Month: July 2019

  • 2022 Cybersecurity Predictions from Lookout: Work From Anywhere Ends On-Premises Security

    2022 Cybersecurity Predictions from Lookout: Work From Anywhere Ends On-Premises Security

    Lookout, an endpoint-to-cloud cyber security company, have put together their cyber security predictions for 2022.

    — Cloud connectivity and cloud-to-cloud connectivity will amplify supply-chain breaches

    One area organizations need to continue to monitor in 2022 is the software supply chain. We tend to think of cloud apps as disparate islands used as destinations by endpoints and end-users to collect and process data. The reality is that these apps constantly communicate with different entities and systems like software-update infrastructure and with each other — interactions that are often not monitored.

    In late 2020, the cybersecurity community uncovered one of the worst breaches in recent memory when the SolarWinds software-publishing infrastructure was infiltrated. More than 100 organizations, including nine U.S. federal agencies, were compromised by trojanized updates that opened backdoors to their infrastructure. This is a prime example of how a weak supply chain can be used to amplify the attack by taking advantage of cloud interconnectivity. Now that this attack vector was proven to be successful, expect copycats to follow suit in 2022.

    In addition to SolarWinds-type attacks, Lookout predicts threat actors to look into exploiting another seldomly-monitored area: cloud-to-cloud interaction. For example, it is very common for organizations to use HR software to capture an employee’s personal and financial information, which is then shared to a payroll system. Once apps are connected to each other, seldom do enterprises monitor these automated workflows for changes in behavior. An attacker could exploit this implicit trust between systems to siphon off sensitive data without anyone noticing.

    — User error and account compromises to become more pronounced

    One of the major advantages of SaaS apps is the ease by which we can collaborate with colleagues, customers and business partners. Using apps like Workday, Salesforce, Slack, Google Workspace or Microsoft 365, we can share content and collaborate with others with very little friction.

    But this interconnectivity also significantly amplifies the impact of any user errors or attacks. Whether an employee accidentally shares a document with the wrong person or a compromised account extracts information, data now moves at lightning speed. As we head into 2022, with hybrid and remote work cemented as the new norm, Lookout expects this to become an even bigger issue.

    — Converging technologies to bring threat hunting to a new level

    One of the steps organizations need to take to tackle evolving threats is to leverage threat hunting, also known as detection and response. The requirement for this is quickly becoming recognized, including with the U.S. government. I’m encouraged by the fact that the U.S. Office of Management and Budget (OBM) provided funding guidance for federal agencies to adopt detection and response capabilities.

    To operationalize threat hunting in 2022, Lookout expects organizations will look into integrated endpoint-to-cloud security solutions that are cloud-delivered. With everyone working from anywhere and using unmanaged devices and networks, there are an unprecedented number of entities and communications for security teams to track. When security technologies converge in the cloud, organizations can take advantage of storage and computing power that on-premises tools never had. Security teams can also leverage security insights in a single place, enabling them to hunt for threats or conduct forensic investigations proactively.

    — DLP to become center of cloud-delivered cybersecurity

    Data loss prevention (DLP) has traditionally been deployed as a standalone tool tethered to an enterprise’s perimeter data exchange points. This isn’t how things work anymore. Data now flows freely between clouds, endpoints and other entities — not just enterprise managed, but also with partners and contractors. To regain control, organizations need full visibility into how their data is handled regardless of where the users are and what device and network they’re using.

    Lookout predicts that organizations will accelerate the move to cloud-delivered solutions where data protection, inclusive of DLP and enterprise digital rights management (E-DRM), are at the heart of it. More and more enterprises will look for advanced DLP capabilities such as exact data match (EDM) and optical character recognition (OCR) to keep abreast of all the new workflows. Only by tapping into the scalability and power of the cloud can security solutions ensure that data is protected efficiently without hindering productivity.

    Is 2022 the beginning of the end for on-premises security?

    Nearly two years after most organizations were forced to experiment with remote work, 2022 will be an inflection point for both threats and cybersecurity solutions. With increased interconnectivity comes heightened security gaps, such as software supply chain vulnerabilities and data leakage. But this also means an accelerated adoption of integrated, cloud-delivered security solutions that enables proactive threat hunting and advanced data protection.

