Weekly Security Headlines: WannaCry Spillover, Mickey Mouse Hacked, DocuSign Phishing and 560 Million Passwords

Not surprisingly, WannaCry remained top of mind last week. We’re sure you’re doing everything you can to patch your environment and prevent similar ransomware attacks in the future. Here are some WannaCry headlines (and other security news) that caught our eye last week.

 

WannaCry Rolls On

According to the Dark Reading article WannaCry’s ‘Kill Switch’ May Have Been a Sandbox-Evasion Tool, researchers early last week were looking into the “kill switch” and consensus seemed to be building that it was a poorly constructed VM analysis/sandbox evasion technique.

WIRED went a bit deeper with their assessment The WannaCry Ransomware Hackers Made Some Real Amateur Mistakes. They concluded:

An attack of this magnitude involving so many missteps raises plenty of questions while delivering a sobering reminder: If actual cybercriminal professionals improved on the group’s methods, the results could be even graver.

Want to learn how fast WannaCry can spread? BleepingComputer’s reporting shows has aggressive and fast this ransomware can propagate to vulnerable machines:

During one of those infections, WannaCry infected the honeypot in a mere three minutes after it was reset, showing the aggressive nature of the ransomware’s scanning module, which helps it spread to new victims…Furthermore, three minutes is about the same amount of time IoT malware will infect a vulnerable home router left connected to the Internet without patches.

Security vendor Check Point created an infection map for anyone curious about the latest global distribution of WannaCry here.

 

House of Mouse Hacked?

Disney has reportedly been targeted by cyber-extortionists who have pirated a copy of the Pirates of the Caribbean: Dead Men Tell No Tales, threatening to release the movie online if a ransom is not paid. Netflix was similarly targeted when a third-party production company was reportedly compromised and leading to episodes of the Orange is the New Black being were leaked online. Infosecurity Magazine reported on it here.

CNBC reported on May 20:

Thus far, Disney has refused to cooperate, raising the possibility that “Pirates” could hit the Internet before its planned release date.

 

No Jailbroken Phones on Your Network. Are You Sure?

Dark Reading recently covered findings from mobile security vendor Lookout. According to the article:

A jailbroken iPhone or a rooted Android phone that connects to the corporate network is one of the greatest fears of CISOs and other security team members, according to a new study. Their fears are not unfounded. Mobile security firm Lookout Security found five in every 1,000 Android devices in enterprises were rooted, while one in every 1,000 iPhones device was jailbroken.

 

DocuSign Phishing Campaign

According to Krebs on Security:

DocuSign, a major provider of electronic signature technology, acknowledged today that a series of recent malware phishing attacks targeting its customers and users was the result of a data breach at one of its computer systems.

Check out Krebs’ write-up to learn more and see a screen shot of a very convincing phishing sample.

 

560 Million Passwords Now Easier to Get

Reports emerged last week of a giant trove of new stolen passwords has surfaced online. According to CNet:

…while this database is composed largely of passwords from a variety of sources, many of them years old, its newfound accessibility — and conglomeration into a single collection — is cause for concern.

[(ISC)² Blog]

GDPR/NIS Countdown: How Ready Are Organisations to Get Their Cybersecurity in Order for the Next Decade?

This month marks the start of the 12-month countdown for organisations to be ready to comply with either – or in some cases both – the General Data Protection Regulations or the NIS Directive becoming law in Europe on the 25th and 10th of May 2018, respectively.

Whether you have started working towards compliance in the last year or not, the deadline to be ready for these new laws is fast approaching, and the pressure to review, change and test new cybersecurity systems increasing.

So, what’s the current state of mind of cybersecurity and business leaders as we count down? In research recently commissioned for Palo Alto Networks, we found that IT security professionals across Europe are generally optimistic about how these laws will help avoid personal data and cybersecurity breaches. However, there is still some hesitation when it comes to how easy the change will be. What is immediately clear is there are vast geographical differences when it comes to openness to new ideas; senior management in countries like Sweden are least likely (28 per cent) to accept suggested ideas for change from internal stakeholders, whereas Dutch respondents were far more willing to adopt new ways to best protect their organisation (39 per cent).

A fear of the unknown continues to present a significant roadblock over the next year, and not all businesses can see the benefit in change. Only a third of respondents think they will get the support to implement the necessary changes, while the majority still feel there will be obstacles to overcome.

