FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Thursday, April 20, 2023

How Can You Identify and Prevent Insider Threats?

The content of this post is solely the responsibility of the author.  AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. 

If cyber threats feel like faceless intruders, you’re only considering a fraction of the risk. Insider threats pose a challenge for organizations, often catching them by surprise as they focus on securing the perimeter.

There is a bright side, however. Understanding the threat landscape and developing a security plan will help you to mitigate risk and prevent cyber incidents. When designing your strategy, be sure to account for insider threats.

What is an insider threat?

Perhaps unsurprisingly, insider threats are threats that come from within your organization. Rather than bad actors from the outside infiltrating your network or systems, these risks refer to those initiated by someone within your organization – purposefully or as a result of human error.

There are three classifications of insider threats:

  • Malicious insider threats are those perpetrated purposefully by someone with access to your systems. This may include a disgruntled employee, a scorned former employee, or a third-party partner or contractor who has been granted permissions on your network.
  • Negligent insider threats are often a matter of human error. Employees who click on malware links in an email or download a compromised file are responsible for these threats.
  • Unsuspecting insider threats technically come from the outside. Yet, they rely on insiders’ naivety to succeed. For example, an employee whose login credentials are stolen or who leaves their computer unguarded may be a victim of this type of threat.

Keys to identifying insider threats

Once you know what types of threats exist, you must know how to detect them to mitigate the risk or address compromises as quickly as possible. Here are four key ways to identify insider threats:

Monitor

Third parties are the risk outliers that, unfortunately, lead to data compromise all too often. Monitoring and controlling third-party access is crucial to identifying insider threats, as contractors and partners with access to your networks can quickly become doorways to your data.

Consider monitoring employee access as well. Security cameras and keystroke logging are methods some companies may choose to monitor movement and usage, though they may not suit every organization.

Audit

Pivotal to risk mitigation – for insider threats or those outside your network – is an ongoing auditing process. Regular audits will help understand typical behavior patterns and identify anomalies should they arise. Automated audits can run based on your parameters and schedule without much intervention from SecOps. Manual audits are also valuable for ad hoc reviews of multiple or disparate systems.

Report

A risk-aware culture is based on ongoing communication about threats, risks, and what to do should issues arise. It also means establishing a straightforward process for whistleblowing. SecOps, try as they might, cannot always be everywhere. Get the support of your employees by making it clear what to look out for and where to report any questionable activity they notice. Employees can also conduct self-audits with SecOps’ guidance to assess their risk level.

Best practices for prevention

Prevention of insider threats relies on a few key aspects. Here are some best practices to prevent threats:

Use MFA

The low-hanging fruit in security is establishing strong authentication methods and defining clear password practices. Enforce strong, unique passwords, and ensure users must change them regularly. Multifactor authentication (MFA) will protect your network and systems if a user ID or password is stolen or compromised.

Screen candidates and new hires

Granted, bad actors have to start somewhere, so screening and background checks do not eliminate every threat. Still, it’s helpful to have processes in place to screen new hires, so you know to whom you’re granting access to your systems. Depending on the nature of the relationship, this best practice may also apply to third-party partners, contractors, and vendors.

Define roles and access

This may seem obvious to some, yet it’s often overlooked. Each user or user group in your organization should have clearly defined roles and access privileges relevant to their needs. For example, your valuable data is left on the table if entry-level employees have carte blanche across your network. Ensure roles and access levels are well-defined and upheld.

Have a straightforward onboarding and offboarding process

Most organizations have a clear and structured onboarding process for registering and bringing users online. Your onboarding process should include clear guidelines for network usage, an understanding of what will happen in the case of a data compromise (deliberate or accidental), where to report issues, and other security measures.

Just as important – if not more – as onboarding is the offboarding process. Languishing user accounts pose a major security risk as they lay theoretically dormant and unmonitored, and no user in the organization will notice if their account is being used. Ensure swift decommissioning of user accounts when employees leave the organization.

Secure infrastructure

Apply strict access controls to all physical and digital access points across your organization. Use least privileged access to limit accessibility, as recommended above. Opt for stronger verification measures, including PKI cards or biometrics, particularly in more sensitive business areas. Secure desktops and install gateways to protect your environment from nodes to the perimeter.

Establish governance procedures

Security requires everyone’s participation, yet organizations need buy-in from key leadership team members and nominated people or a team to hold the reigns. Establishing a governance team and well-defined procedures will ensure attention to security risks at all times and save valuable time should a breach occur.

