Palo Alto Networks researchers were recently credited with discovery of two new Apple product vulnerabilities.
Researchers Tongbo Luo and Bo Qu discovered a webkit vulnerability (CVE-2016-1855) affecting Safari in OS X Mavericks v10.9.5, OS X Yosemite v10.10.5 and OS X El Capitan v10.10.5.
Tongbo and Bo also identified an OpenGL vulnerability (CVE-2016-1847) affecting Apple TV (fourth generation and later), iPhone 4S (and later versions), iPod Touch (fifth generation and later), and iPad 2 (and later versions).
Apple addressed both findings in a recent security update. Palo Alto Networks has also released IPS signatures covering these vulnerabilities (for current customers, available in content release 585).
Palo Alto Networks is a regular contributor to vulnerability research in the Microsoft, Apple, Android and other ecosystems. By proactively identifying these vulnerabiliites, developing protections for our customers, and sharing the information with the security community, we are removing weapons used by attackers to threaten users and compromise enterprise, government and service provider networks.
In a recent conversation with Linda Moss, VP of Global Enablement and Education at Palo Alto Networks, I was shocked to learn just how significant of a cybersecurity workforce shortage there is in this industry. Our conversation included both the volume of threats seen in the modern threat landscape and the growing number of opportunities this landscape is creating for students and IT professionals to either begin or transition into a lucrative career in cybersecurity.
With the cybersecurity industry expected to grow from $75 billion to $170 billion in the next five years, or so, the need for trained professionals is skyrocketing. In my opinion, Linda has one of the most exciting jobs in our company, but also one of the largest responsibilities, as her team develops a curriculum that will enable a next-generation cybersecurity workforce. Some experts predict that, by 2019, the demand for cybersecurity professionals will increase to approximately 6 million globally. What is even more surprising is that the shortage of trained professionals is projected to be 25 percent – or 1.5 million jobs unfilled.
I was happy to capture our conversation in a short video that I’d like to share with you. Here, Linda and I discuss several key areas of education, including the overall skills shortage, types of training available, the Palo Alto Networks Certified Network Security Engineer (PCNSE) certification, and the Accredited Configuration Engineer (ACE) accreditation. In addition, Linda has some great insight regarding the importance of working with colleges and universities to ensure future generations get the necessary skills to prevent successful cyberattacks through the Palo Alto Networks Academy program.
Palo Alto Networks joined a cybersecurity business development mission of 14 U.S. ICT companies to Japan, Korea and Taiwan from May 16–24, 2016. The mission, led by U.S. Assistant Secretary of Commerce Marcus Jadotte, aimed to foster cooperation with these countries on cybersecurity from both a policy and business angle, exchanging challenges, experiences, ideas and best practices from both government and industry perspectives.
Palo Alto Networks was honored to be part of this high-level delegation. As three of the most developed and networked countries in Asia, Japan, Korea and Taiwan have extremely digitized economies, ICT-savvy businesses and citizens, and some of the most advanced manufacturing in the world. Thus, these countries have essential roles to play in helping the region chart a solid course in cybersecurity policies that take account of the interconnectivity and interdependence of each other and the global economy.
Each stop offered numerous opportunities to engage with governments, academics, industry officials, and other thought leaders, all of whom are taking steps to craft workable approaches to cybersecurity. All three stops included conferences or workshops where participants shared about their current cybersecurity policy activities. Palo Alto Networks spoke at the Spotlight on Cybersecurity Conference in Tokyo and the Korea-U.S. Cybersecurity Policy and Business Exchange in Seoul, providing our views on cybersecurity in critical infrastructure and the Internet of Things (IoT), as well as the increasing emphasis we see in the United States on cybersecurity being viewed as an issue for the C-suite.
The Taiwan stop of our trip from May 23–24 had fortuitous timing, coinciding with the first two days of the new administration that had been inaugurated the prior week. Taiwan President Tsai Ing-wen has made cybersecurity one of her top priorities, and the government plans to finalize and pass later this year its pending Cybersecurity Act, which will lay out expectations and requirements for the government as well as government-owned companies and infrastructure on cybersecurity. We look forward to working with Taiwan as it passes this law.
All in all, the mission shed extensive light on activities in the three countries. We appreciated the governments of Japan, Korea and Taiwan sharing with us their current actions and future plans to strengthen their cybersecurity and seeking industry’s input on these initiatives. Japan, Korea and Taiwan alike are devoting more government and private sector resources to combat cyberthreats, and protect critical infrastructure, and investing in computer emergency response teams (CERTs), cyberthreat information-sharing, public-private partnerships, and international cooperation.
