Showing posts with label threat intelligence. Show all posts
Showing posts with label threat intelligence. Show all posts

Saturday, December 21, 2019

YubiKey for RSA SecurID Access offering helps address growing digital risks with enterprise-grade FIDO authentication capabilities

RSA will extend its enterprise offering of modern authentication and identity assurance through an alliance and joint solution with Yubico. The solution, YubiKey for RSA SecurID Access, set to be available by March 2020, combines a FIDO2-enabled hardware device by Yubico with the benefits of enterprise-grade security, risk-based authentication and simplified credential lifecycle management delivered by RSA SecurID Access.


In a dynamic workforce, users expect a frictionless experience, regardless of where they are or what applications they are accessing. At the same time, organizations want to reduce the risk of security breaches, secure critical assets and minimize the costs associated with credential lifecycle management. 



Stolen identity is a critical security issue, and often the weakest link in security postures. In fact, 80 percent of breaches involve compromised and weak credentials and last year security breaches cost companies an average of $3.86 million per breach.


As organizations continue to pursue digital transformation initiatives, identity management has become increasingly complex. Continuing leadership in authentication and identity assurance, the strategic partnership will add to the range of authentication methods offered in the RSA SecurID Access Suite. 


RSA and Yubico will address a variety of workforce use cases with a simple login experience enabled by the YubiKey for RSA SecurID Access and backed by the enterprise-grade security of RSA SecurID Access. The YubiKey complements the existing range of authentication methods of RSA SecurID Access including push notification, one-time password, SMS and biometrics to enable the broadest support for diverse user populations and use cases. 


FIDO authentication is uniquely suited for use cases like passwordless logon to PCs and laptops and mobile-restricted environments (e.g., call centers). The joint solution will also provide identity insights, threat intelligence, and business context for user access, devices, applications and behavior to provide businesses with the confidence that users are who they say they are.


RSA SecurID Access provides the backend software and services required for a full range of authentication options like the YubiKey for RSA SecurID Access to be successfully deployed, managed and used across an enterprise environment. 


RSA SecurID Access bridges islands of identity, and with one of the strongest partner ecosystems in the industry (RSA Ready), RSA SecurID Access provides a unified platform for secure enrollment, access control, policy enforcement and lifecycle management across all of an enterprise’s applications from data center, endpoint and network perimeter to the cloud. 



For customers, this enables features like secure (multi-factor) enrollment, self-service, emergency access, and a single FIDO registration across all enterprise applications. It also provides broader compatibility and a consistent user experience for YubiKeys within the enterprise.


RSA is a longstanding member of the FIDO Alliance as well as a member of the Board of Directors. As a market leader in multi-factor authentication, RSA is committed to supporting the new FIDO2 standard and providing best practices for FIDO deployment in the enterprise with RSA SecurID Access.


“Our partnership with RSA demonstrates a shared commitment to protect millions of users from security breaches,” said Jerrod Chong, Chief Solutions Officer, Yubico. “This collaborative effort combines RSA’s long-standing expertise in identity and access management, with Yubico’s proven leadership in standards and innovation, to bring forward a unified FIDO-based hardware authentication solution for enterprises, their partners and their customers.”


“With ongoing support for FIDO, RSA continues to deliver modern authentication solutions and identity assurance to help enterprises meet business needs, provide a range of authentication options for users and protect their most valuable assets,” said Jim Ducharme, VP of Identity and Fraud & Risk Intelligence Products, RSA. “The strategic partnership extends our support for FIDO in RSA SecurID Access allowing integration with applications from ground to cloud to address the evolving threats and challenges in today’s dynamic workforce.”

Friday, December 13, 2019

Barracuda boosts MSP offerings through integration of Content Shield Web Security Solution and Managed Workplace RMM

Barracuda Networks announced that it has integrated Barracuda Content Shield with Managed Workplace, its remote monitoring and management (RMM) platform. Managed service providers (MSPs) using the RMM can now leverage the cloud-based web security solution’s web filtering and malware protection to better protect their customers’ end users from web-borne threats. 


Barracuda Content Shield is a SaaS-based solution available at a per-user pricing model, which makes it easier for MSPs to scale based on demand.

Offering content filtering, malware protection, granular policy enforcement and reporting, Barracuda Content Shield works with existing antivirus (AV) solutions to protect against malicious files, stopping malware before it reaches the endpoint.


This integration helps MSPs enhance their end-user online security service offering with agent-based DNS and URL filtering; help protect their customers’ end-users from web-borne threats; and get at-a-glance visibility into threats prevented across all customers.

