Showing posts with label threat. Show all posts
Showing posts with label threat. Show all posts

Friday, December 20, 2019

Anomali, Trend Micro identify credential harvesting campaign targeting government procurement sites

Multiple government procurement services were targeted by a credential harvesting campaign that uses bogus pages to steal login credentials. Cybersecurity company Anomali uncovered a campaign that used 62 domains and around 122 phishing sites in its operations and targeted 12 countries, including the United States, Canada, Japan, and Poland.

The Anomali Threat Research Team identified a credential harvesting campaign designed to steal login details from multiple government procurement services. The procurement services are used by many public and private sector organisations to match buyers and suppliers. 


In this campaign, attackers spoofed sites for multiple international government departments, email services and two courier services. Lure documents sent via phishing emails were found to contain links to spoof phishing sites masquerading as legitimate login pages relevant to the spoofed government agencies. Victims duped into following the phishing email link would then be invited to login. Anyone who fell victim to the adversaries would have provided them with their credentials.

This credential harvesting campaign has been primarily targeting government bidding and procurement services. The focus on these services suggests the threat actor(s) are interested in potential contractor(s) and/or supplier(s) for those governments targeted. The purpose of this insight could be a financial incentive to out compete a rival bidder, or more long term insight regarding the trust relationship between the potential supplier and the government in question. 


Campaigns like these are difficult to protect against because unless the domains hosting the phishing pages are known as malicious, an organisations firewall will not know to block it. Legitimate sites were also hosting the phishing pages, and were likely compromised as part of the campaign. At the time of writing none of the sites in this campaign were active, Anomali researchers consider it likely that the actors will continue to target these services in the future.

The use of bogus login pages continues to be a popular method for credential harvesting campaigns. The Trend Micro Cloud App Security solution blocked 2.4 million attacks of this type in the first half of this year — a 59 percent increase from 1.5 million in the second half of last year.

Organizations should look into adopting advanced technologies such as the Trend Micro Cloud App Security solution. It combines artificial intelligence (AI) and computer vision in order to help detect and block attempts at credential harvesting in real time. 

After suspected phishing emails go through sender, content, and URL reputation analyses, computer vision technology and AI will examine the remaining URLs to check if a legitimate login page’s branded elements, login form, and other website components are being spoofed.

For this campaign, threat actors used phishing emails carrying documents written in the language of the country being targeted. The phishing emails were also found with URLs to fake but legitimate-looking login pages. If the recipient of the phishing email clicks on the malicious URL, they will be redirected to a login page that is an imitation of a legitimate website the campaign is spoofing. A login attempt will then lead to the theft of the user’s credentials.


Aside from the websites of international government departments, those belonging to email services and two courier services were also spoofed by the threat actors. The U.S. Department of Energy, Canada’s Government eProcurement service, China’s SF-Express courier service, and Australia’s Government eProcurement Portal were some of the target organizations.

Email users should always be aware of the latest phishing tactics in order to avoid falling victim to credential harvesting attacks. After all, such attacks are becoming highly deceptive; in fact, it has become relatively easy for cybercriminals to obtain a .gov domain that they can use to further disguise their schemes.

To minimize the chance of becoming a victim, users can be cautious of emails from individuals or organizations that ask for personal information. Most companies will not ask for sensitive data from its customers, especially with stricter data privacy laws; look out for grammatical errors and spelling mistakes in suspicious emails. Emails from legitimate companies are often proofread to ensure that the materials they send out are error-free. 

Emails that call on a sense of urgency or have an alarmist tone should not be hastily acted on. If in doubt, recipients should verify the status of their accounts with their company’s system administrator or service provider.

Optiv Security expects election hacking, ‘hybrid threat actors’ to top the list of 2020 cyber threats

Optiv Security announced its cybersecurity industry predictions for 2020 and beyond. A focus on privacy, evolving threat actors, pervasive deepfake videos, and increased election interference are among the issues Optiv sees taking on greater importance in the New Year.


Optiv expects the most common issues that the industry may face in 2020 include hybrid threat actors may become more commonplace. Optiv’s 2019 Cyber Threat Intelligence Estimate (CTIE) found a growing number of “hybrid threat actors.” These are attackers who impersonate one type of adversary to disguise their true intentions (for example, a nation state imitating a generic hacker targeting a customer database, when its true aim is to steal intellectual property). 