    On-premises security tools that are deployed in isolation are no longer enough, even for on-premises workloads. To tackle the ever-evolving challenges of a cloud-first world, organizations need to invest in an integrated platform that can secure their data from endpoint to cloud. Join Lookout on their upcoming webinar on January 27th at 10 am GMT: 3 Steps to Protect Cloud Data in the Wake of the Pfizer Data Leak.

    To learn more about how organizations should take advantage of the convergence of security technologies, download a complimentary copy of the “2021 Gartner Strategic Roadmap for SASE Convergence.”

  • Microsoft Provides Workaround for L2TP VPN Connections Issues on Windows

    Microsoft Provides Workaround for L2TP VPN Connections Issues on Windows

    The Redmond giant confirmed on its Windows Health Dashboard yesterday that its recent cumulative updates for Windows 10 (KB5009543) and Windows 11 (KB5009566) are causing problems with select IPSEC connections. “After installing KB5009543, IP Security (IPSEC) connections which contain a Vendor ID might fail.

    VPN connections using Layer 2 Tunneling Protocol (L2TP) or IP security Internet Key Exchange (IPSEC IKE) might also be affected,” the company explained.

    The problem has been reported by several IT administrators in a Reddit thread, which explains that users encountered a VPN connection error 789 when trying to use the Windows VPN client. “Can’t connect to VPN. The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer.”

    Passwords Haven’t Disappeared Yet

    123456. Qwerty. Iloveyou. No, these are not exercises for people who are brand new to typing. Shockingly, they are among the most common passwords that end users choose in 2021. Research has found that the average business user must manually type out, or copy/paste, the credentials to 154 websites per month. We repeatedly got one question that surprised us: “Why would I ever trust a third party with control of my network?

    The reports suggest that users have also noticed this bug with some third-party VPN providers, including Cisco Meraki, SonicWall, Ubiquiti, WatchGuard Firewalls, as well as the WatchGuard client.

    Microsoft provides a workaround for the L2TP VPN connections issue

    Microsoft has said that it’s actively investigating the VPN connection issues and plans to deliver a fix in an upcoming update. In the meantime, the company has asked users to mitigate the bug by disabling the Vendor ID on the VPN server-side settings.

    From the Windows Health Dashboard: Certain IPSEC connections might fail

    After installing KB5009543, IP Security (IPSEC) connections which contain a Vendor ID might fail. VPN connections using Layer 2 Tunneling Protocol (L2TP) or IP security Internet Key Exchange (IPSEC IKE) might also be affected.

    Workaround: To mitigate the issue for some VPNs, you can disable Vendor ID within the server-side settings. Note: Not all VPN servers have the option to disable Vendor ID from being used.

    Next steps: We are presently investigating and will provide an update in an upcoming release.

    In case you missed it, Microsoft has also acknowledged a new bug that prevents recent emails from showing up in Outlook searches. The Redmond giant has provided a temporary workaround to resolve the issue on Windows 10 machines.

  • Here’s exactly what you need to do to launch a mobile app

    Here’s exactly what you need to do to launch a mobile app

    The future is mobile; isn’t it time for your business to be part of it?

    I examined eight different ways your business could benefit from offering a mobile app. These included keeping up with your competitors, solving a problem that your customers face, retaining customer data to simplify  conversions, and effectively managing customer loyalty programs.

    If you’ve determined that the time is right for your own business to launch a mobile app, you’re certainly not alone. Statista estimated that as of the first quarter of 2018, over 7 million apps were available for download in the leading app stores. Mobile analytics powerhouse App Annie, meanwhile, found that the average U.S. consumer uses mobile apps for two hours and 15 minutes each day — which adds up to over one month during the course of a year.

    With numbers like that, it’s easy to see how launching an app that your customers adopt and use can be an enormous opportunity for your business. But remember: The quality of your app is paramount. According to a study by Localytics, 71 percent of mobile apps looked at by researchers were uninstalled within 90 days of installation.

    The plug-and-play option: Buildfire

    Buildfire offers customers two options for building a mobile app. You can hire its team of professional developers to create an app for you, or you can utilize its intuitive plug-and-play app builder. The platform has a wide range of templates to suit almost any business type.

