Robusta Technology & Training to Offer (ISC)² Official Cybersecurity Education in Vietnam

Training Registration Opens for First Official CCSP & SSCP CBK Training Seminar in March and April 2017

Hong Kong/Hanoi – Jan 16, 2017  (ISC)²® today announced it has appointed Robusta Technology and Training Center (Robusta), a leading training company in Vietnam, as an (ISC)² Official Training Provider (OTP) to offer official (ISC)² cloud security and cybersecurity education to potential its certification candidates in Vietnam. The first official (ISC)² CBK® Training Seminar for the Certified Cloud Security Professional (CCSP®) will be held on March 27 in Hanoi. The official (ISC)² CBK Training Seminar for the Systems Security Certified Practitioner (SSCP®) will be held on April 3 in Ho Chi Minh City.

Robusta is a leading training company in Vietnam. As an (ISC)² OTP, Robusta will offer official (ISC)² CBK Training Seminars to security professionals looking to become certified.  The first two certifications to be offered are the CCSP and SSCP. Globally acclaimed, (ISC)²’s credentials qualify cyber, information, software and infrastructure security professionals throughout their careers. The CCSP credential is appropriate for professionals with deep-seated knowledge and competency derived from hands-on experience with information security and cloud computing. CCSPs help candidates achieve the highest standard for cloud security expertise and enable organizations to benefit from the power of cloud computing while keeping sensitive data secure. The SSCP is suitable for those pursuing technical skills and practical security knowledge for hands-on operational IT security roles. It provides industry-leading confirmation of a practitioner’s ability to implement, monitor and administer IT infrastructure in accordance with information security policies and procedures that ensure data confidentiality, integrity and availability.

“Cybersecurity has become the prime concern of thousands of enterprises worldwide. Cyber threats pose a real challenge in many developing nations, including Vietnam.  Robusta Technology and Training, one of the top training providers in Vietnam, has been dedicated to raising the issue of cybersecurity threats and emphasizing the importance of proper methods to defend cyberattacks amongst the public. Working with (ISC)² to provide world-class cybersecurity education is a major step in our journey to serve and give back to the IT community. Together, we aim at providing more certified cybersecurity professionals to strengthen the nation’s defense capability,” says Thuan Ta, president, Robusta Technology and Training.

“We are delighted to add Robusta Technology and Training to our reputable network of OTPs in Vietnam. The working relationship with Robusta will help to enhance the development of capacity building with (ISC)²’s official education program in Vietnam. The CCSP education will definitely cater to the needs of candidates looking for advanced cloud security education, and SSCP education is ideal for those who would like to develop practical security knowledge in hands-on operational IT roles,” says Clayton Jones, managing director, (ISC)² Asia-Pacific.

For more information or to register for training seminars, please contact Robusta team at Learn@robusta.vn or call  (+84) 939 586 168 or visit http://www.robusta.vn/.

About Robusta
Established in May 2010, Robusta Technology and Training, a national leader in virtualization, cloud computing, big data, and security training services, has quickly become one of the most trusted and prestigious training brands in Vietnam.  After 7 years of rapid growth, Robusta is now an authorized training partner for technology leaders including VMware, Microsoft, Cisco, EMC, etc. Robusta has provided more than 10,000 students with industry-leading technical training that delivers the most intuitive and advanced courses and certification. For students and corporate clients, we commit to provide the highest quality source materials and the latest products and technologies. Our trainers are experienced experts both in training and conducting big corporate and governmental projects. Our classes are conducted with innovative and interactive approaches. We deliver not only knowledge but also hands-on experiences and consultation to our students. Placed in both Vietnam and the United States, our labs are well-equipped with latest cloud technology, allowing students to gain access to our labs 24/7 anytime, anywhere they are. For more information, visit Robusta.vn and connect with us on Facebook.