The tools of the trade

“Organizations must be able to address the risks from malicious insiders who intentionally steal sensitive data for personal reasons as well as users who can accidentally expose information due to negligence or simple mistakes.”

Thankfully, you don’t have to do it all alone. With a data-aware insider threat protection solution, you can rest with the peace of mind that you – and your network – are safe.

The post How Can You Identify and Prevent Insider Threats? appeared first on Cybersecurity Insiders.


April 21, 2023 at 09:10AM

The Double-edged Sword of Hybrid Work

By Mishel Mejibovski, Head of Operations and Strategy, SURF Security
While some companies insist on going back to their original work practices and are forcing their employees back into the office, many others have realized the benefits of hybrid work models and have adopted them as their new way of operations.
As this trend continues to grow, it inevitably forces companies to invest more resources in end-user security; According to Gartner, spending on security and risk management products and services will grow by 11.3 percent in 2023, reaching an all-time high of $188 billion.
Although remote work has its obvious benefits, such as increased flexibility and productivity, and while most industries made the shift to remote work following the pandemic, it also presents a new set of security challenges.
CISOs are faced with managing and securing new complex IT environments where business-critical applications and communications are spread throughout multiple clouds. Meanwhile, employees and third parties work from any given location and device while constantly opening up new attack surfaces. All this is keeping IT teams awake at night.
Tackling Security Challenges
With employees and third parties accessing applications and data from various locations and networks, both on personal and corporate-owned devices, it has become increasingly difficult to ensure that these assets are protected against unauthorized access and breaches. One of the biggest concerns is the use of third-party devices and networks to access corporate assets. These devices and networks usually don’t have the same level of security as those provided by the company, leaving the assets vulnerable to attacks. Additionally, employees may be accessing these assets from different geographical locations, making it difficult for the company to enforce its security policies and monitor for potential threats.
To address these challenges, companies are forced to implement a variety of security measures to protect their corporate assets, adding to their security stack and making it more difficult to keep up with.
One of the most important requirements is the deployment of a comprehensive DLP strategy. Implementing an endpoint Data Loss Prevention solution enables organizations to protect sensitive data regardless of an endpoint’s physical location. It protects any type of data regardless of where it’s accessed and who’s accessing it. Working from home, or anywhere outside the office, is the new normal, and that is why DLP is so crucial as one of the means for providing a safe environment to work in.
Identity and access management controls are also a foundational security piece. They are crucial in ensuring that only authorized users are allowed access to corporate assets. This can include using multi-factor authentication (MFA) to confirm the identity of users as well as implementing role-based access controls to restrict access to certain assets based on an individual’s job function or level of clearance.
The zero-trust security model has also been gaining momentum for years and has become practically imperative considering the surge in remote working and cloud computing and high-profile cyber attacks taking advantage of new attack surfaces. This can include using network segmentation and micro-segmentation to restrict access to specific parts of the network, as well as implementing software-defined perimeter (SDP) solutions to create a secure and isolated environment for accessing corporate assets.
Web isolation is an integral part of a Zero-trust approach that is widely applied across organizations. It provides businesses with security against web-based threats by isolating their browsing activity away from their physical desktop.
Lastly, SaaS management solutions are becoming increasingly important as SaaS adoption grows exponentially, with 85 percent of organizations expected to become cloud first by 2025 with a market size well over $50 billion and growing. These solutions can help to ensure that all access to cloud-based assets is secure and compliant with company policies and regulations.
Collapsing the Security Stack
The era of hybrid work comes with many benefits, however. Now, the browser is becoming the main OS through which many employees perform most of their everyday tasks. Therefore, companies are finding it necessary to implement a variety of complex security tools to try to keep up with security gaps that occur. As a result, IT professionals and CISOs are having difficulty managing the volume of security tools, not to mention how costly it is with regard to licensing and administration.
Fortunately, there is a way to collapse the security stack into one single control point – the corporate browser. With the browser the first line of defense, the cyber security stack – CASB, VPN, DLP, SWG, and ZTNA – can all be consolidated into one centralized control point. Businesses need to ensure that their team members are able to access corporate data and applications, on-premise and cloud-based, with complete security. Implementing a zero-trust enterprise browser enables to easily track and provide complete authentication, validation, and authorization of team members who need to access only what is relevant to get the job done without interrupting their workflow.
Mishel Mejibovski is Head of Operations, SURF Security, which provides a zero-trust secure enterprise browser. www.surf.security. Mishel has extensive experience in the security space, from physical to technical. He was deputy head of the security department for El Al in the UK and also served in military intelligence for the Israel Defense Force.