Palo Alto Networks commends the U.S. government for organizing this mission. The leadership from Washington was complemented in each capital by senior U.S. embassy officials—including Ambassadors—who hosted our delegation and counterpart government and industry officials, signifying the importance placed by the United States on dialogue and cooperation on cybersecurity with these three countries. The mission facilitated extremely fruitful discussions that are hugely important both in government and industry. We look forward to building upon the relationships and partnerships we have in Japan, Korea and Taiwan and continuing to work with these leading countries to enhance cybersecurity and resilience in the global economy.
Danielle Kriz, Jae Heun Shim, and Charles Choi of Palo Alto Networks, with the mission delegation, at the residence of U.S. Ambassador to South Korea Mark Lippert.
We often hear about cyberattacks consisting of exploits or malware meant to gain control of victim machines, and the term “phishing” has become more widely used and understood. Even my dad now knows what phishing is, not because I told him, but because of headlines in news publications like these:
According to Verizon’s recently released 2016 Data Breach Investigations Report, phishing attacks overwhelmingly aim to steal legitimate user credentials. Genuine credentials are valuable because they provide attackers with “authorized” access, which is less likely to trip any alarms or alert administrators, which, in turn, means more time for attackers to do what they will.
Verizon reported that around 1000 breaches in 2015 were the result of stolen credentials. If you’re the attacker, why try to break in through the second story window when you’ve got a key to the front door? And if you’re the target, how do you stop attackers from using your own front door keys to break into your house?
Verizon recommends a few things to stop credential phishing and limit attackers’ movement, should they be able to bypass your network protections:
Use an email gateway to inspect email content and filter out those pesky phishing emails. (We highly recommend Proofpoint – keep reading to find out why!)
Provide your users with a straightforward way to contact your security team should they suspect a phishing attempt.
Require strong authentication – no one should be using default passwords or easily guessable passwords consisting of less than 12 characters – and when two-factor authentication is available, use it!
Use internal network segmentation to limit how far attackers can get and make sure they cannot easily pivot to where the high-value stuff is kept.
Inspect outbound traffic for signs that users have been compromised. Look for suspicious HTTP and DNS connections and file transfers – these are signs of command-and-control traffic and data exfiltration.
Of course, being a security company, we always have phishing attacks top of mind as challenges to solve. We’ve recently implemented new features within PAN-DB to help our customers fight the ongoing phishing battle using URL Filtering and WildFire.
Recognizing New Phishing Websites
WildFire now includes frequent updates to PAN-DB’s phishing category in its generated set of protections. It actively looks for links to spoofed websites and web forms containing usernames and passwords that are intended for unapproved or unknown web applications. These quick categorizations enable our customers to block access to newly discovered phishing sites so your users don’t get duped into giving away their credentials.
Better Together
In addition, we’ve recently partnered with Proofpoint to help our joint customers better secure themselves against malicious emails, including phishing emails and emails with exploitive or malware attachments and malicious links. Armed with Proofpoint deployed for email, and a WildFire API key, customers can easily integrate Proofpoint’s visibility into all pre-filtered incoming email with WildFire’s thorough analysis engine to prevent attacks both at the email gateway and at the firewall – a double layer of protection against phishing.
As Verizon has noted, 63 percent of confirmed data breaches involved leveraging weak, default or stolen passwords. This problem is not one that technology can fix by itself; real people are being targeted, and real people are necessary to overcome phishing attacks. User education – though not 100 percent effective against phishing attacks (some of these targeted emails areinsanely well-crafted, guys) – can help to significantly decrease the attackers’ success rates.
Has your organization done anything unique in terms of people, process or technology to help tackle the phishing problem? And, of similar importance (not really), how many other phishing puns can you think of?
Check out the lightboard video below to learn more about phishing and how Palo Alto Networks helps to prevent it.
Leaders from Japan, Canada, France, Germany, Italy, the UK, and the US, as well as representatives of the European Union, gathered for the G7 Ise-Shima Summit in Japan May 26-27 to address major global economic and political challenges. Notably, for the first time at a G7 Summit, their discussions included cybersecurity. In fact, the “G7 Ise-Shima Leaders’ Declaration” released May 27 contains several consensus items regarding cybersecurity, captured as a standalone topic, reflecting the critical importance and geopolitical consequences of this issue in today’s world.
Among other things, the Leaders’ Declaration endorses the G7 Principles and Actions on Cyber, which promote security and stability in cyberspace as well as the digital economy, and commits the leaders “to take decisive action” regarding those Principles. Cybersecurity came up not only in this Summit, but also in an array of related G7 meetings leading up to it this spring: the G7 Foreign Ministers’ Meeting April 10-11, the G7 ICT Ministers’ Meeting April 29-30, the G7 Finance Ministers and Central Bank Governors Meeting May 20-21, and the G7 Energy Ministerial Meeting May 1-2. This consistent discussion reflects governments’ growing concerns over the malicious use of cyberspace by hackers, criminals, state actors, and terrorists, as well as emerging global trends that challenge an open and interoperable cyberspace—all of which threaten our critical infrastructure, digital economy and economic growth.