    That’s useful if your service feels less straightforward than apps you may admire. You can also use an assortment of plug-ins to help you customize the functionality, as well as the look-and-feel of your mobile app.

    Once your app is ready to launch, Buildfire will then submit your app to Apple’s App Store and the Google Play store for Android. A platform like Buildfire works for businesses which have a clear picture of what functions they want and how the app should appear. In terms of the app’s drag and drop interface, the app allows you to test different options until you find one you’re happy with.

    Buildfire’s built-in emulator will also allow you to test how your app looks and behaves on a wide variety of mobile devices. If you want to build your own mobile app without writing a single line of code, Buildfire is an option worth exploring.

    The back-end option: Firebase

    Firebase is Google’s own mobile development platform and can help you power apps that work on iOS, Android and the web. While Firebase eliminates the need for server-side programming and offers robust database and analytics capabilities, you will still need to develop the front-end of your mobile app ( i.e., the part of the app your customer sees).

    For people who don’t know how to code, the Firebase option is less user-friendly than platforms like Buildfire, but its powerful database functionality handles all the heavy lifting on the back-end once your client-side app is developed.https://2689fa48ada9ce5d71c29877b8a8ee73.safeframe.googlesyndication.com/safeframe/1-0-38/html/container.html

    The DIY approach

    If you’re the type of person who likes to get your hands dirty and aren’t intimidated by learning to write code, building your own mobile app from scratch may just be the right challenge for you.

    Though considerably more time-consuming and demanding than using an intuitive solution like Buildfire or hiring a developer, building your mobile app yourself not only offers greater control and flexibility over the final product, but provides a significant learning opportunity. One of the benefits of having built your app from the ground up is that you will be well-positioned to make detailed improvements and customize your app, based on user feedback.

    Writing code is no longer as daunting a prospect as it once was, and there are a wealth of web-based resources and communities of freelance web developers offering step-by-step tutorials on mobile app development.

    The freelance approach

    If you’ve concluded that a mobile app could be a significant boon to your business; if you’re looking for customization in design and functionality beyond what a template-based approach can offer; or if you need to build an app quickly, there are few (if any) substitutes for hiring an experienced developers.https://2689fa48ada9ce5d71c29877b8a8ee73.safeframe.googlesyndication.com/safeframe/1-0-38/html/container.html

    While finding the right developer with appropriate experience and expertise can be a challenge, professional platforms such as CodementorX screen their freelance web developers stringently and even offer a risk-free trial period to ensure the developer is a good fit for your project.

    Final thoughts

    According to Statista, over 52 percent of website traffic took place on mobile devices in 2018. As more and more aspects of our online lives move to mobile devices, developing a mobile app for your business is becoming more of a necessity than a luxury.

  • What FBI Says It Found In Jeffrey Epstein’s Home

    What FBI Says It Found In Jeffrey Epstein’s Home

    What’s inside the $77 million Manhattan mansion owned by Jeffery Epstein, the the billionaire who was arrested in New York on sex trafficking charges? Along with taking Epstein into custody, the FBI raided the mansion and uncovered “an extraordinary volume of photographs of nude and partially-nude young women or girls,” according to court documents. Epstein pleaded not guilty to the charges against him. His opulent mansion was built in 1933 for a member of the family that owns Macy’s.
  • What Is Cybersecurity?

    What Is Cybersecurity?

    With our lives moving increasingly into the digital realm with more and more internet-connected devices, our security needs are evolving. We can think of cybersecurity as “the art of protecting networks, devices and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity and availability of information,” according to the Cybersecurity & Infrastructure Security Agency (CISA), a branch of the Department of Homeland Security. Just as you wouldn’t leave your front door unlocked or your windows open to the street, you need to think about protecting your sensitive data – your finances, personal communications, pictures, medical records, and other sensitive information. This requires paying regular attention to the security of your hardware, software, and passwords, as well as taking other practical steps like shoring up your cloud security and application security. Network security is also paramount, whether it’s a home or office network.