Optiv believes a possible increase in the number of adversaries to adopt this technique and launch “imposter” attacks to obfuscate their true intentions, adding yet another layer of complexity to threat hunting and incident response.


Apple’s “privacy as a human right” campaign should cause others to follow. As the world’s foremost technology organization going all-in on privacy will shift the competitive landscape, security and privacy could become a competitive differentiator for companies that follow Apple’s lead and grab “first mover” status in their markets. Laggards may risk meeting the unseemly fate of past organizations that failed to embrace important technology paradigms such as internet, cloud, and mobile computing.

Election misinformation campaigns could proliferate. The effectiveness of the Russian misinformation campaign of 2016 increases the possibility of increased copycat attacks for the 2020 election. These attacks could come from nation states as well as domestic groups supporting rival U.S. politicians. This activity threatens to trigger a major public/private response to the online misinformation problem.


Optive expects to see the first cases of deepfakes used to manipulate stock prices. There has been much publicity around the potential to impact elections using deepfakes (AI-doctored videos that enable individuals to make it appear people said things they never said). However, not enough attention has been paid to how cybercriminals can make money using deepfakes against businesses. 

This might change in 2020, as it’s possible we will see the first deepfake attacks designed to impact stock prices, by having CEOs, financial analysts, Federal Reserve leaders or other powerful economic figures make phony statements that will cause stock market movements. Cybercriminals would use these videos to make quick fortunes in the market.

There should be widespread realignment of IT and security organizations. As boards view cybersecurity as a peer-level risk to traditional enterprise risks, such as lawsuits and product recalls, more CISOs should become peers of CIOs and other executives, rather than direct or indirect reports. This would cause a realignment of the IT and security organizations to eliminate conflicts and encourage collaboration. 


The most critical of these will be the continued expansion of DevSecOps, in which security is fully integrated into the application development process; and patch management, which will move from being divided between security and IT (security finds vulnerabilities, IT patches them), to becoming a unified process with a single point of accountability.

Cybersecurity basics may continue to vex consumers and enterprise organizations.Whether insufficient passwords, lack of education and training around phising attacks, or simple upkeep and compliance, the tiny details of cybersecurity will continue to be the cause of a vast portion of compromises if left unaccounted for. Simple passwords (those without special characters or are extremely obvious, such as “password123”) only take minutes to crack by professional hackers and can be done inexpensively.

“As we look beyond 2019 and into 2020, we have a solid idea of what threats the industry is facing, and not just ransomware and phishing attacks, but new, hard-to-combat threats,” said Anthony Diaz, Division Vice President, Emerging Services at Optiv. “As is always the case, us ‘good guys’ are forced to play catch up with bad actors, who constantly remain a step ahead. There is much IT and business leaders must be aware of when it comes to cybersecurity, as the pace of change is quite high. That is why we recommend cybersecurity programs focus on proactive risk mitigation and build out from there. This ensures your organization is actively looking for, combating, and identifying threats before they can cause damage.”

Friday, December 13, 2019

Barracuda boosts MSP offerings through integration of Content Shield Web Security Solution and Managed Workplace RMM

Barracuda Networks announced that it has integrated Barracuda Content Shield with Managed Workplace, its remote monitoring and management (RMM) platform. Managed service providers (MSPs) using the RMM can now leverage the cloud-based web security solution’s web filtering and malware protection to better protect their customers’ end users from web-borne threats. 


Barracuda Content Shield is a SaaS-based solution available at a per-user pricing model, which makes it easier for MSPs to scale based on demand.

Offering content filtering, malware protection, granular policy enforcement and reporting, Barracuda Content Shield works with existing antivirus (AV) solutions to protect against malicious files, stopping malware before it reaches the endpoint.


This integration helps MSPs enhance their end-user online security service offering with agent-based DNS and URL filtering; help protect their customers’ end-users from web-borne threats; and get at-a-glance visibility into threats prevented across all customers.

Additionally, through the combination of the two tools, MSPs will benefit from a centralized view of the threats detected and quarantined. If threats such as malicious files, domains, or URLs are discovered on any device connected by Barracuda’s threat intelligence network, every user is protected against that threat. 


“A recent survey by Spiceworks found that when companies don’t restrict internet activity, 58 percent of employees will spend at least four hours per week on websites unrelated to their jobs,” said Brian Babineau, senior vice president and general manager, Barracuda MSP. “And earlier this year, a study found that 40 percent of malicious URLs were located on good domains. These and other statistics point to the need for robust, easy-to-manage web content filtering that protects end-users from web-borne threats. Barracuda is answering that call with the integration of Barracuda Content Shield within Managed Workplace, a move that illustrates our commitment to providing our partners with a broad portfolio of security and data protection solutions spanning web, network, and e-mail, and backed by our global threat intelligence.”