About (ISC)²
(ISC)² is an international nonprofit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP®) certification, (ISC)² offers a portfolio of credentials that are part of a holistic, programmatic approach to security. Our membership, over 123,000 strong, is made up of certified cyber, information, software and infrastructure security professionals who are making a difference and helping to advance the industry. Our vision is supported by our commitment to educate and reach the general public through our charitable foundation– The Center for Cyber Safety and EducationTM. For more information on (ISC)², visit www.isc2.org, follow us on Twitter or connect with us on Facebook.

###

© 2017, (ISC)² Inc., (ISC)², CISSP, SSCP, CCSP, CAP, CSSLP, HCISPP, CCFP, ISSAP, ISSEP, ISSMP and CBK are registered marks of (ISC)2, Inc. 

Media contacts:

Tiffany Tạ                                                          Kitty Chung

Robusta Technology and Training                    (ISC)² Asia-Pacific

Email:Tiffany@Robusta.vn                            kchung@isc2.org

Tel:      (84) 939 586 168                                   (852) 2850 6989

[(ISC)² Press Release]

How Responsible Leadership Preserves Trust in the Digital Age: Thoughts Heading into Davos

Next week, I will have the privilege of participating in the annual meeting of the World Economic Forum (WEF) in Davos, Switzerland, organized this year around the theme of “Responsive and Responsible Leadership.” As WEF notes, 2016 demonstrated that existing systems and institutions at national, regional, and global levels have strained to keep pace with an increasingly complex and interconnected world. Yet, the growth of this complexity and interconnectedness shows no sign of slowing, as the Fourth Industrial Revolution (last year’s theme) drives “the convergence of technologies that blur the lines between physical, digital, and biological systems.”

As I noted last year in the run-up to Davos, the future prosperity promised by the Fourth Industrial Revolution relies upon the trust that we all place in technology to function properly – and securely. Our embrace of connected devices, smart homes, self-driving cars, and other innovations underpins the digital economy, but it also leaves us vulnerable to new forms of attack. Cybersecurity, therefore, is an absolute necessity for future economic prosperity. For this reason, I can think of few topics that more urgently require responsible leadership than cybersecurity – and not just cooperation but also collaboration among public and private sector interests.

Responsible leadership in the digital age requires questioning established practices and leading the implementation of changes when warranted. To this end, I will encourage my fellow attendees to adapt to the emerging threat environment by choosing a prevention-based approach that proactively identifies and manages cybersecurity risks to their organizations. For many, this involves scrutinizing legacy approaches to cybersecurity that have failed to keep pace with the Fourth Industrial Revolution, and ensuring that operational teams apply the proper combinations of people, process and technology to prevent successful attacks.

The decreasing cost of computing power makes it easier and cheaper than ever for cyber criminals to launch attacks in greater volume and with greater sophistication. Attackers enjoy decreasing start-up and marginal costs, using automated, specialized, and scalable tools to achieve their objectives. Legacy defenses are inadequate to deal sufficiently with this rise in volume and sophistication, dependent as they are on decades-old core technology, patchwork systems and manual intervention by security teams. To effectively address this risk, responsible leaders must instead focus their organizations’ cybersecurity efforts on automated prevention of attacks, decreasing the likelihood of, and raising the cost required for, a successful attack. By focusing on prevention, we make attacks cost-prohibitive for attackers, diminish their success, and securely enable the technologies underlying our digital age.

The Fourth Industrial Revolution holds great promise, but it will also challenge us in unprecedented ways. Few challenges, in my view, are as serious as that of cybersecurity, which is why it is the perfect topic for responsible leadership. I look forward to bringing this message to Davos, and hope we can all work toward a fresh approach to cybersecurity focused on the prevention of successful cyberattacks.

[Palo Alto Networks Research Center]

Campaign Evolution: EITest from October through December 2016

EITest is a name originally coined by Malwarebytes Labs in 2014 to describe a campaign that uses exploit kits (EKs) to deliver malware. Until early January 2016, “EITest” was used as a variable name in the attacker’s malicious injected script in pages on legitimate websites compromised by this campaign. While the variable name is gone, the name for the campaign remains: we still call this campaign “EITest” and it continues to use EKs to distribute a variety of malware.

