FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Saturday, December 26, 2020

The Bitglass Blog

This year, the fabric of our society has forgone unimaginable changes due to the global pandemic, and it’s likely that the impact will persist long after it is gone. The inevitable push towards a remote, cloud-first business ecosystem has catapulted in recent months, and many enterprises were simply not ready to securely enable remote work. In the interest of exploring how organizations have adapted to the unforeseen adjustments, Bitglass teamed up with a leading cybersecurity analyst firm and surveyed hundreds of community members consisting of IT and cloud security professionals about the state of security in their organizations. 

The post The Bitglass Blog appeared first on Cybersecurity Insiders.


December 27, 2020 at 09:10AM

Agent vs Agentless Monitoring: Why We Chose Agentless

This post was originally published by upguard.

When we set out to create a cloud-based tool for configuration monitoring, we used the tools we knew and wrote UpGuard using JRuby. For our application, JRuby had many good qualities: getting started only required a one line install, the agent only needed to talk out on port 443, and it was platform agnostic. Using JRuby we demonstrated the value of system visibility, attracted our first cohort of customers, and raised the funds to expand UpGuard. Now we’re not only scrapping that agent, we’re moving away from agent-based architecture altogether. Here’s why.

As we’ve learned more about configuration monitoring and discovery, both from our own R&D and from working with our customers, we’ve realized that an agentless connection manager is better than a per host installed agent. Given the investment in JRuby as a technology, our first attempt was to use the JRuby agent as a connection manager. Since expanding to deployments of tens of thousands of nodes, the performance and memory requirements of JRuby quickly became problematic. (If you want to argue about JRuby, here’s the post where you should do it.) Given the position of the company at the time, we had the rare luxury of choosing between optimizing the 2-3 year old code base in order to meet the needs of our customers or rewriting it all together. Rather than accepting the limits of JRuby, we rewrote our application in Go to achieve the goal of an agentless connection manager with the best technology available.

We are proud to announce two great things simultaneously: the launch of our fully featured agentless connection manager, and a tech refresh that improves UpGuard’s benchmark’s across the board.

The Argument for Agentless

 

1) Maintenance costs. Far and away, the biggest argument for an agentless design is to slash maintenance costs. UpGuard is intended to make large infrastructures easier to manage and to increase the server/admin ratio. An installed agent means additional costs for users whenever updates are rolled out. There is absolutely no way around that problem with installed agents. More subtly, since those updates will have to make it through a change management process, it also means that (potentially many) different versions of UpGuard will be deployed at any given time. More supported versions = higher likelihood that something will break and need fixing. Supporting fewer versions also means we can provide a higher level of support for the current connection manager and deliver requested features more quickly.

Read more here: www.upguard.com

The post Agent vs Agentless Monitoring: Why We Chose Agentless appeared first on Cybersecurity Insiders.


December 26, 2020 at 05:39PM

Best Practice: Identifying And Mitigating The Impact Of Sunburst

This post was originally published bycheckpoint

During the closing weeks of 2020 a Cyber Security attack became one of the main headline news stories of what had already been a news-rich year. Attributed to a campaign that began months earlier, the information security teams of government agencies and private organizations quickly shifted their focus to a vulnerability in the SolarWinds Orion solution, which could open a backdoor into organizational communications networks. Dubbed Sunburst, this incident called into question the trustworthiness of the primary technology tools that organizations use to manage their corporate technology resources.

As with any security incident, security practitioners would initially focus on identifying signs of potential Sunburst activities in their networks and systems. From there they would prioritize immediate remediation activities. Once these initial efforts were complete, security teams would need to consider broader structural changes to their security programs.

This blog provides information intended to assist with these primary phases and is structured according to the following flow:

  1. A summary of the Sunburst breach
  2. Network mitigations
  3. Host remediation
  4. Additional considerations
  5. Potential considerations for longer-term security improvements, including guidance on DevOps, Endpoint and cloud environments, according to the Zero-Trust Architecture framework

Some of the recommendations included in this blog apply to what was known about the Sunburst event at the time of writing. Check Point will update the document as more information becomes available.

