Showing posts with label attacks. Show all posts
Showing posts with label attacks. Show all posts

Tuesday, January 26, 2021

How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder

 

Ransomware attacks have reached the boiling point. They’ve gone from nuisance to significant financial burden—as well as a mortal threat to critical infrastructure. Financial damage from ransomware attacks is in the hundreds of millions of dollars for some organizations. And, of course, our F5 Labs threat researchers have something to say about it. So, let’s start the clock to explore How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder. 

Full article: https://www.f5.com/labs/articles/threat-intelligence/ransomware-how-it-has-evolved-to-be-faster-stealthier-and-strike-harder

Tuesday, September 10, 2019

90 Seconds of Security: F5 SIRT's Top Threat for Summer 2019

Find out what threats topped F5 Security Incident Response Team's (SIRT) emergency response list for Summer 2019. F5 SIRT sees all sorts of attacks against F5 devices and the services they protect. 

For more information about this specialized service visit: https://www.f5.com/sirt


Tuesday, January 21, 2014

The Icebox Cometh

Will the Internet of Things turn homes into a House of Cards?

Our homes are being invaded...but not with critters that you'd call an exterminator for.  Last summer I wrote Hackable Homes about the potential risks of smart homes, smart cars and vulnerabilities of just about any-'thing' connected to the internet.  (I know, everyone loves a bragger)  Many of the many 2014 predictions included the internet of things as a breakthrough technology? (trend?) for the coming year.  Just a couple weeks ago, famed security expert Bruce Schneier wrote about how the IoT (yes, it already has it's own 3 letter acronym) is wildly insecure and often unpatchable in this Wired article.  And Google just bought Nest Labs, a home automation company that builds sensor-driven, WiFi enabled thermostats and smoke detectors. 

So when will the first refrigerator botnet launch?  It already has.

Last week, Internet security firm Proofpoint said the bad guys have already hijacked up to 100,000 devices in the Internet of Things and used them to launch malware attacks.  The first cyber attack using the Internet of Things, particularly home appliance botnets.  This attack included everything from routers to smart televisions to at least one refrigerator.  Yes, The Icebox!  As criminals have now uncovered, the IoT might be a whole lot easier to infiltrate than typical PCs, laptops or tablets.

During the attack, there were a series of malicious emails sent in 100,000 lots about 3 times a day from December 23 through January 6.  they found that over 25% of the volume was sent by things that were not conventional laptops, desktops or mobile devices.  Instead, the emails were sent by everyday consumer gadgets such as compromised home-networking routers, connected multi-media centers, televisions and that one refrigerator.  These devices were openly available primarily due to the fact that they still had default passwords in place.

If people don't update their home router passwords or even update the software, how are they going to do it for the 50+ (give or take) appliances they have in their home?  Heck, some people have difficulty setting the auto-brew start time for the coffee pot, can you imagine the conversations in the future?  'What's the toaster's password?  I need to change the bagel setting!'  Or  'Oh no!  Overnight a hacker replaced my fine Kona blend with some decaf tea!'  Come on. Play along!  I know you got one you just want to blurt out!

I understand this is where our society/technology/lives are going and I really like the ability to see home security cameras over the internet but part of me feels, is it really necessary to have my fridge, toaster, blender and toilet connected to the internet?  Maybe the fridge alerts you when something buried in back is molding.  I partially get the thermostats and smart energy things but I can currently program my thermostat for temperature adjustments without an internet connection.  I push a few buttons and done. Plus I don't have to worry about someone firing up my furnace in the middle of July. 

We have multiple locks on our doors, alarm systems for our dwellings, security cameras for our perimeter, dogs under the roof and weapons ready yet none of that will matter if the digital locks for our 'things' are made of dumpling dough.  Speaking of dumplings, the smart-steamer just texted me with a link to see the live feed of the dim sum cooking - from inside the pot! 

My mind just texted my tummy to get ready.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, August 20, 2013

DNS Doldrums

DNS is one of the primary technologies enabling the Internet – translating the names people type into a browser into an IP address so the requested service can be found on the internet. It is one of the key elements in the network that delivers content and applications to the user.  If DNS goes down, most web applications will fail to function properly so it is critical to have a strong, secure and scalable DNS infrastructure.

A bunch of recent DNS outages show that while protecting the application from the typical SQLi, XSS and other OWASP Top 10 related risks is important, if DNS is not answering, those application hacks do not really matter since no one can get to the site anyway.

This month, 3 Dutch web hosting companies had their name servers altered by attackers.  They, according to articles, changed the various company's name servers to malicious servers hosted by the crooks.  They apparently managed to break into the national domain registrar, SIDN, to make the malicious change along with setting the Time to Live value to 24 hours.  This meant that any ISP that cached the bad information would continue to deliver the wrong address for the next day.  Among others, a large Dutch electronic retailer had to take down a bunch of servers that were delivering malware due to the breach but thousands of domains were affected.

