FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Wednesday, October 30, 2019

Security Congress: Securing a Rapidly Changing Environment

Congress SessionThe cyber ecosystem is changing faster than ever, creating new attack surfaces and increasing the challenge of defending against new and evolving threats. The fast-changing landscape requires new ways of thinking and approaches to protect environments that spread across on-premise and cloud infrastructures and connect IT with OT (operational technology) systems.

Just accepting that the expansion of the ecosystem – and the growing presence of technology in our lives – will increase risk isn’t good enough. This is a point (ISC)2 CEO David Shearer made clear at the kickoff of the organization’s Security Congress 2019 this week in Orlando. We cannot accept the idea that “expansion of the cloud must expose us to greater risk instead of greater opportunity,” he said. “As technology becomes more and more prevalent, so too must cybersecurity.”

Of course, developing cybersecurity tools and policies to keep up with new threats is not an easy task. But there is also opportunity in the expansion of the cyber ecosystem, said Curtis Keliiaa, Senior Network Engineer and Principal Investigator at the U.S. Department of Energy’s Sandia National Laboratories.

As new standards such as the IPv6 (Internet Protocol, version 6) specification and the 5G cellular network take hold, the opportunity arises for introducing security controls upfront, Keliiaa said. Both IPv6 and 5G will require the implementation of new hardware, applications and security. Referring specifically to IPv6 during a session on the evolving cyber landscape, he said: “Right now, we have a chance to build security like we never have. Now we know how bad the cyber problem is,” he said.

Data is the focus, he said. As data moves around widely dispersed connected systems, cybersecurity teams need to “follow the data,” Keliiaa said. Data owners are transitioning into the role of data stewards, which requires an understanding of what and where the data is in order to protect it.

The IPv6 specification is intended to replace the older IPv4, but it will be some time before that actually happens. In the meantime, both standards will be in use side by side, creating complexity and challenges in managing risk.

IPv6 needs champions who will approach the C-suite and make a case for migration, Keliaa said. When talking to executives, he advised: “Be right; don’t talk opinion. Be fast; don’t waste their time.” Executives have a lot on their plates besides managing risk; they also have to think about increasing profits and managing the entire organization efficiently.

Cloud Challenges

An example of how changes in technology impact cybersecurity involves penetration testing of cloud systems. Mike Weber, CISSP, vice president of Coalfire Labs, said that moving assets to the cloud adds complexity to the process – and it’s not possible to test everything. With that in mind, he told attendees at Security Congress to put a plan together for cloud penetration tests.

The plan should include rules of engagement, a timetable and methodology. It’s essential to identify the scope, he said. “Your objective needs to be narrow enough so you don’t have to boil the ocean. If you try to test all of an organization’s cloud, then you’re going nowhere.”

Weber stressed the importance of asking permission from cloud providers before doing a test. Unfortunately, different cloud service providers have different sets of rules for testing. If the test involves two or more providers, getting approval from all of them can be time-consuming and delay projects. Thankfully, he said, the rules are starting to converge and these issues eventually will go away.

The post Security Congress: Securing a Rapidly Changing Environment appeared first on Cybersecurity Insiders.


October 31, 2019 at 09:09AM

Security Visibility is Mission-Critical

IaaS has continued to evolve and make it easier for companies to set up public cloud infrastructure faster than ever. Many are doing just that and moving more and more workloads to cloud environments. Although in these new, dynamic environments where changes happen often, and fast, security is mission-critical, but achieving security visibility is still a challenge for security teams.

The same properties that make a dynamic cloud environment attractive to businesses often add complexity to matters of security and compliance—a daunting challenge for quickly evolving, agile businesses, as well as those with legacy systems resistant to change.

If you’re hosting critical applications in public cloud infrastructure, security and compliance visibility should be a top priority. Without it, you might be in for some very unpleasant surprises. 

Security Visibility is Mission-Critical in IaaS

In today’s business environment, the core value of many organizations depends on their digital footprint. Unauthorized access or damage to their cloud infrastructure poses a significant risk to the business. That’s why an effective cloud security solution should help you do three things:

  1. Prevent data breaches – Protect your business from risk, protect your customers from exposure, and show your meeting compliance requirements.
  2. Protect infrastructure assets – Your business processes depend on them, which makes them critical to your company, that’s why attackers want to subvert them for their own purposes or to disrupt business operations.
  3. Maintain compliance – If you can protect the business from risk, you can comply with regulators, and fulfill contractual requirements.