The post The Double-edged Sword of Hybrid Work appeared first on Cybersecurity Insiders.


April 21, 2023 at 12:04AM

Cost of state cyber attacks not to be covered under insurance says Lloyd

Bank of America has expressed its concerns over Lloyd’s recent policy decision to exclude cyber insurance coverage for large corporations hit by cyber attacks funded by adversary states. The decision to exclude such attacks from standard insurance policies is tentative, but the London-based insurance firm is sure that recent developments, such as the 2017 NotPetya attack on the NHS, have made it think twice about including the costs incurred through such incidents under general cyber insurance coverage.

It is still unclear whether the company plans to introduce a separate insurance cover with a title tag and an extra premium to bring such attacks under special cover. As of now, it offers a standard policy under which a company needs to follow all security procedures to be covered under the attack. However, if the attack seems to be motivated by retaliation or ideology, the costs incurred will not be covered in the marketplace.

State-funded attacks are those that are ideologically motivated and not financial. To date, China, Russia, and North Korea have launched such digital invasions either to create political rifts, concerns among the populace (such as the Moscow invasion of Ukraine), espionage, or to steal funds to fulfill nuclear ambitions.

Excluding such invasions might trigger backlash from customers. However, if the financial services offering firm offers clarity, it can face a win-win situation, as any state-backed attacks can bring partial or complete impairment to state infrastructure, leading to a cyber war, with an exclusion mentioned in the cyber policy cover in the fine print.

The post Cost of state cyber attacks not to be covered under insurance says Lloyd appeared first on Cybersecurity Insiders.


April 20, 2023 at 08:31PM

Pillars of Threat Blocking-as-a-Service

By Pat McGarry, CTO of ThreatBlockr

There are two indisputable facts about the cybersecurity industry right now. One, we are still in the middle of a massive staffing crisis. Two, one of the biggest drivers of this staffing crisis is burnout of security professionals.

A recent study indicates up to 84% of cybersecurity professionals are experiencing burnout. Personally, I was surprised that number wasn’t closer to 100, given what these men and women face on a day-to-day basis.

The past three years have been the gift that keeps on giving to threat actors. Threat surfaces widened with the rise of remote and hybrid work, networks became more vulnerable, and breaches became big business on the dark web.

The technologies we deploy to protect our data have been overwhelmed by a flood of malicious traffic and security teams are forced to respond to more and more alerts from more and more tools, worried that one misstep could result in disaster. Security professionals are not set up for success, which explains why there are 3.4 million cybersecurity roles unfilled worldwide. This is unsustainable.

We can’t keep throwing more of the same kinds of security technologies onto our networks and expecting different results. Threat Blocking-as-a-Service (TBaaS) gets you different results.

Instead of chasing after ever-changing attacks and threats, TBaaS focuses on known threat actors. This model blocks traffic entering the network as well as calls and traffic back out, all autonomously. Importantly, this type of enforcement can only be accomplished by leveraging massive amounts of cyber intelligence to get the clearest picture possible of who the threat actors attacking our networks, users, and data are.

The impact of TBaaS to networks and their security teams is felt instantaneously. We know that 30-50% of the traffic hitting a security stack is coming from IP addresses of known threat actors. Blocking this results in an immediate increase to your security posture while providing a significant boon to the performance of the rest of the security stack. This also eases the pressure on security teams significantly.

The idea of TBaaS – using cyber intelligence to block known threat actors from entering or exiting the network – is so simple that people assume their security stack technologies are already doing that. Unfortunately, without TBaaS, they aren’t. Threat Blocking-as-a-Service stands on five pillars that make it effective:

  • Visibility
  • Risk management
  • Consolidation
  • Budget

Every other tool in the modern security stack might have one, two, or maybe three of these assets, but TBaaS is the only one that combines all of them. Let’s dive into why this holistic approach makes such a difference.

Visibility

The threats coming in and out of our networks are constantly changing. Where we patch for one type of attack, threat actors deftly evolve more, each time adding layers of obfuscation and complexity. Most of these threat actors are well-funded – often by nation-states – which is of course why they have the resources to inflict such harm and adapt their methods so rapidly.

However, the constant in this discussion is not the “what” of the attacks but rather the “who.” Who are sending these attacks? And where are they?