    The consequences of a cybersecurity incident can range from an embarrassing disclosure of private information to devastating financial losses, or even cyber threats that impact your personal security. Any device connected to the internet can be hacked or hijacked, including your car, baby cam, medical devices, and of course computers and smartphones. Hackers can target you for financial gain or to steal personal data for identity theft, but also for revenge or even for political purposes. Malicious actors may seek out businesses for industrial espionage or ransomware, or attack government agencies for political reasons.

    People working remotely may be using personal devices for both business and personal activities, which increases the risk. And security cameras and smart home devices, which are connected to the internet and often controlled with a home security system, can also be hijacked or hacked as a way to get into a home network.

    An attacker can strike in any number of ways: stealing your sensitive information, infiltrating your home network, or compromising your credentials for your accounts like email, medical, and social media.

    An attacker can strike in any number of ways: stealing your sensitive information, infiltrating your home network, or compromising your credentials for your accounts like email, medical, and social media. All of these raise the specter of identity theft. These problems are compounded if someone hijacks an account and uses it to send out malicious messages asking friends for money or tricking them into downloading malicious software.

    You could unknowingly become part of a botnet that allows a hacker to control a network of personal computers that can be used for a broader attack or other criminal activity. The trend of working from home that gained traction during the COVID-19 pandemic has opened up new opportunities for hackers looking for weak points to access corporate networks, according to the consulting firm Deloitte. And by working from your home network or computer, “you might be opening up your computer to the risks your company may be facing,” says Daniel de los Santos, a security researcher with Forescout Technologies. “If there is a ransomware attack on your organization, your files might also be impacted.”

    For individuals, theft of your passwords could allow a malicious actor to impersonate you online or take over your accounts, with the potential for loss of your money or personal data. Malware injected into your personal devices could also give hackers access to your friends and contacts, and send out messages that could trick them into downloading the same viruses or trojans.

    A malicious actor can be motivated by revenge or politics, or they might simply be looking for a way to steal your money. Attackers might also be interested in your health, personal, and social media data, which may include birth dates, billing information, and more, to be used to build profiles for identity theft. Credit card and social security numbers are sold on “dark web” marketplaces where criminals find buyers for data stolen through a data breach, Wi-Fi hacking, insecure browsing, or other means.

    Another risk that can lead to a security breach is ransomware, which encrypts all your data until a ransom is paid. This kind of attack is normally directed at businesses and organizations with the capacity to pay, but individuals can also be victims. Weak security can also open you up to cyberstalking and potential risks to your physical security, especially for women, according to the Marshall University Women’s & Gender Center.

    Some people can feel intimidated by computer security, but a few common-sense tips can help. With these tips, you can help avoid becoming a victim of cyber attacks and increase your network security, application security, and cloud security, all of which will go along way toward protecting your sensitive data from cyber threats.

    Keep your home network and devices up to date

    Start by ensuring you have up-to-date hardware and software for your home network. The most secure Wi-Fi routers have WPA3 (Wi-Fi Protected Access 3), an upgrade from WPA2. This, combined with strong passwords, will help protect against cyber attacks. In addition, your home PC and other devices should have regular security updates and some form of antivirus or security software installed. “If your operating system is out of date, you are essentially vulnerable to attack by hackers who have devised a way to exploit your system,” says John Dickson, vice president for security solution architecture at firm Coalfire.

    All the devices on your home network are connected to the internet and should be password-protected.

    Be aware that all the devices on your home network are connected to the internet and should be password-protected. That includes your home security system, if you have one, and any smart home devices like video doorbells or garage door openers. Don’t rely on the login provided with your equipment. “People think about computers a lot, but now there are so many devices in your house connected to the internet,” de los Santos says. That includes things like your smart TV, thermostat, robotic vacuum, video doorbell, and maybe even a washer or dryer that can be controlled from your smartphone. These devices also might need updates to software or “firmware” that allows them to connect, which could be more complicated than updating your PC or phone.

    Keep work and personal use separate

    The lines are blurred between home and work nowadays, but it’s important to maintain boundaries between your professional and personal data to avoid a compromise in one area that affects the other. (See more tips below for working remotely.)

    Protect your home security system

    If you have a home security system installed, it needs password protection like anything else. For a DIY system, don’t rely on the default password, which can be relatively easy for a hacker to guess. A professional installer can help you create strong passwords and set up two-factor authentication, which sends an alert to a separate device asking your permission to get into an account.