With only one in ten respondents admitting that pressure to comply with new laws would make them open to ideas for change, there is a major shift in perception needed to ensure European businesses are ready come May 2018. Our research found that:

  • 43 per cent of IT security practitioners were concerned changes to legislation will unleash a wave of previously unknown personal data and cybersecurity breaches that need to be reported.
  • Half of all IT professionals (49 per cent) said they avoid security system changes or updates because they think their current system is already broadly secure.
  • 56 per cent of IT security professionals think the GDPR/NIS implementation will be a pain both financially and operationally.

With all that in mind, there are several ways businesses can prepare themselves today ahead of May 2018:

  • Gain visibility of what information is being used and through which applications. If you don’t have ongoing insight into how your business is already processing information through technology, then you can’t validate if this is appropriate and what controls must be wrapped around it.
  • Too much of cybersecurity is legacy technology – leverage the new regulations as an opportunity to clean your house, validate that everything is fit for a purpose, today and in the future, especially considering that cybersecurity will continue to evolve, and the biggest shortfall is skilled cybersecurity people. Consider how you apply and maintain an adaptive cybersecurity ecosystem that is automated to work at the same speed as the attacker.
  • Ensure that you have clear leading and lagging metrics to validate the effectiveness of your cybersecurity. Can you prove to your own business and others that you are effectively aligning current best practices to the risks?
  • Test your capabilities – not just the technology, but also the people and processes around these, including the broader businesses teams.
  • Cybersecurity leaders will need to validate that their cybersecurity capabilities are relevant to the risk they face and that they leverage current best practices, referred to as “state of the art”, with clearly documented processes and measures.

To learn more about how you can prepare your business for the upcoming new laws, please see the following Palo Alto Networks assets:

[Palo Alto Networks Research Center]

A Management System for the Cloud – Why Your Organization Should Consider ISO 27018

Cloud computing technologies have revolutionized the way organizations manage and store their information.  Where companies used to house and maintain their own data, a host of organizations have now made the switch to a cloud-based model due to the ease of use and cost-saving benefits promised by the cloud.

But what is a cloud without a little rain?  The benefits of cloud technologies have not come without their costs.

Within the world of cloud computing, there have been three persistent concerns:

  1. Security
  2. Security
  3. Security

A quick search for the pitfalls and concerns organizations face with cloud computing yields a recurring motif.  Every company looking to incorporate a cloud-based service has to weigh the benefits that a cloud environment affords against the risks associated with entrusting an organization with its sensitive data.  This data tends to include personally identifiable information (henceforth referred to as PII), which is generally the most scrutinized category of data and is subject to some of the strictest legal and regulatory requirements.

Customers of cloud service providers want to rest assured that the PII they have entrusted a cloud service provider with is maintained and held to at least the same level of security standards that they would have placed if the data had remained within their control.  For some organizations, the stakes are even higher as this is mandated by certain legal and regulatory requirements such as the Health Insurance Portability and Accountability Act (HIPAA) for electronic personal health information and the Graham-Leach-Bliley Act (GLBA) for sensitive financial information.

Many cloud service providers maintain that they are ignorant to the data ingested on behalf of their customers.  However, in the event of a security breach involving either personal health information or sensitive financial data, significant fines and reputational damage can be incurred by the cloud service provider if appropriate security and privacy measures are not in place.  This is where an effective information security management system, with specific control considerations tailored to cloud security and privacy surrounding PII, can prove invaluable to a cloud service provider.

You may have questions regarding what an information security management system is.  To define an information security management system, it may be easier to first understand what it is not.  An information security management system is not referring to an actual “system”, “application”, or “tool” that performs information security functions.

A broader definition is as follows: an information security management system represents the organization’s holistic approach to addressing information security concerns.  This includes top management’s buy-in to addressing these risks which can be demonstrated in its actions by performing the following:

  • Fostering a top-down approach to information security that encourages personnel throughout the organization to be aware of information security best practices
  • Performing risk assessments that are tailored to its organization’s unique threats and vulnerabilities
  • Proactively searching for issues and concerns through the use and selection of internal auditors
  • Monitoring and measuring the performance and effectiveness of the information security management system
  • Establishing a commitment to continually improving the information security management system
  • Ensuring that security controls are implemented and applicable to its organization’s goals and purpose

The standard most commonly used to demonstrate an organization’s effective implementation of an information security management system is the ISO 27001 standard.  The ISO 27001 standard serves as a baseline framework which virtually all service providers, cloud-based or otherwise, can work toward implementing.  It is worth noting that ISO 27001 provides a multitude of benefits to organizations that implement an effective information security management system, but two are perhaps the most pertinent and deserve to be mentioned:

  • An effective information security management system demonstrates to prospective and current customers that the service organization means business about protecting the data that it is entrusted with and responsible for.
  • An effective information security management system assists organizations with establishing a forward-thinking, proactive approach to addressing information security concerns as opposed to enabling a backward-looking mindset which is generally fostered by audit culture, which typically focuses on historical information.