We reviewed EITest in March 2016 and October 2016. However, the EITest campaign looks noticeably different than when we last reviewed it three months ago.

The EITest campaign is focused on the Delivery, Exploitation, and Installation phases of the cyber attack lifecycle. The way the attacker executes each of these phases changes over time, and this blog examines the changes during the last quarter of 2016. Two significant changes have occurred during this time.

  • Since our last report, EITest no longer uses a gate between the compromised website and the EK landing page (possibly in response to that report).
  • Script injected by the campaign into pages on legitimate websites no longer contains any obfuscation.

Perhaps the most interesting thing about EITest is its longevity.  People have been tracking this campaign since 2014, and its longevity suggests that despite the shifting EK landscape, EKs remain a profitable venture for the criminals involved.

Chain of Events

Successful infections by the EITest campaign generally follow a set sequence of events. It currently uses at least two variations of Rig EK to deliver a variety of ransomware. The infection sequence is similar to other campaigns utilizing EKs to distribute malware. To understand how campaigns use EKs, see our previous blog on EK fundamentals. For EITest, we see the following steps:

  • Step 1: Victim host views a compromised website with malicious injected script.
  • Step 2: The injected script generates an HTTP request for an EK landing page.
  • Step 3: The EK landing page determines if the computer has any vulnerable browser-based applications.
  • Step 4: The EK sends an exploit for any vulnerable applications (for example, out-of-date versions of Internet Explorer or Flash player).
  • Step 5: If the exploit is successful, the EK sends a payload and executes it as a background process.
  • Step 6: The victim’s host is infected by the malware payload.

For most of its history, EITest has used a gate between the compromised website and the EK landing page. However, the EITest campaign has stopped using a gate after we published our previous blog about it on October 3, 2016.  Since then, injected script from this campaign links directly to an EK landing page. Gates are no longer used by EITest.

Figure 1: Chain of events for the EITest campaign as of October 3, 2016.

EITest and Rig EK

The EITest campaign still uses Rig EK to deliver its malware. Our research shows EITest most often uses a variant of Rig EK called Empire Pack. Many in the community refer to Empire Pack as “Rig-E” to distinguish it from other variants and still emphasize its relationship to the original Rig EK.  Empire Pack uses the same URL patterns we’ve seen from Rig EK since late March 2015, while other variants of Rig EK like Rig-V (an improved “VIP” version or Rig) and Rig standard moved on to different URL patterns.

Of note, the variant of Rig EK that EITest uses depends on the payload it delivers. Most EITest payloads are sent using Rig-E.  However, EITest has used Rig-V to distribute ransomware like Cerber or CryptoMix (also known as CryptFile2).

Payloads sent by EITest

Since October 2016, the EITest campaign continues using Rig EK to distribute a variety of malware.

We occasionally see ransomware like Cerber or CryptoMix from the EITest campaign. More often, the campaign will distribute information stealers like Gootkit or the Chthonic banking Trojan. EITest has also delivered other types of malware like Ursnif variants and Latentbot.

Patterns of injected script

When we last examined injected script by the EITest campaign, it still used obfuscation to disguise the EK landing page URL.  By October 15th 2016, EITest stopped obfuscating URL within the injected script.  Figure 3 shows the injected script shortly before the change.  Figure 4 shows the injected script shortly after wit an unobfuscated landing page URL.

Figure 3: Injected EITest script in page from a compromised website on October 13th, 2016.

Figure 4: Injected EITest script in page from a compromised website on October 17th, 2016.

Throughout the rest of 2016, injected script from EITest hasn’t changed that much, as seen in Figure 5.

Figure 5: Injected EITest script in page from a compromised website on December 30th, 2016.

Conclusion

EKs are still a popular method to distribute malware. Campaigns like EITest continue to use EKs to deliver a variety of malware, including information stealers and ransomware. These campaigns do not have a specific target and anyone with a Windows system that’s out of date or has out of date applications is vulnerable to infection.