This past June, the popular business social network LinkedIn was offline for at least a half a day due to a DNS issue.  The company claims that this was not due to criminal behavior but internal human error.  Somehow the main home page was redirected to a domain parking page which indicated the name was up for sale.

Also in June, DNSimple detected a DNS Amplification Attack on their network.  This is where an attacker attempts to use additional servers to 'amplify' the attack - small queries that turn into huge responses.  Instead of allowing the bounce, DNSimple tried to absorb the attack by blocking some IP addresses but ultimately at some point, all the name servers were no longer responding.  All hands to respond.  In their incident report, they noted that their current DNS server implementation allowed ANY queries on UDP to pass through and attempted to respond to them, albeit with the TC (truncation) bit set. In addition, the overhead created by their ALIAS resolution system was also a factor, especially with ALIAS records pointing to other records within DNSimple.  With some adjustments they hope to mitigate this from happening again.

There were a few others of note, In June, Network Solutions had its DNS servers hijacked and reconfigured to a malicious website after it botched efforts to thwart a DDoS attack.  The Spamhaus Project was nailed by a DNS DDoS attack.  And last week, a reported vulnerability in the BIND DNS software could give an attacker the ability to easily and reliably control queried name servers.

We rely on DNS for almost every interaction we have with web applications.  It helps us find our favorite e-tailer, social network, travel, news, gaming or entertainment site along with potentially finding our work related resources when we are mobile.  For organizations, it helps direct and bring people to your content.  Without it, our letter managed mind would have to start remembering a bunch of numbers.  Imagine how much you'd use the internet if you had to remember dozens of number combinations to do anything.  I bet the growth, the internet of everything, would come to a screeching halt.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 11, 2013

Small Business is a Big Target

If you think that small businesses are not an enticing enough target to breach, think again.  While the media has certainly upped it's coverage over the last couple years pertaining to data loss, many of the headlines involved global brands and tens of thousands records...not the corner deli, the mom/pop shop or the new start up.  Yet a couple of recent reports show that small businesses and start-ups are prime targets for data loss.

The annual, chuck full of stats, Verizon Data Breach Report noted that of the 621 confirmed data breaches, almost half happened at companies with less than 1000 employees and almost 200 at companies with less than 100 employees.  A Symantec report echoed the finding.  In theirs, small businesses with less than 250 employees accounted for 31% of the attacks in 2012, up 18% from 2011.  Symantec also notes that start-ups are especially vulnerable in the early going.

Why are these groups targets?

They have valuable data - intellectual property, financial information, digital identities - but may not have the resources to properly protect that data.  Many large, global companies have beefed up their security in fear of becoming the next headline in a major newspaper.  Thieves usually go after the easiest target - those with limited resources to protect against such an attack.  Thieves may also infiltrate a smaller organization to jump on a global network if a partnership is in place. Take out the villages before entering the capital.  In a start-up's situation, as they quickly launch, employees may be enticed to click a malicious link in an email...which then spreads.  Most startups get infected with malware within the first year.

From marketing organizations to cleaning products to credit repair services, here are some stories of how cyber attacks almost destroyed 5 small businesses.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, April 24, 2013

Targets of Opportunity

#dbir

...Is one of the findings in #Verizon's 2013 Data Breach Investigations Report, which is chuck full of interesting data.  75% of the attack victims were selected because they had a weakness that an attacker knew how to exploit rather than being specifically chosen.  The difficulty of the initial compromise was low for 68% of the breaches meaning the attackers used basic methods or automated tools and scripts.  It also means that there are sloppy configurations, needless services and exposed vulnerabilities that are bringing this attention.

Overall, the report covers 47,000 reported security incidents, of which, there were 621 confirmed data breaches.  This is important since they focus on the 621 confirmed data loss incidents rather than the 47,000 reports.  There will probably be a ton of articles reporting the results but a good place to start is securosis.com with their How to Use the 2013 Verizon Data Breach Investigations Report.  This is a great primer for the document.

There is a pretty even distribution of industries hit from financial to retail and restaurants to manufacturing, transportation and utilities to government and defense contractors.  The overwhelming majority of attacks are perpetrated by outsiders at 92% of the confirmed data breaches with insiders at 14%.  Interestingly, for all reports (the 47,000 not just the 621 confirmed) insiders accounted for 69% of the incidents.  Typically this was due to carelessness rather than criminal misuse.  76% of the network intrusions exploited weak or stolen credentials and most often, the attack was driven by financial motives at 75%.

Some other interesting data for me was that 66% of the breaches remained undiscovered for months or more and 69% of those were discovered by outside entities.  So organizations are in the dark about their intrusions, and it takes an outsider to point it out.  It's like those people who drive away with the gas hose still hooked to their tank. 

I was also curious about breaches as a result of BYOD.  Not many.  In 2011 they only saw 1 breach that involved personally owned devices and only a couple more in 2012.  They will keep watching and do expect that it may increase but for now, so far so good.  Could be because while BYOD is a hot topic, most surveys indicate that only around half the organizations are digging in.