The above-mentioned points may be enough for any service organization to consider implementing an information security management system.  The reputational benefit that an organization can enjoy by demonstrating to its customers that it takes its handling of information seriously is difficult to measure.  The cost-savings that an organization can enjoy by implementing effective response procedures in the event of a security incident are also incalculable – just ask United Airlines.  Sure, maybe that was a different kind of incident, but the age-old adage remains: failing to prepare is preparing to fail – this is the essence of ISO.

However, the buck does not stop at ISO 27001, especially for cloud service providers who by virtue of their trade must take information security more seriously.  This is where organizations can implement, in addition to the requirements held forth by the ISO 27001 standard, a slew of measures to increase the security and privacy measures in place when handling sensitive data, such as PII.  This standard is referred to as ISO 27018, which can be achieved in tandem with an effective information security management system in accordance with the ISO 27001 standard.

ISO 27018, otherwise referred to as ISO/IEC 27018:2014, builds upon an organization’s information security management system by establishing a group of privacy-based controls that are dedicated to protecting PII in public clouds that act as PII processors, with an emphasis on protecting PII in the cloud.  ISO 27018 provides a new subset of controls dedicated to the protection of sensitive personal data.

A high-level overview of some of the ISO 27018 requirements are included below:

  • Providing cloud customers with the ability to access, correct, and erase their own PII
  • Ensuring that data is processed according to its intended purpose and not taken out of context
  • Procedures for the deletion of temporary files
  • Implementing defined disclosure procedures
  • Providing open, transparent notice in the event that sub-contractors are utilized
  • Encouraging accountability on behalf of the cloud service provider through the implementation of breach notification procedures
  • More stringent information security requirements on the part of the cloud service provider

Hopefully after considering the above, it is more clear that implementing an information security system aligned with ISO 27001 is tremendous for a service organization, but for cloud service providers hoping to assuage any security and privacy concerns for their customers, aligning these controls with ISO 27018 may be the organization’s best option.

As the technologies around us evolve, so do their underlying threats and vulnerabilities.  An effective information security management system affords an organization a proactive, forward-thinking approach to information security.  This is all the more important given that cloud computing technologies have been plagued with security and privacy concerns since their inception; the risks will only continue to increase.

If you represent a cloud service provider, it may be time to consider how your organization can benefit from the implementation of an information security management system that aligns its 27001 controls with the ISO 27018 objectives.

For more information on ISO 27018, you can view our webinar on-demand: Privacy in the Cloud – an introduction to ISO 27018

[Cloud Security Alliance Blog]

Ransomware: Why Are Organizations Still So Vulnerable?

Ransomware attacks are not new. In fact, ISACA has been sounding the alarm on the increasing spate of ransomware for quite a while. Unfortunately, it takes a massive-scale cyber attack like the recent WannaCry incident for such cyber crimes to gain national and international notoriety. In fact, another recent ransomware attack that caught the public’s attention in the U.S. came when San Francisco’s transportation department was hit last November, impacting the city’s light rail transit system.

There is a reason why ransomware attacks are becoming popular: For the bad guys, it simplifies the crime and the process of monetization.

Think about it. Earlier, even a simple computer crime involved two steps to get to monetization. First, the criminals have to break in and steal personal information like credit card details, and then secondly, sell it on the dark web, often to organized crime groups, in order to get paid. The buyers in turn use the credit card or other information to commit fraudulent transactions.

With ransomware, crime has become an easy, one-step monetization process. Attackers break in to a computer system, install ransomware and get the payment directly from the person or organization impacted. It’s a one-to-one interaction, and payment is easily received. While accepting ransomware payment in bitcoins may seem a bit more challenging than accepting a credit card payment, anonymity is crucial to cybercriminals, making it well worth the modest additional effort.

But even with increased awareness on cyber attacks and the heightened need for cyber security, the question remains: why are organizations still so vulnerable? And what can they do about it?