The cyber intelligence community is comprised of government, open source, and private enterprises who research answers to those two pivotal questions. The TBaaS model is based on the idea of “the more intelligence the better” and ingests intelligence feeds and lists from anywhere with up-to-the-minute updates. This provides as much visibility as possible into the threat landscape, which in turn allows for significant network, user, and data protection.

Defense

Currently, the majority of threat intelligence is leveraged in the “detect/respond/recover” functions of a security stack. Make no mistake: utilizing threat intelligence in this space is essential. However, failing to leverage the full power of threat intelligence ahead of a breach has left systems open to breaches. As such, TBaaS is very much a “left of boom” technology.

Utilizing massive amounts of cyber intelligence to block traffic to and from known threat actors is the true defense for any network, and the second pillar of TBaaS.

Risk management

One of the most pivotal concepts in cybersecurity is redundancy: we create overlapping protections so one piece’s failure doesn’t mean system failure. For decades, however, the “identify and protect” piece has been filled by one single technology: the firewall. Firewalls were never built to handle either the amount of traffic thrown at them nor the amount of encrypted traffic they would have to parse.

The TBaaS model instead welcomes other tools and technologies, but also reduces risk by creating a true protection model.

Consolidation

No matter how great all your technologies are, if they aren’t talking to each other you’re headed for disaster. Another pillar of TBaaS is the consolidation of information: not just ingesting and acting on cyber intelligence, but also feeding its own actions and logs into the rest of the security stack to utilize. This type of data consolidation can reduce multiple alerts as well as aid in the “detect/respond/recover” phases if an unknown threat makes its way into the network.

Budget

One of my colleagues loves to ask people when making cybersecurity budget decisions: what is your budget for ransom? Because the truth is, unless you’re actively blocking known threat actors, it’s not a matter of if a breach happens, but when, and how often.

Cybersecurity budgets are tight, which is why another pillar of the TBaaS model is budgetary value. Of course, the solution itself should be affordable, but it also alleviates other issues causing budget headaches.

  • Autonomous. Operates and updates without the need for staff to monitor, reducing the strain on the security staff.
  • Reduce known-bad traffic hitting the security stack. Optimizing performance for the rest of the security stack.
  • Reduce alerts. This also helps relieve the burden placed on expensive in-house cybersecurity staff, as well as help to avoid alert fatigue.

Clearly, what we’re doing as an industry isn’t working very well. Threat Blocking-as-a-Service is a paradigm shift in the industry to solve that conundrum. Sometimes it’s the simplest solutions that we can’t believe we weren’t already doing. By focusing on stopping the threat actors, by definition you stop all of the threats they present. That is Threat Blocking-as-a-Service.

The post Pillars of Threat Blocking-as-a-Service appeared first on Cybersecurity Insiders.


April 20, 2023 at 07:59PM

Trending Google news headlines on Ransomware, Penalties and Espionage

1.) AhnLab, a South Korean cybersecurity firm, has issued an alert about a ransomware attack on Microsoft SQL Servers that are being bombarded with Trigona Ransomware payloads meant to encrypt files after stealing data. Hackers induce the same ransomware via brute force or dictionary attacks, where hackers use easy-to-guess credentials to bypass logins. Trigona was first spotted in October 2022 by MalwareHunterTeam, who analyzed the possibilities and concluded that the malware-spreading gang uses Monero Cryptocurrency from their victims to offer a decryption key in exchange.

2.) Real estate firm OrangeTee & Tie has been slapped with a fine by Singapore’s Personal Data Protection Commission (PDPC) after the company failed to protect its user data, leading to a breach of information related to 25,000 customers and employees. This includes details such as names, bank account numbers, transaction details of the property, and ID card details. ALTDOS, a hacking group from Southeast Asia, was behind the incident, and it is known that the group of threat actors demanded 10 BTC for the return of the information, along with an assurance that no stolen data would be published online thereafter. After learning about the facts of the cyber incident, PDPC slapped a fine of $37,000 on the property firm for failing to take proactive security measures in advance to prevent data from being spilled from over 11 databases.

3.) Blind Eagle, an espionage actor speaking Spanish, is linked to the cyber attacks launched on the private and public sector in Colombia, Spain, Chile, and Ecuador. Security firms Check Point and BlackBerry have discovered that the threat actors group uses spear-phishing campaigns to deliver commodity malware such as AsyncRAT and BitRAT. Also known as APT-C-36, the group is financially motivated and has been found launching promiscuous attacks against citizens in South America since 2018.