Additionally, through the combination of the two tools, MSPs will benefit from a centralized view of the threats detected and quarantined. If threats such as malicious files, domains, or URLs are discovered on any device connected by Barracuda’s threat intelligence network, every user is protected against that threat. 


“A recent survey by Spiceworks found that when companies don’t restrict internet activity, 58 percent of employees will spend at least four hours per week on websites unrelated to their jobs,” said Brian Babineau, senior vice president and general manager, Barracuda MSP. “And earlier this year, a study found that 40 percent of malicious URLs were located on good domains. These and other statistics point to the need for robust, easy-to-manage web content filtering that protects end-users from web-borne threats. Barracuda is answering that call with the integration of Barracuda Content Shield within Managed Workplace, a move that illustrates our commitment to providing our partners with a broad portfolio of security and data protection solutions spanning web, network, and e-mail, and backed by our global threat intelligence.”

Trend Micro warns against sighting of ransomware bugs, Snatch and Zeppelin

Two ransomware families – Snatch and Zeppelin – with noteworthy features were spotted this week. Snatch ransomware is capable of forcing Windows machines to reboot into Safe Mode. Zeppelin ransomware, on the other hand, was responsible for infecting healthcare and IT organizations across Europe and the U.S.

Snatch reboots infected machines into Safe Mode to bypass security software and encrypt files without being detected. It was designed to do this because security software often do not run in Windows Safe Mode, since it’s meant for debugging and recovering a corrupt operating system (OS).


Researchers at SophosLabs found that the ransomware operators use a Windows registry key to schedule a Windows service called SuperBackupMan, which can run in Safe Mode and cannot be stopped or paused. The malware even goes further by deleting all volume shadow copies on the system, thus preventing the forensic recovery of encrypted files.

Snatch ransomware, first discovered back in 2018, does not target home users or use mass distribution methods such as spam campaigns or browser-based exploits. Instead, the malware operators go after a small list of targets that include companies and government organizations. The operators were also found recruiting hackers on hacking forums and stealing information from target organizations.


Zeppelin, which is a new variant of the VegaLocker/Buran ransomware, was spotted (with compilation timestamps no earlier than November 6, 2019) infecting companies located in Europe and the U.S. through targeted installs. Reported by BlackBerry Cylance, the Zeppelin ransomware, also a ransomware-as-a-service (RaaS) family, was found being used to infect certain healthcare and IT companies.

Zeppelin ransomware appears to be highly configurable and can be deployed as a .dll or .exe file, or wrapped in a PowerShell loader. Aside from encrypting files, it also terminates various processes, including those associated with backup, database, and mail servers. Zeppelin executables were found wrapped in three layers of obfuscation. Its ransom notes range from generic messages to elaborate notes tailored to specific organizations. Notably, it appears Zeppelin ransomware is not being widely distributed — or at least not yet.

The researchers believe that Zeppelin, similar to Sodinokibi ransomware, is being spread through managed service providers (MSPs) to further affect customers. Moreover, the ransomware can also be distributed through malvertising operations and watering hole attacks.


Aside from maintaining an up-to-date operating system to address exploitable vulnerabilities, users should adopt the standard best practice of backing up data via the 3-2-1 rule. Users can also consider deploying comprehensive, multilayered security solutions that will protect against ransomware attacks coming from different entry points. 

Trend Micro advises users and organizations to secure ports and services that are exposed on the internet; enable multi-factor authentication to protect admin accounts from potential brute-force attacks; secure remote access tools as they can be used as entry points; employ the principle of least privilege and regularly monitor the network for threats; and perform regular password audits for stronger access control to help prevent ransomware attacks.

Trend Micro solutions such as the Smart Protection Suites and Worry-Free Business Security solutions, which have behavior monitoring capabilities, can protect users and businesses from these types of threats by detecting malicious files, scripts, and messages as well as blocking all related malicious URLs. 

Trend Micro XGen security provides a cross-generational blend of threat defense techniques against a full range of threats for data centers, cloud environments, networks, and endpoints. It infuses high-fidelity machine learning with other detection technologies and global threat intelligence for comprehensive protection against advanced malware.

Thursday, December 12, 2019

Kaspersky finds zero-day exploit in Windows OS used in targeted attack, part of malicious WizardOpium operation

Kaspersky automated detection technologies have found a Windows zero-day vulnerability. The exploit based on this vulnerability allowed attackers to gain higher privileges on the attacked machine and avoid protection mechanisms in the Google Chrome browser. The newly discovered exploit was used in the malicious WizardOpium operation.