• Whitelisting: Sometimes a ransomware attack can start off with a phishing episode where someone within an organization downloads and runs a malicious executable. Once that happens, the company’s end-point security products (typically an antivirus software solution) is often not enough to detect the attack. That’s why organizations like ISACA, US-CERT and the National Association of Corporate Directors (NACD) also recommend implementing whitelisting or application control – a process by which an organization runs only “known good applications.”

In the past, whitelisting has been hard to manage and maintain. For example, when a company implements the whitelisting approach, every person and device in the company will run only known good code. But the problems arose in keeping the lists up to date, such as when an executive had to run an application like WebEx or GotoMeeting. When the application ran and automatically installed a new version of the solution, the executive would be prevented from launching it, until it was entered into the whitelist. The lack of productivity with old versions of whitelisting solutions spelled doom for that approach.

However, in the last year or so, the next generation of whitelisting solutions have hit the market, and they are far superior to the old ones. Newer solutions can trust entire families of software and pull the latest whitelists, making the process of managing “known good software” more intuitive and convenient for IT departments. So, it’s critical for organizations that earlier discarded the whitelisting approach to revisit that consideration again, especially in the face of increasing ransomware attacks.

• Patching: Keeping systems patched and up to date is important, but it is not a panacea since spear phishing attacks can still trick victims into installing ransomware.

 Backups: Maintaining a good backup helps organizations navigate the waters of a ransomware attack far more deftly. For example, when San Francisco’s transportation system was hit last fall, the city refused to pay hackers the $70,000 ransom that was being demanded. Instead, it took a few days to painstakingly restore backups and during that time, the city let the residents ride in the transit system for free.

Interestingly, we are also seeing the emergence of quirky trends among ransomware criminals. These hackers are increasingly adopting best practices to close ransom transactions quickly, as the ransom demands are often not too high compared to the time and effort it would take to restore the backup.

So, to motivate the victim to pay the ransom, ransomware attackers are:

  • Offering discounts if the ransom is paid within a set number of days
  • Adopting a “try before you buy” approach, where the affected party can ask for a specific file to verify the veracity of the hacker’s claims
  • Offering technical “chat” support after the ransom has been paid to assist the victim in recovering files

But despite these best practice claims by cybercriminals, organizations that have become victim to ransomware attacks need to make sure a thorough cleanup process is executed as part of the incident response – perhaps even scrubbing and restoring the entire system and network – to make sure the attackers are no longer there.

Rob Clyde, CISM, Board Director, ISACA, Executive Chair of the Board of Directors at White Cloud Security

[ISACA Now Blog]

Why Directors Feel Inadequate in Terms of Cybersecurity and What They Can Do About It

Executive Summary

The National Association of Corporate Directors says that directors do not feel adequate in terms of mitigating cybersecurity issues. The problem is that we have led ourselves to believe that cybersecurity risk is somehow different from all the other risks that directors deal with daily. This is incorrect. The same risk strategies apply: acceptance, avoidance, mitigation and/or transfer. The needed change is that directors must insist that their technical C-level executives transform technical risk into business risk. The board needs to help them with this because many are not comfortable doing it. But once done, all that is left to do is for the board to learn and understand at a high level some of the technical issues involved in these strategies. Start with the Cybersecurity Canon Project: a collection of network defender-recommended books about all aspects of security. As a priority, read these three books first: “Navigating the Digital Age,” “How to Measure Anything in Cybersecurity Risk,” and “Measuring and Managing Information Risk: A FAIR Approach.”

Introduction

Based on a recent survey conducted by the National Association of Corporate Directors, only 19 percent of board directors feel confident that they grasp the nuance of cybersecurity risks well enough to make well-informed decisions. A whopping 59 percent of directors surveyed by the NACD say that they feel inadequate to oversee these risks. [1] Those are shocking numbers since most every business today has some sort of cyber component. As the world sprints into the digital age, you would be hard-pressed to find a business that has no digital component helping to drive the efficiency and innovation of the company.

How Did We Get Here?

This situation is largely the fault of the network defender community: your CIOs, CSOs and CISOs. From the first CISO who was hired back in the mid-1990s [2] until the present day, the network defender community has insisted that the risks associated with cybersecurity were somehow unique compared to the myriad of other risks that directors deal with every day. They said that, because this kind of risk is mostly associated with computers, the internet and hackers, it belongs in some sort of risk category that requires special handling. This is wrong.