As the EK model of distribution remains profitable, we expect to see malware delivered by EKs through campaigns such as EITest. Domains, IP addresses, and other indicators associated with this campaign are constantly changing. Fortunately, EKs are relatively ineffective against people using a fully-patched Windows operating system who ensure their applications are all up-to-date. Furthermore, customers of Palo Alto Networks are protected from the EITest campaign through our next-generation security platform.

[Palo Alto Networks Research Center]

Long Con or Domino Effect: Beware the Secondary Attack

Lightning may not strike twice, but cybercrime certainly does. The latest example: A year after the major hack of the U.S. Office of Personnel Management (OPM), cyber criminals are again targeting individuals impacted by the OPM breach with ransomware attacks.

In the new attack, a phishing email impersonates an OPM official, warning victims of possible fraud and asking them to review an attached document—which, of course, launches the ransomware.

OPM attack part of bigger trends in ransomware
The new round of attacks could come from two sources—both are part of trends in ransomware.

  • The long con: The first scenario is that the same individuals that executed the original OPM hack are now launching these ransomware attacks. If this is the case, it at least alleviates some concerns that the OPM hack was state-sponsored cyberterrorism and/or a sign of a new kind of “cold war.” But the trend toward this type of “long con” is scary in its own right. Users are already more likely than ever to “click the link”—now patient cyber criminals are using hacked data to deploy extremely authentic phishing scams.
  • The “kick ‘em while they’re down” attack: It’s more likely that the OPM ransomware attack is just an example of enterprising cybercriminals seeing vulnerability in the already-victimized. This is another unsettlingly effective trend—like “ambulance chasing” for cybercriminals: Follow the headlines to find organizations that have recently been hit with a cyberattack (of any kind), then swoop in posing as official “help” in investigating or preventing further damage. Clever cybercriminals know they can prey on the anxiety, fear and uncertainty of users in this position.

How can you get ahead of evolving ransomware?
Though we’ve said it a thousand times, it’s more true than ever: Ransomware is evolving at an incredible rate and it is overwhelming traditional data security tools. Paying the ransom becomes an appealing option to unprepared businesses, and this steady cash flow only fuels the problem.

Want to see where ransomware is headed next and understand how you can snuff out this threat? Read our new report, The ransomware roadmap for CXOs: where cybercriminals will attack next.

Jeremy Zoss, Managing Editor, Code42

[Cloud Security Alliance Blog]

“My life story is not complete without ISACA”

Much of Phillimon Zongo’s youth was spent walking or running great distances barefoot, sometimes en route to school, other times scouring the township for empty cola bottles he could sell for change. Whatever the distance, Zongo was determined to find a way to afford food to fill his belly and knowledge to fill his brain.

Zongo’s first pair of shoes came when he was 12, prompting months of adjusting his steps to acclimate to the new sensation. But with or without footwear, in warm or wintry conditions, traversing the roads of rural Zimbabwe often was preferable to being home, where he and his large family lived in poverty.

His living conditions deteriorated further as a teenager. Needing affordable housing closer to his new school, Zongo moved away from his family at the age of 14 and shared a bleak, squalid structure – lacking water, electricity and with a makeshift door that would not lock – with fellow tenants who often became embroiled in jarring verbal and physical clashes with visitors.

During his youth, Zongo hid his living conditions from friends for fear of being bullied. Now that he has ascended to remarkable heights – personally and professionally – the ISACA member revisits his upbringing with pride.

“It’s not painful at all,” Zongo says. “Like so many kids, we were born into these situations. It was never our choice. My parents were loving and supportive, and I greatly appreciate that. They were also born into poverty, but they did all they could so that we would lead better lives. Would I have loved to get my first pair of shoes much earlier in life? Of course, yes, but that was beyond my control. What matters is I managed to make do with what I had, and I am here now.”

These days, here is Sydney, Australia, where Zongo is a successful cyber security consultant in the financial services industry. In October, Zongo was honored by the ISACA Sydney Chapter as Best Governance Professional of 2016, reflecting recognition from industry peers about the thought leadership he has contributed to the profession. That includes a 2016 article on managing cloud risk in the ISACA Journal; another ISACA Journal article, this one on opportunities and risks of automation, published this January.