When the needs of a business expand to require diverse methods of data access and storage, often as a result of enabling competitive advantage, the risk of potential exposure increases. To manage business risk and protect customers, it is critical to maintain complete visibility into this rapidly changing landscape and its security posture.

Share Security Model
While CSPs do a great job of providing a secure foundation across physical, infrastructure, and operational security. You maintain responsibility for protecting the security of your application workloads, data, identities, on-premises resources, and all the cloud components that you control within your public cloud infrastructure—referred to as the “Shared Responsibility Model.” 

Maintaining your part of the shared security model is critical but a complex task. The very nature of these distributed systems can make it difficult to obtain accurate and up-to-date security visibility and inventory of cloud assets. In addition, rapid growth across multiple environments can make it nearly impossible to consistently apply best practices for security and compliance. 

The most prominent breaches today typically involve the loss of data. Even where there is no direct harm to business operations, potential repercussions to customers, partners, and the public add legal, compliance, and marketing risk to the direct impacts of an attack. 

Security is Challenging in IaaS Environments

The scale and speed of IaaS environments are bigger and much faster compared to traditional IT environments, with the number of assets in your public cloud potentially growing rapidly, and exponentially. Before you know it you could have thousands or tens of thousands to track and manage.

In addition, companies taking advantage of public cloud infrastructure often create and maintain many cloud services accounts. Reasons vary—for example, different accounts might be used by different business units or to separate development and production environments. 

Whatever the reason, every account is a potential target for attackers, meaning complete security visibility and continuous monitoring for exposures is key to maintaining security across your cloud infrastructure. 

User-error Causes Security Vulnerabilities
Add to the challenge of simply managing a multitude of accounts, all t
he chances for human error on the numerous configuration items in public cloud infrastructure, and you have a recipe for disaster.

Misconfiguration of the AWS cloud platform took the number one spot in this year’s AWS Cloud Security Report as the single biggest vulnerability to cloud security (62%), followed by unauthorized access through misuse of employee credentials and improper access controls (55%) and insecure interfaces/APIs (52%)

Without security automation, securing your cloud infrastructure has become almost impossible, so making sure you select the right cloud security solution is key to meeting your cloud infrastructure security requirements.

Public Cloud Security Solution Checklist

Your ideal cloud security visibility infrastructure solution should be:

  • FAST – Aligns with dynamic IaaS. Automatic deployment and assessment
  • PORTABLE – Works across multiple IaaS providers and components  
  • SCALABLE – Expands or contracts to meet shifting needs
  • INTEGRATED – Visibility mechanisms are part of the infrastructure
  • CONTINUOUS – Supports rate of change demands with continuous issue visibility
  • COMPREHENSIVE – Covers all critical aspects of both security and compliance
  • ACTIONABLE – Presents actionable security and compliance intelligence

Halo Meets Key Cloud Security Requirements

CloudPassage has built the Halo platform to help security teams deal with the challenges of cloud infrastructure, as well as maximize its benefits and opportunities. By optimizing and automating security visibility, it helps your team boost security defenses, streamline operations, and ensure compliance across your public cloud and hybrid infrastructure.

Better still, it provides immediate short term value by:

  • Enabling immediate discovery and visibility of all your assets across your cloud infrastructure, at a high level, and rapid rollout of deeper visibility into workloads
  • Providing the basis for building out advanced security programs by enabling you to implement internal security policies and roll them out in a structured way, as well as automate remediation and make DevOps a force multiplier

Download our white paper: Achieving Complete Security Visibility for Public Cloud Infrastructure to learn more about the challenges of security visibility in these dynamic environments, the characteristics of an effective solution and how Halo can help keep your clouds safe and compliant.

The post Security Visibility is Mission-Critical appeared first on Cybersecurity Insiders.