Individuals interested in speaking with Check Point about Sunburst and other security topics are invited to interact with their account teams and to contact Check Point via the contact details listed on its public website at: https://www.checkpoint.com/

Read more here: blog.checkpoint.com

The post Best Practice: Identifying And Mitigating The Impact Of Sunburst appeared first on Cybersecurity Insiders.


December 26, 2020 at 05:27PM

Friday, December 25, 2020

Identity Verification: How to improve digital adoption & trust

Digital transformation is re-shaping industries, transforming businesses and operational models at a pace never before seen. This wave of change is increasingly placing users at the centre of digital innovation – for this reason it’s important that secure identity verification is implemented as part of online service providers’ operations.

Furthermore, the COVID-19 pandemic has prompted industries such as travel, hospitality, online gaming and public services to rethink their customer engagement models in favour of implementing a more user-centric online approach. As a large proportion of the world’s population has had to live under strict lockdown restrictions for several months and many businesses have had to shut their physical operations as a result of the pandemic, it is imperative to have remote access to essential services across a range of sectors.

Face-to-face interaction has become particularly challenging. So how do you build strong customer relationships and establish trust when asking them to provide sensitive personal information such as an ID document or biometrics remotely and online, while guaranteeing regulatory compliance?

Identity verification in a remote world

Simply put, identity verification is making sure that the person on the other side of the screen is who they claim to be. It consists of four simple steps:

  1. The user takes a photo of their official ID, such as a passport or driver’s license
  2. The service provider verifies that the ID is authentic by checking the consistency and integrity of the data
  3. The user takes a selfie
  4. The service provider verifies if the person is alive (versus a photo) and physically present, and that the face matches the document.

Thankfully, numerous technological developments, including facial biometrics, artificial intelligence (AI) and machine learning can help you make customer onboarding quick and secure. Furthermore, when combined, these technologies not only help to verify the user remotely, but also improve the onboarding experience, making it as comprehensive as possible.

How do you ensure customer trust?

When enrolling customers, businesses need to be able to check their credibility without putting them off. Identity verification requires the use of sensitive personal information; therefore, customers need to be re-assured that their data is handled securely including how it is handled, what it is used for, where and how it is stored and whether the individual has any control over it.

So how can organisations make the user trust them with their ID and biometric data, especially in times when ID verification is done remotely?

Companies can now benefit from AI-driven identity verification solutions without compromising customer trust. Here are a few things you need to consider:

  • What about identity theft? As many as 1 in 10 people are now victims of identity fraud annually, whereby fraudsters are using sophisticated online tools to get access to people’s data. Therefore, you need to ensure that the solution you’ve put in place is robust enough to protect users against document fraud and identity spoofing.
  • How is the user’s data managed? An essential part of ensuring customers’ trust in the ID verification system in place is to be explicitly clear and transparent about the way you use any data collected in the process and how you protect it. Make sure that no personally identifiable information (PII) is stored locally, and that the data is only transient. Data privacy needs to be thought about very seriously when implementing a digital onboarding solution, allowing users to stay in control of what PII is shared with companies.
  • What about cybersecurity? Since 2018, data breaches have exposed more than 38 billion records. Implementing best security practices is mandatory/pre-requisite to guarantee that the service is not vulnerable to any attacks or data breaches.
  • Does the service meet regulatory requirements? Businesses need to set up appropriate secure remote identity verification solutions, as it may be risky in the current climate when Know Your Customer (KYC) / Anti-Money Laundering (AML) compliance procedures are so stringent, and threats posed by fraudsters are as broad as they are serious. Following the GDPR and whatever regulation that applies is not just key, but unavoidable.

How to boost customer acquisition remotely without compromising trust

Now that trust is established, how do you get more customers to use your service, in order to increase conversions without impeding the user experience?