Zero-day vulnerabilities are previously unknown bugs in software, which, if found by criminals first, enable them to operate unnoticed for an extended period of time, inflicting serious and unexpected damage. Regular security solutions do not identify the system infection nor can they protect users from a yet-to-be-recognized threat.


The new Windows vulnerability was found by Kaspersky researchers as a result of a separate zero-day exploit. In Nov 2019, Kaspersky’s Exploit Prevention technology, which is embedded in most of the company’s products, detected a zero-day exploit in Google Chrome. 

This exploit allowed attackers to execute arbitrary code on a victim’s machine. Upon further research of this operation, which the experts called ‘WizardOpium,’ another vulnerability was discovered, this time in Windows OS.


It emerged that the newly discovered Windows zero-day elevation of privileges (EoP) exploit, CVE-2019-1458, was embedded into a previously discovered Google Chrome exploit. It was used to gain higher privileges in the infected machine as well as to escape the Chrome process sandbox – a component built to protect the browser and the victim’s computer from malicious attacks.
  
Detailed analysis of the EoP exploit showed that the abused vulnerability belongs to the win32k.sys driver. The vulnerability could be abused on the latest patched versions of Windows 7 and even on a few builds of Windows 10 (new versions of Windows 10 have not been affected).


“This type of attack requires vast resources. However, it gives significant advantages to the attackers and, as we can see, they are happy to exploit it,” said Anton Ivanov, security expert at Kaspersky. “The number of zero-days in the wild continues to grow and this trend is unlikely to go away. Organizations need to rely on the latest threat intelligence available at hand and have protective technologies that can proactively find unknown threats such as zero-day exploits.”

Saturday, November 2, 2019

Rackspace chooses Armor to deliver improved security for hybrid cloud environments

Rackspace announced that it has selected Armor, provider of cloud security-as-a-service solutions, to deliver security for hybrid cloud environments to customers worldwide. Armor’s next-generation cloud security platform, Armor Anywhere, will be integrated into Rackspace’s comprehensive portfolio of security services for all major private and hyperscale public clouds, creating complete hybrid cloud security solution on the market.

The Armor Anywhere service uses an agent installed across on-premise, cloud, or hybrid environments. The Armor Anywhere agent uses ideal security capabilities to secure the environment. 


Once installed, the Armor Anywhere agent defends the environment at the host level, monitoring inbound and outbound traffic, gathering logs, monitoring changes to critical les, and providing customers with patch status and updates. The Armor Anywhere agent is lightweight and can be deployed in under 2 minutes.

Security results from the Armor Anywhere agent provide valuable data to Armor’s SOC, where experts manage and secure systems and workloads—monitoring both inbound and outbound traffic at the host—and identify malicious threats in real-time to enable quick response and containment before larger issues occur.

Armor Anywhere is made up of multiple detection tools which are deployed into a customer’s IT environment via a lightweight software component. The platform collects, correlates and analyzes millions of events and logs from various network and cloud native tools to produce enriched, correlated event data, which is ready for triage and action from Rackspace’s security experts.


Rackspace offers a comprehensive portfolio of security and compliance services for all major private and hyperscale public clouds – including 24x7x365 proactive threat detection and response services from Rackspace’s global Security Operations Center (SOC), with locations in San Antonio and London. 

Rackspace integrates with all of the hyperscale cloud control planes to offer customers hybrid cloud security capabilities, including, but not limited to, host and network protection, threat intelligence and security analytics, log management, vulnerability scanning, and compliance assistance services.


“To handle threats effectively, enterprises need a platform that consolidates threat intelligence, security analytics, alerts and response,” said Vikas Gurugunti, EVP and GM, Rackspace Solutions and Services. “Rackspace’s security services, coupled with the powerful detection and analysis capabilities of Armor Anywhere, will give our customers a high-quality security solution focused on hybrid cloud security outcomes. This new collaboration ensures that we accelerate the value of the cloud and deliver Fanatical Experience during every phase of our customers’ digital transformation.” 

“Armor is honored to be working with Rackspace,” said Armor CEO Mark Woodward. “Rackspace goes beyond simply helping organizations manage their IT infrastructure and migration to the cloud. They are a proven leader in helping customers securely transform their entire organization across every phase of their digital journey. Armor’s market-leading cloud security solutions have successfully helped to protect organizations’ sensitive data for 10 years. By working together, I am confident that Rackspace will have the most comprehensive, secure and business-enabling managed cloud security services in the market.”

The integration of Armor’s technology and capabilities into Rackspace’s security service offerings will be made available to customers in 2020. 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...