Tuesday, November 26, 2019

Kaspersky reports that fraudulent browser push notifications as a means of phishing and advertising are gaining popularity

Kaspersky research revealed that the monthly number of affected users has grown from 1,722,545 in January to 5,544,530 in September 2019. In total, during the first nine months of 2019, Kaspersky products protected more than 14 million users from attempts to allow websites to show unwanted notifications. Given that essentially every web user is a potential victim, this threat, although unsophisticated, requires additional attention.



Browser push notifications were introduced several years ago as a useful tool that kept readers informed with regular updates, but they are often used to bombard website visitors with unsolicited advertisements or even encourage them to download malicious software. 


The detected options include passing subscription consent off as another action, such as a CAPTCHA; switching the “accept” and “decline” buttons on subscription alerts mid-action; showing notifications from phishing copies of popular websites; and showing fraudulent subscribe pop-ups on websites.


Useful, user-friendly features, such as push notifications, are easy-to-use instruments for scams based on social engineering techniques, and therefore their growing popularity is not entirely unexpected. In light of the recent calendar invitations scam detected by Kaspersky, the company’s experts decided to dive deeper into push notification scams and phishing to find out how this tool can be abused.



Since a user’s consent is required in order to start sending notifications, attackers have come up with multiple, often out-of-the-box ways to trick and force people to sign up for subscriptions. 


To avoid receiving annoying notifications or scam ads, users can where possible, block all subscription offers, unless they come from popular and trusted websites, and be vigilant to ensure that they are not redirected to a fake website. If the user is unable to avoid an unwanted subscription, block it in the browser settings.


Adoption of a reliable security solution, like Kaspersky Security Cloud, which blocks ad and scam push subscription offers in browsers, can delete subscriptions that have already been approved, and has an anti-phishing feature.

Thursday, November 21, 2019

Kaspersky Sandbox automates protection from advanced threats, combats advanced threats

Kaspersky launched its new Kaspersky Sandbox designed to help organizations combat advanced threats intended to evade detection by endpoint protection platforms (EPP). 

The Kaspersky Sandbox solution is ideal for companies with no dedicated security team, where the IT security role is assigned to the IT department; small businesses that don’t want to incur additional IT security resources; large organizations with a geographically distributed infrastructure and without on-site IT security specialists; and companies who need to ensure that their full-time IT security analysts are fully focused on critical tasks.


The solution automatically analyzes new suspicious files and sends the results to the installed EPP. As a result, organizations are able to strengthen their protection from previously unknown threats, even if they lack teams of experienced threat analysts or have limited resources.


Unlike many threat intelligence services targeted at experienced security analysts, Kaspersky Sandbox does not require manual operations to examine the impact of suspicious files. When endpoint protection solutions detect a suspicious object that cannot be categorized as malicious without deeply analyzing its behavior, they automatically send it to run in Kaspersky Sandbox.

To detect the malicious intent of an object, Kaspersky Sandbox carries out behavioral analysis as well as collects and analyses all artefacts. In addition, if the object performs malicious actions such as encrypting or downloading a malicious payload using a zero-day exploit, the Sandbox recognizes it as malware and reports it to the endpoint protection solution for further actions.


Kaspersky Sandbox also stores the decision on whether or not the object is a threat in the operational cache located on the Kaspersky Sandbox server. With this feature in place, if the analysis of the file that has already been run in the Sandbox is requested by another endpoint within the managed network, the EPP gets the decision from this shared knowledge base without having to re-scan the file, speeding up the response and reducing the workload on servers of virtual machines.


According to a Kaspersky survey of IT decision-makers, 47 percent of SMBs and 51 percent of enterprises say it is becoming more challenging to differentiate between generic and advanced attacks. This means that security analysts have to spend more time evaluating numerous suspicious files instead of focusing on investigating and responding to the most critical threats.  

Thursday, November 7, 2019

McAfee MVISION Cloud offers “Shift Left” with security to boost compliance and reduce risk on Microsoft Azure

McAfee announced updates to McAfee MVISION Cloud for Microsoft Azure that will help customers “Shift Left” with security to preemptively help to address compliance and risk within their cloud infrastructure. 