Cyber Risk Is Not a Special Kind of Risk

Risk is risk, whether it manifests from employee injury, property loss, business interruption, liability or a cybersecurity breach. Directors deal with this cyber risk the same way they deal with all other risks: they find ways to alleviate or eliminate potential material risk to the business. They use basic risk management strategies like acceptance, avoidance, mitigation or transfer. [3] From these strategies, all that is new to the director in dealing with cybersecurity risks are the potential technical mitigation strategies you might choose. But that is why you have the technical C-staff working for you. The CIO, CSO and CISO will understand the technical details. What you should be asking them to portray is the potential risk to the business.

This is hard for most technical C-levels. They understand the technical details, but many have trouble transforming that technical risk into business risk. They will need your help with understanding the business risk strategies that directors already understand and separating all the “scary” risks – because they come from hackers – from the potential-material-impact risks that threaten the company. In other words, there are many alarming scenarios that we all can manufacture when it comes to hacker stories, but articulating the scenarios that will have high impact to the business if they occur and, at the same time, have a high probability of occurring in the short term is the key. This is a conversation with which many technical C-level executives do not have a lot of experience. Once done, the last thing to do is for the director to gain a high-level understanding of the technical solutions your technical C-level executives recommend.

Director Homework

When learning about a new knowledge domain, the thing to do is to check the literature. Fortunately, there is a community project at your disposal on which directors can rely, called the Cybersecurity Canon Project. [4] Think of it as the Rock and Roll Hall of Fame for cybersecurity books. This is not just a book list. In order to get on the list, some network defender has to write a book review justifying why a particular book should have been read by all of us by now. There is a committee that consists of all types of network defender experts who read all of the submissions and decide which books make it onto the candidate list, and which books ultimately get put into the canon. For directors, I recommend two books that are currently on the candidate list and one book that is already in the canon.

“Navigating the Digital Age: The Definitive Cybersecurity Guide for Directors and Officers,” published by the New York Stock Exchange and Palo Alto Networks

“Navigating the Digital Age” is the first comprehensive book specifically designed to enlighten and educate corporate directors and officers in terms of cybersecurity. The book includes more than 30 contributors, so it is meaty; and while there is some overlap in the material covered, it contains a dense collection of information around fundamental principles for the board members to do their jobs; board standards to consult; the executive on whom they should rely – the CISO; which committees they should create to support their efforts; what they should worry about in terms of fiduciary responsibility and the potential for litigation; the perceived cybersecurity disconnect between shareholders and board members; and finally, how they should think about disclosing breach information to the public. [5] This is a free-to-download book published in partnership by the New York Stock Exchange and Palo Alto Networks. Since the publication of this book, Palo Alto Networks has published companion books in France, Australia, Japan, Singapore and the U.K. We plan to publish books in Germany and Holland this year too. [6]

“How to Measure Anything in Cybersecurity Risk,” by Douglas W. Hubbard and Richard Seiersen

“How to Measure Anything in Cybersecurity Risk” is a book anyone who is responsible for assessing risk should read. It is grounded in classic quantitative analysis methodologies and provides a good balance of background and practical examples. The authors lay out a solid case for why other industries with the similar challenge of a lack of quantifiable, standardized or historical actuarial table-like data are able to use classic statistical modeling and methodologies to measure risk in a qualified, repeatable way. [7]

“Measuring and Managing Information Risk: A FAIR Approach,” by Jack Freund and Jack Jones

“Measuring and Managing Information Risk” is a book that not only describes what risk is but also teaches you how to measure it quantitatively so that practitioners can demonstrate to their leadership that they understand the problem. It shows how to deliver financially derived results tailored for enterprise risk management and is intended for organizations that need to either build a risk management program from the ground up or strengthen an existing one.

It covers key areas, such as risk theory, risk calculation, scenario modeling and risk communication within the organization. [8]

Conclusion

Cybersecurity risk is no different from any other kind of risk that directors normally handle in their day-to-day jobs. In the early internet days, we let the technicians convince us otherwise. Now we are trying to re-learn what the real truth is: that we can use the same traditional risk strategies for cybersecurity as we do with all other business risks: acceptance, avoidance, mitigation and/or transfer. Many of our technical C-level executives need help transforming technical risk into business risk. The director can help with that. Insist that your technical C-levels sort out the “scary” risks from the probable high-impact risks. To gain a high-level understanding of some of the issues, directors should refer to the Cybersecurity Canon Project and read the literature that the network defender community recommends, beginning with these three books: “Navigating the Digital Age,” “How to Measure Anything in Cybersecurity Risk,” and “Measuring and Managing Information Risk: A FAIR Approach.”

Sources

Book Reviews

References

[Palo Alto Networks Research Center]

English
Exit mobile version