The post Trending Google news headlines on Ransomware, Penalties and Espionage appeared first on Cybersecurity Insiders.


April 20, 2023 at 10:35AM

Wednesday, April 19, 2023

Facebook introduces new AI model capable of detecting objects in images

Meta, the parent company of Facebook, has introduced a new AI model to the world that can identify objects in an image. The newly developed AI model is known as the “Segment Anything Model” (SAM for short) and can understand objects inside images and videos.

The ability to detect specific objects is called segmentation, and Meta seems to be democratizing its AI development for analyzing objects on ocean floors, various underwater photography sceneries, space, and country borders.

According to the press release made by Meta last week, the accurate segmentation technology is an AI-trained infrastructure model induced with large amounts of data to perform specialized tasks.

The WhatsApp parent company says that SAM and its Segment Anything 1-billion mask dataset (SA-1B) are available under a permissive open-license framework for research, and the dataset has approximately 11 million licensed and privacy-preserving images in its final dataset.

Now, the big question is, what if this technology falls into the wrong hands? Criminals can use this tech to find out objects and things from selfie photos taken in bedrooms and restrooms by celebrities and then blackmail them.

NOTE – Irrelevant to the article topic, we have received info that the social media networking giant is planning to start a fresh round of layoffs. In this layoff spree, about 4,000-4,500 employees across the world can receive the “pink slip,” starting from April 20th of this year. Mostly, those working in the technical departments of FB, Instagram, Reality Labs, and WhatsApp will be affected. Those involved in various AI projects are safe for now, and new hirings are on the horizon. American news resource Vox was the first to report this development and expects that the layoff email will be sent to employees in the early hours of Thursday between 4:00 am to 5:00 am. This was an expected move, especially after the Meta founder Mark Zuckerberg announced in March this year that his company intended to eliminate around 10,000 jobs in the next 3 months. Interestingly, in February this year, Amazon announced its plan to lay off around 9,000 employees and is anticipated to divert the investments to the development of AI models.

The post Facebook introduces new AI model capable of detecting objects in images appeared first on Cybersecurity Insiders.


April 19, 2023 at 08:35PM

Over 25 billion email address and phone numbers available on dark web and Putin hacking British Power Network

Precisely speaking, the heading is related to two different articles with different stories. The first one goes as follows: According to a study conducted by Digital Shadows Photon research team, and their report dubbed “Account Takeover in 2022,” about 25 billion email addresses and phone numbers, along with an equivalent number of credit card details and related logins, are available on the web. Surprisingly, most of the data has been sold and used in multiple cyber attack campaigns, with only a small number of bank account credentials and healthcare data being utilized.

Websites embedded with scanning tools and various mobile applications are paving the way for hackers to collect and harvest data as per their needs, and website URLs like ID Security and Have I Been Pwned can be used by concerned people and authorities to check whether their email or phone number is being used or sold on the dark web.

For those who are extremely concerned about their data leak, they can use other services such as Aura, LifeLock, and ID Watchdog by paying $10 a month. These services, and others like them, can keep a constant tab on the dark web and check whether your data is being used for any criminal activity or such.

No matter how much you try, one thing is for sure: we cannot do anything if the credentials leak onto the dark web. However, changing our password at regular intervals like 7-10 days and generating a password with a mixture of at least 15-18 alphanumeric characters, along with one or two special characters, can help prevent criminals from breaking into our accounts.

Coming to the second news, the UK’s National Cyber Security Centre has issued an official cyber threat notice that Kremlin-aligned hacking groups, such as Killnet, will try their best to disrupt the power utilities operations in and around the UK. The threat notice was extended to other countries in Europe, as Putin has put them at the top of his country’s foe list.

Posting the same on a prominent social media platform, Oliver Dowden, the Cabinet Minister of Britain’s Infrastructure, confirmed the news that ‘Wagner’s’ will launch devastating attacks to disrupt and destroy the entire energy sector across the UK, but assured that the country’s cyber army was well prepared for such invasions and is excellently equipped to thwart such attacks to the core.

The highlight is that Britain now has the potential not only to defend its infrastructure but also to launch retaliation-filled attacks leading to dismantling Russia from all spheres.

The post Over 25 billion email address and phone numbers available on dark web and Putin hacking British Power Network appeared first on Cybersecurity Insiders.


April 19, 2023 at 10:38AM