced Fusion Center solutions with offerings like Azure Sentinel, we’ll be able to address the dynamic nature of today’s business operations, reduce complexity and operational costs, and enhance the speed and scale in which issues are remediated by integrating processes and people with leading technologies.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...