October 31, 2019 at 09:09AM

Physical threats to Cybersecurity that you must address

Photo by Nahel Abdul Hadi on Unsplash
Over 90% of data breach is attributed to human error costing a company anywhere from $1.25 million to $8.19 million. Tackling cybersecurity does not only entail non-physical risks, but also includes an assessment of physical threats such as human, internal, and external hazards. Only then can an appropriate and effective security plan to dissuade hackers and thieves be devised.
Internal and External Risks
Internal dangers may include fire or unstable power supply. Another risk is humidity which can cause the appearance of mold that will damage data and equipment. Mold remediation and regular maintenance of the heating, ventilation, and air-conditioning (HVAC) system are necessary to ensure that equipment is stored properly.
While lightning, flood, and earthquakes are difficult to predict, preparing a comprehensive risk assessment is the first step. A detailed plan on what to do if…

Karoline Gore Posted by:

Karoline Gore

Read full post

      

The post Physical threats to Cybersecurity that you must address appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:09PM

Cyber Attacks on Asian Ports cost $110 Billion

A survey conducted by London firm Lloyd says that the cyberattacks on Asian Ports could cost as much as $110 Billion which is equal to the loss borne by natural catastrophes in 2018. Therefore, covering commercial risks has become a lucrative earning option for insurance providers having businesses in Europe, Asia, and the United States.

 

Lloyd’s report also states that the past year witnessed the disruption of operations in more than 15 ports running in Japan, Malaysia, Singapore, South Korea, and China. However, the bad news is that more than $101 billion assets remain uncovered by any insurance cover which might prove disastrous in the near time.

 

Readers of Cybersecurity Insiders have to notify that the report was compiled after the Financial Firm simulated a malware-based cyber-attack by ships which usually leads to disruption of services and scramble of database records at the ports.

 

As Asia is home to a few of the world’s largest ports, any disruption could lead to a major economic loss as these ports act as commercial hubs to transport industrial goods, automobiles, clothing, and electronic goods.

 

Besides those countries which are linked to these ports will also witness a deep impact, leading to temporary or permanent business closures.

 

Note 1- The report was compiled by researchers from the University of Cambridge for Risk Studies- as a part of the Cyber Risk Management (CyRIM) Project sponsored by Lloyd’s.

 

Note 2- China, Malaysia, Singapore, and South Korea are reported to be home to Asia’s largest ports.

 

The post Cyber Attacks on Asian Ports cost $110 Billion appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:09PM

Security Congress Day 2: From PAM to Cyber Insurance to Finding a Voice

Breakout sessionWhile cybersecurity spending is expected to hit $124 billion this year, only a small portion of it will go toward identity management. Yet, a disproportionate number of breaches occur because of flaws in access management and dangerous practices such as the sharing of passwords, according to Tariq Shaikh, CISSP, Senior Security Advisor for CVS Health.

Identity management spending accounts for 5% to 10% of total cybersecurity spend. When it comes to privileged access management (PAM), Shaikh said the portion is even smaller — 1%. It’s time to change that, he argued during a session on PAM at the (ISC)2 Security Congress 2019, taking place in Orlando this week. Considering how many breaches result from access management issues, Shaikh said PAM can substantially reduce the number of security incidents.

Shaikh’s presentation was one of dozens of sessions on the second full day of Security Congress, covering a range of topics, including challenges around cybersecurity protection, how to cope with data privacy and security regulations, and how to find your voice as a professional to make yourself heard.

“Your ability to secure your assets depends on how well you manage privileged access,” Shaikh said. “It’s the critical attack vector.” He added that PAM isn’t a one-and-done situation, but rather an ongoing endeavor that requires updating to keep up with the evolution of the threat landscape.

He shared a list of best practices for PAM implementation, which includes separating user accounts and infrastructures for routine business and privileged activities, using a centralized enterprise authentication solution, removing privileged access from users who don’t need it, and keeping track of who has privileged access and their activities.

To build a business case for PAM, Shaikh recommended communicating the objectives of the PAM program and the changes it will bring, using simple language, and developing informational materials about it such as FAQs and tutorials.

Cyber Insurance

During a session on cyber insurance, Lisa Angelo, Principal at the Angelo Law Firm, and Seth Jaffe, General Counsel and Vice President of Incident Response at LEO Cyber Security, discussed several ongoing court cases involving companies that bought cyber insurance policies. In many cases, insurers have denied claims for a number of reasons.

One claim involving healthcare records, Columbia Casualty Co. v. Cottage Health System, was denied because medical records that were breached had been stored in an unsecured system accessible through the internet.

In another case, Mondelez v. Zurich, the insurer invoked an Act of War exclusion to turn down a claim after a company suffered two NonPetya ransomware attacks that affected 24,000 laptops. At one point, the insurer agreed to pay $10 million but took too long to pay. The customer threatened to sue and later Zurich rescinded the settlement offer.

These legal disputes, Jaffe and Angelo said, deliver important lessons on how to approach negotiations with insurers when taking out a cyber policy. Mondelez, for instance, demonstrates the need for explicitly excluding acts of cyber terrorism from an Act of War clause.