Given growing concerns over the current economic downturn in many countries, it makes sense that the Leaders focused on the economic contribution of cyberspace, and confirmed that “an accessible, open, interoperable, reliable and secure cyberspace” is an “essential foundation for economic growth and prosperity.” Indeed, cyberspace is a fundamental enabler of our digital lifestyle, although malicious actors can use it to threaten our daily lives, economies, and national or international security.
This vision of cyberspace as a foundation for progress is shared by the G7 host country, Japan, whose Cybersecurity Strategy 2015 was the first Japanese national information securitystrategy to recognize that cyberspace is also a frontier for innovation and sustainable economic growth.
We welcome the G7 Leaders’ decision to launch a new G7 working group on cyber to enhance policy coordination and practical cooperation to promote security and stability in cyberspace. The Declaration does not say who will populate the working group. While we expect the core members to be government officials, it is crucial to adopt a multi-stakeholder or “Track 1.5” approach to incorporate industry input. Governments and the private sector alike seek greater cybersecurity and resilience, and it is necessary to combine government insights about policy and national strategy with industry knowledge about technical innovation for cyber threat prevention and defense. All players must participate to ensure that the envisioned coordination and cooperation is practical and feasible.
It also is commendable that the G7 is focusing on cybersecurity in critical industry sectors dependent on cyber infrastructure, namely finance and energy. The Declaration highlights the work of the G7 Cyber Experts Group in the financial area to foster cybersecurity and enhance cooperation among G7 countries in this arena. This is important, given the ongoing trend of cybercrimes targeting the financial sector, such as the theft of $81 million from Bangladesh’s central bank in February 2016.
In the Joint Statement from the G7 Energy Ministerial Meeting earlier in May, the Ministers committed to advancing resilient energy systems including electricity, gas and oil, in order to respond effectively to emerging cyber threats and to maintain critical functions. The usefulness of this commitment is evidenced by the power outage, caused by cyber-attacks, which affected 225,000 people in Ukraine in December 2015. Such cyber sabotage against critical infrastructure can potentially disrupt medical services and other key social services, leading to the loss of lives. These areas of focus demonstrate the G7 countries’ concern about the potential damages to these sectors of critical infrastructure, which can sap competitiveness, cause a loss in business and consumer confidence, and dampen the countries’ economic strength and security.
Finally, it is meaningful that this heavy emphasis on cybersecurity was made at the series of G7 meetings hosted by Japan. We are sure that Japan played an important role in ensuring this emphasis. Japan has its own internal interests, including the security of the electric power industry in the wake of the Great East Japan Earthquake in 2011 (which led to catastrophic consequences with the cascading impacts from the Fukushima Daiichi nuclear power plant accident). As the host of the G7 Summit 2016 and the upcoming Tokyo Summer Olympic Games in 2020, Japan is expected to set an example of cybersecurity and the protection of critical infrastructure. Best practices and new partnerships will be born from the lessons.
The next steps for the G7 leaders and the new G7 cyber working group are to figure out how to overcome silos and facilitate smooth communication across borders, among key players in government and industry. While bureaucratic stove piping is not unique to cybersecurity, the repercussions can be more problematic when cyber attacks or threats affect multiple sectors, governmental agencies, and countries. Given that attackers will always try to exploit the weakest link, the scale of global Internet interconnectivity means that one country’s robust cyber defenses – or economic prosperity – may be weakened if its counterparts fail to protect themselves. This could lead to information breaches and compromised systems or networks globally.
The call for a multi-stakeholder approach to cybersecurity across borders is not new, but has been slow to gain solid footing. It could be that we have lacked clear goals or deadlines. The Tokyo Olympic Games 2020 would be a golden opportunity to create a prototype of a Track 1.5 cybersecurity dialogue and information-sharing framework. Only four years away, the event has a wide variety of stakeholders, including the G7 countries. Such a prototype can help pave the way to more efficient global cooperation on cybercrime and critical infrastructure protection.
This is the second in a series of blogs co-authored by Mihoko Matsubara and Danielle Krizaimed at introducing Japan’s cybersecurity efforts and their significance to a global audience, including governments, global industry, and other thought leaders. Subsequent blogs are expected to cover additional thoughts on the METI/IPA Cybersecurity Guidelines, Japan’s role in global cybersecurity capacity-building, cyber threat information-sharing and prospects for Japan, the cybersecurity ramifications of planning for the Tokyo Olympic Games 2020, and other topics.