Any obstructions to the end-to-end journey can force the user to start the process again, which can be incredibly frustrating and can cause the user to leave. Therefore, ID verification needs to be built with consumer behaviour at its heart and with privacy as a cornerstone of the process.

The front-end application must be user-friendly and as straightforward as possible. For example, advanced ID verification models use passive liveness detection based on machine learning models, and the user is asked for nothing more than to take a selfie.

Today’s expectation is a seamless service delivered immediately. Would you then prefer a real time, automated solution, or one that involves agent intervention in the onboarding process, at the expense of the customer simply giving up?

Customers will be more likely to use the service thanks to the convenience it provides. The service provided needs to add value to the customer, otherwise, they wouldn’t hesitate to go elsewhere. For example, a seamless end-to-end traveller journey is possible by implementing a remote ID verification programme, without compromising customer security. This will allow passengers to check-in for a flight from home and avoid long queues at passport control or when boarding the plane.

Communicating the new service benefits of a highly verified and proven level of security and trust to customers, as well as making it clear that it complies with privacy legislation, is key to improving digital adoption in our touchless journey.

The post Identity Verification: How to improve digital adoption & trust appeared first on Cybersecurity Insiders.


December 25, 2020 at 09:12PM

How unique digital identity numbers can help to securely deliver services remotely

Unique digital identities have become a key form of identification for citizens globally due to the convenient, fast and secure access to public and private services they offer. Many African countries for example have been implementing them as part of their national identity programmes. The COVID-19 pandemic has greatly emphasised the need to accelerate the deployment of unique identities to allow citizens to access the social and economic benefits they’re entitled to.  

The ID4Africa movement recently ran a dedicated webinar on this topic, shining a spotlight on unique digital identity numbers as a way to deliver services remotely in response to the COVID-19 pandemic. In this post, I am going to recap some of the main points discussed including whether there should be one unique identity number used by all stakeholders or if different sectors should be allowed to create their own identifiers.  

Weighing the risks and opportunities  

While various points of view were shared, there were two distinctive sides taken around the opportunities and risks of having a unique digital identity.   

The main benefit of unique digital identity numbers is that governments can implement one central identification system that can be used across all administrative entities. Furthermore, it will provide them with the opportunity to offer services to the private sector, generating additional income for the state. It will also allow them to link information from siloed data sources in a simple and secure way, while allowing each individual to access the rights that are attached to their unique identity.  

The panellists’ main concern with implementing unique identifiers is that they could potentially be used for malicious purposes by stakeholders. For this reason, in France for example, it is forbidden to use an individual’s social security number as an identifier to avoid discrimination.  

During the ID4Africa webinar the panellists also discussed the notion of tokenization which allows the use of a virtual copy of unique identifiers; however, this could require both individuals and the state to spend significant time doing admin. To make it simpler, sectorial identifiers can be used to limit the interoperability between sectors such as health, education, and law enforcement, which could otherwise result in personal data being kept in silo. This way the individual stays in full control of their data and they have the right to decide who can have access to it.  

How can citizens safely enjoy the benefits of unique identity numbers? 

If properly handled, interoperability of databases can offer great opportunities to empower populations, which is the ultimate goal for developing countries. This statement was highlighted by Aimé-Martial Massamba, Deputy Project Director National Biometric Register IBOGA for the Ministry of Interior in Gabon during the webinar, who mentioned that having a unique identity is necessary in order to offer accurate services to the population and fight identity fraud. 

To make sure that citizens can safely enjoy the benefits of a unique identity, governments need to implement a technical solution that is interoperable and responsive to the diverse needs of all users while safeguarding data privacy, security and user rights. Personal data protection is a MUST and there should not be any exceptions no matter the use case.    