It’s important to understand what the policy covers before signing a contract, Angelo said.

“Pay attention to what you’re signing up for and work with them to see what you can negotiate.”

Finding Your Voice

A late-afternoon panel discussion focused on knowing how to speak up to “sell yourself in your career, business and life. Panelists advised attendees to find ways to communicate effectively, not only through public speaking but also through writing, video and audio recordings. A strong focus was placed on understanding what your audience wants and finding ways to deliver the content effectively.

“It’s more about the audience than it is about me when I give a talk,” said Keri Pearlson, Executive Director and Principal Investigator of Cybersecurity at the MIT Sloan School of Management’s research consortium. It’s important to listen so you can deliver the right message, she added.

Another panelist, Katzcy CEO Jessica Gulick, spoke about timing, giving out content in digestible pieces, and repeating information when necessary. Make the information relevant to your audience, and resist the temptation to make it about you, she said. “If you want it to be sticky, make it relatable. Give them a framework so that they can remember.”

The post Security Congress Day 2: From PAM to Cyber Insurance to Finding a Voice appeared first on Cybersecurity Insiders.


October 30, 2019 at 09:08PM

Tuesday, October 29, 2019

Facebook sues Israeli firm NSO for spying on 1400 targets via WhatsApp malware

Facebook has issued a press update yesterday saying that an Israeli firm named NSO group has used malware tactics to spy on 1400 targets across the world between April- May 2019 via WhatsApp. The social networking giant is intending to sue the firm for carrying malpractices and will be contacting all affected customers individually by detailing them about the cyber attack.

 

Chances are high that Facebook might intend to block the company soon from using its service on a permanent note as it has violated laws including the US Computer Fraud and Abuse Act.

 

News is out that a research company named Citizen Lab has given a hint about the breach to Facebook early last week after it was hired to survey some of the users of WhatsApp.

 

It is said that at least 100 cases of journalists or human rights activists were targeted by the attack which took place across 20 different countries including Africa, Asia, Europe, the Middle East, and North America.

 

Cybersecurity Insiders has learned that NSO indulged in spying deeds after it was acquired by Novalpina Capital, a private firm from London.

 

Note 1- NSO is widely known to sell spying software to government agencies and hackers across the world. However, the company claims that its company’s objective is to sell its spyware strictly to government clients only and has secured a license to do from the Israeli Government.

 

Note 2- NSO is reported to have carried surveillance through its Pegasus spyware on a small section of WhatsApp users by hacking into the smartphones of users through a mobile security flaw. But as the activity done by orders from any government is yet to be probed by Facebook.

The post Facebook sues Israeli firm NSO for spying on 1400 targets via WhatsApp malware appeared first on Cybersecurity Insiders.


October 30, 2019 at 10:42AM

Google Pay users get Biometrics Security

All those who use Google Pay for making digital payments might feel happy by knowing that the technology giant has introduced Biometrics security to allow users to protect their online transactions using fingerprint and facial recognition features.

The feature can be seen in the latest 2.100 version of the app and will be rolled out across the digital wallet platform in the next few days.

As a result of this payment security update, users can also opt for biometrics API so that they can use fingerprints or facial recognition to authenticate a money transfer along with the option of using the regular PIN inputs.

Users who have tested the feature are reportedly finding their transactions being processed faster than the regular PIN security.
Currently, the Biometric addition feature will only be available to users using Google Pay app on the Android 10 version. But pretty soon it will also be rolled out to those using the Android 9 operating system on their devices.

To those who haven’t heard about Google Pay, it is just a rebranded digital payment version of UPI based TEZ app which was launched in the year 2017. In the year 2018, Google renamed TEZ as Google Pay which now has more than 67 million active users around the world.

Also from now on, all Google Pay users will get SMS notifications on their respective mobile phones that any request approval will deduct money from their respective bank account linked to the Google Pay wallet on a respective note.

NOTE- Android 10 happens to be the latest mobile operating system of Google which was released on September 3rd of 2019. It was first released in March this year to Pixel smartphones and might be introduced into foldable smartphones released by Samsung and LG early next year. Google has announced that the Android 10 version of OS will get guaranteed security updates for the next three years. Also, the OS is speculated to bring in a revolution among 5G smartphone users by offering greater protection, transparency, and control over data.

The post Google Pay users get Biometrics Security appeared first on Cybersecurity Insiders.


October 30, 2019 at 10:38AM