    Lock down your phone

    With the smartphone at the center of our digital lives, it’s important to keep control of your device and protect against the so-called SIM swap attack, which is when someone convinces your cell phone carrier to switch your phone number over to their own SIM card. This could override two-factor authentication if an attacker gains control of your phone where you receive an access code. “This type of hack is very common,” says Ben Sadeghipour, head of hacker education at the ethical hacking startup HackerOne. To help prevent a SIM swap attack, he advises consumers to set up an additional password with their carrier before a change can be made to their account. “Use a password only you know,” he says. “Don’t use your favorite band that you posted on social media.”

    Secure all your accounts

    Your social media and financial accounts should also have two-factor authentication so that even if an attacker guesses your password, a second step is required for access. Some online giants such as Microsoft are pushing for “passwordless” access to critical accounts using an authenticator app. Others such as Google are promoting physical security keys for authentication. Apple uses biometrics such as fingerprint or face identification.

    Also consider using a password manager that can help you set up unique, strong passwords for all of your accounts without having to remember them. It’s strongly recommended that you keep separate passwords for each of your accounts, so that if one is compromised it won’t affect the others. “The uniqueness of the passwords is important,” says de los Santos. This can help avoid compromises based on “credential stuffing,” or the automated use of stolen passwords to gain access to a person’s other accounts.

    Find out what’s already compromised

    It’s possible that one or more of your accounts have already been affected by a hack or data breach. You may or may not get notified about these, but there are ways to check yourself using websites like Google Password CheckupFirefox Monitor, or haveibeenpwned.com. Change passwords for any compromised accounts, and stay up to date on any new data breaches.

    Update, update, update

    Operating system updates are important for your computer or phone, as they often patch security holes discovered by researchers. But other software needs to be updated as well, including your web browsers, mobile apps, and especially any antivirus software you may be using. “Hackers are always trying to stay one step ahead by exploiting bugs in software, while antivirus companies are always updating their software to catch these new exploits,” says Dickson. “It’s a cat and mouse game. If your antivirus software is out of date, you are essentially unprotected.”

    Be vigilant

    Many successful cyber attacks can be carried out even if the victims have strong cybersecurity, by tricking people into giving up their credentials or other key information. For example, the Federal Trade Commission notes that hackers can send “phishing” emails that ask for personal information and appear to come from legitimate companies like your bank or colleagues. Some phishing attempts can be identified in email spam filters, but experts say it’s important to verify the origin of the sender and any website asking for login credentials or other personal data. Most legitimate companies will not send links asking you to click through to verify your sensitive information so as not to compromise your information security.

    Attackers can be wily about using “social engineering” to dupe people into giving up their credentials. “What motivates people is greed and fear,” de los Santos says. “You need to be careful if there’s a message that says you won a million dollars or that your password has been stolen.”

    Use a VPN for any work-related activity on your home network, which provides an extra layer of protection and separation.

    Use a VPN for any work-related activity on your home network, which provides an extra layer of protection and separation. De los Santos advises people to keep separate devices if possible for work and personal use. “As soon as you start mixing things, it becomes harder,” he says. Malicious actors know more people are working from home and are taking advantage of potential weaknesses in home networks. “It’s a lot easier to break into a residential home than an office,” Sadeghipour says.

    Information security firms have seen more cyber attacks seeking to exploit remote workers during the pandemic. For example, a report from the online security firm Malwarebytes found an increase in malicious spam posing as information regarding Zoom, Microsoft Teams, Slack, and other business applications.

    Some people forget that their router – the hub for your home network – has a password as well, which should be strong and “unique,” or not shared by other accounts. Even if your other devices are secure the router may give access to a malicious actor. Don’t rely on the password in the device out of the box, which might be something easy to guess like Admin123. “People from outside can see your router, and that’s where the password configuration comes into play,” de los Santos says.

    Identity theft is one of the most dreaded consequences of weak cybersecurity or information security, with the potential for huge ramifications including monetary losses and damage to one’s credit rating. A cyberthief can set up accounts in your name, misuse your social security number, file bogus unemployment claims or tax returns or commit other crimes which could lead authorities to your door. Some victims may be unaware that their data has been stolen until damage has been done.