With McAfee MVISION Cloud, security is pushed earlier into the DevOps process so that security professionals can catch risky configurations before they become a threat in production. This gives organizations the ability to deploy applications in the cloud with greater speed and efficiency. 


While Infrastructure-as-a-Service (IaaS) and Platform-as-a-Service (PaaS) environments provide customers with choice and flexibility, if not configured correctly, they also potentially increase the organization’s surface area for security risks. 




McAfee detects compromised account activity in Azure based on brute force login attempts, logins from new and untrusted locations for a specific user, and consecutive login attempts from two locations in a time period that implies impossible travel – even if the two logins occur across multiple cloud services – to support immediate remediation and limit exposure.


McAfee automatically constructs a behavior model with dynamic and continuously updated thresholds for each user and group to identify activity indicative of insider threat. Privileged user analytics identifies risk from inactive administrator accounts, excessive permissions, and unwarranted escalation of privileges and user provisioning.


McAfee MVISION Cloud for Azure enforces DLP policies across data at rest and in motion to ensure compliance with regulations and internal policies. McAfee supports DLP rules based on keywords, data identifiers, user groups, and regular expressions. Enforcement actions include coach users, notify administrator, block, quarantine, and delete. Leverage pre-built industry templates, create custom policies in McAfee, or leverage policies in an existing on-premises DLP solution.



With the new features in McAfee MVISION Cloud for Azure, security groups can integrate policy natively into DevOps processes and toolsets to discover security issues before systems are deployed to accelerate business in the cloud. 


New capabilities include security scans for Azure Resource Manager templates that allow users to discover risky configuration issues or violations in Azure Resource Manager Templates prior to deploying resources. Its inline integration with the tools developers use: security checks inside the DevOps pipeline through API integration with tools including Microsoft Git, Github, and Azure DevOps. Security Feedback is natively integrated into the build process saving time, effort, and frustration.



The offering also offers unified cloud security for Azure ecosystem to allows developers to leverage Azure services knowing security will be built-in by design (IaaS/PaaS/Container services) aligning closely to the Cloud Security Posture Management (CSPM) best practices. Its preemptive risk avoidance improves compliance with regulatory frameworks and reduces the likelihood of data loss, abuse or fines associated with improper security controls by highlighting security findings before they become security incidents.


The new “Shift Left” capabilities in McAfee MVISION Cloud for Microsoft Azure are available now.

Friday, November 1, 2019

Borusan Holding adopts A10 Networks Thunder SSLi to protect network from hidden threats

A10 Networks announced that Borusan Holding has selected A10 Thunder SSL Insight to help protect its network from hidden threats that may come in with the growing amount of encrypted internet traffic. Thunder SSLi is a comprehensive SSL/TLS decryption solution that enables security devices to analyze enterprise internet traffic against potential threats.


The vast majority of web and application traffic is encrypted using SSL/TLS to ensure data integrity and privacy, not necessarily security. This creates real issues as security tools become blind to any nefarious activity happening in encrypted traffic - before the attack, during the attack, and even after the attack. Criminals take advantage of this and hide attacks in an enterprise’s encrypted traffic.

Guarding against such hidden threats is a top priority for Borusan. Volumes of encrypted web traffic were rising dramatically, driven by the adoption of Microsoft Office 365 and other cloud-based applications. Outbound SSL traffic was a growing blind spot.


Borusan evaluated the SSL inspection products and chose Thunder SSLi because of its interception technology, source-side NAT support, and integrated load balancing, which helps to distribute internet traffic between proxy appliances.


Thunder SSLi decrypts traffic across all ports, enabling third-party security devices to analyze all enterprise traffic without degrading performance. Thunder SSLi decrypts HTTPS traffic and forwards it in clear text to the firewall, proxy, IPS and deep-packet inspection solutions. Thunder SSLi then re-encrypts traffic and sends it off to its final destination.


“Today, encryption has become ubiquitous. And while encryption can ensure the privacy of the data, it can put enterprises at risk,” said Yasir Liaqatullah, vice president of product management at A10 Networks. "Cyber criminals are increasingly taking advantage of encrypted traffic to launch phishing and ransomware attacks, and to spread viruses and Trojans embedded into documents. Thunder SSLi is a high-performance, dedicated SSL inspection solution that allows enterprises to remove the blind spots while maintaining compliance with privacy standards.”

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...