“I have accomplished so many other things, but this is close to my heart given the importance of education to my life and how ISACA opened so many doors to me,” Zongo says. “I feel so privileged to be able to give back.”

Zongo’s life story, he says, “is not complete without ISACA.” His successful pursuit of Certified Information Systems Auditor (CISA) certification bolstered Zongo’s qualifications for his first position as an enterprise risk services consultant with Deloitte.

“Pursuing my CISA qualification was one of the most game-changing decisions I ever made,” Zongo says. “It afforded me the opportunity to work for some of the most respected global brands and connected me with a global network of highly accomplished professionals. Mostly importantly, it instilled in me high ethical standards, essential to retain the high levels of trust and confidence the society places on our profession.”

The Deloitte opportunity helped Zongo grow into a polished professional, as he quickly adjusted to corporate dress codes and navigating the etiquette of taking clients out for lunch.

“The problem is that society gives people labels, and these I have had to actively resist,” Zongo says. “If you are from the country they call you unpolished, in a way that suggests you can never attain polish. These, if left unchecked, can precipitate self-hate or undermine your confidence.”

Two years after starting with Deloitte, Zongo accepted a consultant position at PwC Australia in 2007. Zongo arrived in Australia with only $300 Australian in his pocket, but he was unfazed, having known much greater financial hardship throughout his life. The ability to anticipate a reliable paycheck outweighed the intense homesickness that marked his first several months in Australia.

Just as Zongo maintained laser focus on his education during his tumultuous youth, he did not allow his new environs to deter him from his career goals. He joined a prominent Australian financial services company as an IT risk manager in 2011 and now is a security consultant there. In recent years, Zongo has become particularly passionate about raising the profile of cyber risk among business leaders.

The resolve he summoned as a youth continues to serve him well. Zongo emphasizes that no matter how much he struggled during his youth, he never felt alone. While some acquaintances from his childhood were able to rise above their difficult circumstances, many, he says, remain “trapped in despair and hopelessness.” Securing a more fulfilling future required a tenacious desire to break the cycle of poverty that afflicted his family for generations.

“I believe we are all born with innate abilities to persevere and overcome life challenges,” Zongo says. “But passion by itself accomplishes nothing; to succeed you need a great deal of stubbornness. Especially where I grew up, you have to overcome these challenges over a long period of time. Perseverance and courage are virtues you nurture through practice.”

About a year after his move to Australia, Zongo married his fiancée from Zimbabwe. He and his wife, Fadzi, have two children – daughter Nyasha Valerie, 3, and a baby boy, Mukundi Christian. In addition to the joy he finds in his work and family commitments, Zongo likes to play golf – a largely unaffordable pastime in Zimbabwe – both for fun and for networking. He is skilled enough to have won several local club competitions, but is more proud of a golf fundraiser he organizes annually to raise money to repair dilapidated infrastructure at his old high school in Zimbabwe, pay fees for underprivileged kids and meet other special needs.

In addition to having earned the CISA, Zongo has passed the Certified Information Security Manager (CISM) exam, and remains grateful that ISACA “has helped me turn my story into one of determination, hard work and passion.”

“The odds were stacked against me, but if I made any excuses – or felt sorry for myself – I would never be speaking to you today,” Zongo says. “I had clear goals in mind, to eventually be able to live a dignified life and support my family, and nothing mattered more to me. I also was fortunate to have individuals who supported me and advocated for my success, and as I walked through the filthy township streets, I knew one thing for certain: I would never let them down.”

Editor’s note: ISACA’s family of more than 140,000 members and certification holders consists of truly outstanding individuals who are making significant contributions to the profession and the world. Watch for more stories like Phillimon’s coming soon, and contact jschwab@isaca.org if you have a member story you’d like to share. If you are not a member, consider joining our community. View the ISACA Member Advantage here.

[ISACA Now]

English
Exit mobile version