One available solution is the use of ALIAS identification numbers. ALIAS refers to a token that is not limited to the generalisation of virtual clones of a unique number, but can be any existing or generated identifier for permanent or temporary usage. It works on a similar principle to virtual payment cards where the card and the information that comes with it can be revoked after a certain period of time. An ALIAS identification number could be:   

  • A registration number given at birth or at identity registration 
  • An existing number, like a social security number. This use case is particularly important when managing migration from an old identity system to a new one, helping to manage the transition to new identifiers 
  • A token used in specific sectors and with a defined duration, such as those used as part of India’s AADHAAR system.  

Importantly, alias identification numbers can put the control back in the hands of individuals by allowing them autonomy over their personal data and to decide who can see the link between identifiers. 

Therefore, there is no need to choose between one unique identifier and several, it’s possible to have both at the same time and enjoy their benefits while mitigating the risks. 

The post How unique digital identity numbers can help to securely deliver services remotely appeared first on Cybersecurity Insiders.


December 25, 2020 at 09:12PM

Data Breach at Sangoma Technologies because of Ransomware Attack

Sangoma Technologies, a Canadian firm dealing in VOIP Services, has announced that hackers stole some of its critical information after launching a ransomware attack on the firm’s database.

The data communications provider announced the details of the cyber incident after the threat actors posted the stolen information belonging to the company on the eve of Christmas 2020.

As a precautionary measure, the company has hired third party experts to investigate the incident and check the extent of the digital damage. The company also shut some of its operational servers to contain the malware spread.

Sangoma confirmed in its latest twitter update that some accounts pertaining to its customers were compromised and is urging its users to change their passwords on an immediate note.

“We are committed in securing and protecting the data of customers, partners and employees and will stand by this aim forever”, said Bill Wignall, President and CEO of Sangoma.

NOTE 1- Unconfirmed sources say that Sangoma technologies servers were hit by CONTI Ransomware. However, an official conformation is awaited on this note!

NOTE 2- Ransomware is a kind of malware that encrypts a database until a ransom is paid to hackers through cryptocurrency.

NOTE 3- Founded in 1984, Sangoma Technologies Corporation offers hardware and software related to Voice, Data and Video Products. It later emerged as a cloud based VOIP services provider after acquiring businesses like VOIP Innovations LLC and .e4 LLC.

NOTE 4- Sangoma customers who are concerned about the data breach can contact the company via email ID sangoma-security@sangoma dot com

The post Data Breach at Sangoma Technologies because of Ransomware Attack appeared first on Cybersecurity Insiders.


December 25, 2020 at 09:11PM

Data Security platform Vera Security acquired by HelpSystems LLC

HelpSystems that offers IT Management software has made it official that it is going to clinch up Data Security firm Vera Security for an undisclosed amount. The deal is said to end by March 2021 provided all goes well as per the SEC.

On a technical note, Vera offers the privilege to its clients to secure, track, and revoke access to devices and platforms that are accessing sensitive data. It offers a military grade encryption that keeps the data flow under control, thus giving the businesses the ability to audit their information to the granular level.

The highlight of Vera is that it helps companies keep sensitive info such as social security numbers, credit card data and patient data with strong security and productive collaboration.

Trade analysts say that HelpSystems is thinking to integrate the tech of Vera into its data security portfolio to meet the demand related to full data life cycle.

HelpSystems works with Fortune 500 companies and those include IBM, Coca Cola, Shutterfly Inc, Mattel Inc, FedEX, Polaris Industries. In-fact, HelpSystems stands at the 22 position of having the top 25 Fortune 500 companies in its clientele list.

Note 1- Equity firms such as TA Associates, Charlesbank Capital Partners, and HGGC are the actual owners of Minnesota based HelpSystems LLC.

Note 2- Founded: in 2014, Vera is a California based company that specializes in offering such as Data Security, File Encryption, Data Control, Dynamic Data Protection, Secure Email, Information Security and Cloud Security along with Cybersecurity and Data Loss Prevention.

The post Data Security platform Vera Security acquired by HelpSystems LLC appeared first on Cybersecurity Insiders.


December 25, 2020 at 12:30PM