    “Sometimes the smallest piece of information can be used against you,” says Sadeghipour. “It can be your phone number, your address. These are things a bank or credit card company will use to verify your identity.

    Bad actors can use data obtained by hacking, but they might also combine this with information you post publicly on social media and from public records. Medical records, credit reports, employment data and more can also be used for identity theft. In many cases, this data can be bought and sold on the dark web by cybercriminals.

    Victims can spend months or years dealing with the financial, emotional, and reputational toll of identity theft. Good cybersecurity practices can help limit the risks of identity theft but it also helps to be cautious about the personal information you share. The Federal Trade Commission offers guidance on both prevention and mitigation of identity theft. Commercial services can offer protection and help in remediating identity theft.

  • Professionals must be aware of these top ten cybersecurity terms with meanings

    Professionals must be aware of these top ten cybersecurity terms with meanings

    The term cybersecurity is dominating the world with the increase in dangerous and risky cyberattacks across the world. Cyberattacks are stealing personal and sensitive information of a business or clients through different processes. All companies across the world are at high risk of having real-time data compromised as well as manipulated. 

    TOP TEN CYBERSECURITY TERMS

    There are some important cybersecurity meanings as well as terms of cybersecurity that all human employees must be aware of in Industry 4.0. Let’s explore some of the top ten cybersecurity terms as well as the meanings of cybersecurity terms.

    VPN

    VPN or Virtual Private Network is one of the top cybersecurity terms that encrypts internet traffic on unsecured networks for protecting the online identity. It extends a private network across a public network to send and receive real-time data across different connections.

    Exploit

    An exploit is a term in cybersecurity meaning a code to reap the benefits of a software weakness or flaw in the security of any application or system. Cybercriminals use exploits to remotely access a network and deeper into the network. It is known as a piece of software or a sequence of commands that cause unintended behaviour. There is a zero-day exploit as an advanced cyberattack defined.

    White Hat/Black Hat

    The meanings of cybersecurity terms such as a white hat and black hat are the ways to find and fix or create multiple security problems in a system. There are two types of hackers— white hat hackers and black hat hackers. White hat hackers are a type of ethical hackers who want to find and solve certain cybersecurity issues whereas black hat hackers are ready to exploit weaknesses to gain or take revenge.

    Malware

    One of the terms of cybersecurity is malware that organizations need to be aware of in 2022. Malware is an umbrella brand of several cyberattacks such as Trojans, viruses, etc. that infect systems to gain confidential data. It is a short form for malicious software and is designed to be invasive as well as harmful for the entire computer system.

    Ransomware

    Ransomware is a type of malware that helps cyber criminals to employ encryption and demand a ransom from an organization. Employees cannot access any file or folder or database without paying the ransom as per the instructions provided.

    Worm

    There is a worm in a computer system related to cybersecurity. This cybersecurity term shows that the malware spreads its copies from one computer to another efficiently. It can be transmitted through multiple software vulnerabilities with the help of spam, instant messages, malicious websites, and many more. It can delete, modify, and inject additional malicious software into files or folders without any human interaction.

    Botnet

    The meaning of this cybersecurity term Botnet is a robot network or a network of computers getting infected by malware with a single attacking party. Cybercriminals use botnets to spread bots for trapping more computers to the large net. It is used to perform DDoS attacks with command and control software.

    Rootkit

    Roolkit is another popular term of cybersecurity designed to provide hackers full access to a target device along with controlling power. It is known as a clandestine computer programme that can actively hide its presence in a system. Professionals may not even notice that the software is in a particular area of a system.

    Phishing

    The cybersecurity meaning of Phishing is to send a fraudulent message to a potential victim as a trick to reveal sensitive data to cybercriminals. It appears to come from a reliable and safe source but it is not. The aim of Phishing is to steal confidential data or to install risky malware to the computer system.

    DDoS

    The full form of this cybersecurity term is distributed denial of service. Cybersecurity meaning is that cybercriminals employ to make an online service to disturb the normal traffic to a web property. It can compromise the computer systems and cause a denial of service to victims.