There is a ton more valuable data in the report and it is an easy, fun read for 63 pages of stats.  Right on page 2 they say, 'Some organizations will be a target regardless of what they do, but most become a target because of what they do.  If your organization is indeed a target of choice, understand as much as you can about what your opponent is likely to do and how far they are willing to go.'  Put it on your list.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, October 13, 2011

Our Identity Crisis

As as kid, my mom would constantly remind me that I was a Hawaiian Prince – a direct descendant of King Kamehameha’s grandparents and the Kekaulike (23rd Moi of Maui) line.  I was born in Hawaii but grew up on the East Coast so as a kid, I was embarrassed to be of Hawaiian Royalty since it was different from the typical ethnic groups of the New England states but that was/is Who I Am.  Of course as I got older I like being 254th in line to the Hawaiian throne…if it was still a sovereign kingdom.  Your identity is what makes you, You.  It is made up of things like, Your Family, Your history, What you say, What you know, Where you are, What you share, Who you know, Your preferences, Your choices, Your reputation, Your profession, Your biggest fears, Your greatest love and all the nuances that make each of us an individual. This information is available on the web, in profiles, contacts, email, data, documents, music, images, blogs, favorites…. Networks… you name it.  Some may confuse ‘image’ or ‘persona’ with identity.  Many celebrities have images to keep, or present a persona that they want their audience to latch to but many times, it is not their true identity and who they really are at their core. There are also certain pieces of our identity we’d also like to keep secret.  That’s the same information that the crooks want.

As we approach the holidays, this is an especially critical time to keep an eye on our information and those devices that contain our information, like our mobile devices.  You may have seen the recent commercials about making payments over your smartphone – the one where everyone pulls out their phones after dinner to pay their share and the guy with cash looks like the fool.  Huh?  I got real, crisp, green money in my hand, right from the ATM and nobody wants it.  The mobile payment infrastructure is still in the early stages but you can imagine the schemes already being hatched by those who would love to intercept those transactions. 

And speaking of crooks, did you see that 111 arrested in massive ID theft bust in New York?  Prosecutors are calling it the largest ID theft fraud case in US history.  For two years, law enforcement dug in for ‘Operation Swiper,’ which targeted a very sophisticated ID theft ring who recruited and paid restaurant workers, retail cashiers and even bank tellers to steal credit card numbers and quickly convert that data into cash.  They had everything – computers, skimmers, card readers, embossers, credit card blanks and shopping crews who went coast-to-coast buying high end merchandise while staying in 5-star hotels.  They made off with over $13 Million in less than a year and a half.

On a separate but positive note, a new Federal law was passed to protect foster children from identity theft.  This new law requires states to run credit checks on older foster children and work to resolve ID theft cases so when the child reaches adulthood, they have a clean slate.  Foster children are prime targets for and face greater risks of ID theft since their information passes through so many hands and agencies.  Most states also still use the foster child’s SSN to identify them, adding to the risk.  Many foster children enter adulthood with massive debt due to someone else leaving them with bad credit.  This law is intended to both protect against that and help those who have been victims.

And lastly, next week is the 4th annual National Protect Your Identity Week (PYIW).  Multiple Better Business Bureaus are joining several government agencies and other national advocacy organizations to offer educational workshops, free document shredding and computer recycling.  Javelin Strategy and Research noted that in 2010, 8.1 million adults were victims of identity theft resulting in the loss of $37 billion.  Plus, according to AllClear ID, children are 51 times more likely to have their identity stolen.

So as the year end festivities start heating up, don’t forget to keep an eye on you along with protecting and embracing your identity.

ps

Related:

Technorati Tags: F5, PCI DSS, virtualization, cloud computing, Pete Silva, security, cloud, credit card, compliance, web, internet, cybercrime, holiday shopping, identity theft,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, July 12, 2011

Protection from Latest Network and Application Attacks

We offer a lot of webinars at F5 and this is one I recently presented to some partners. As I’ve mentioned, security attacks are moving “up the stack."  90% of security investments are focused on network security, however, 75% of the attacks are focused at the application layer.  Plus the average loss of revenue per hour for a layer 7 DDoS attack is approximately $220,000.  Modern DoS attacks are distributed, diverse and cross the chasm that divides network components from application infrastructure. A unified application delivery platform with multi-layer visibility is the best way to detect and mitigate multi-layer attacks.  This webinar covers how to prevent sophisticated web attacks utilizing your BIG-IP system and the BIG-IP Application Security Manager.  Running time: 53:52

In this webinar, we will discuss:

  • Examples of current attacks and the effects on those companies
  • The human element
  • How to protect from latest web threats
  • How to quickly resolve vulnerabilities
  • PCI compliance

ps

Resources:

Technorati Tags: F5, webinar, Pete Silva, security, business, education, technology, internet, big-ip

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, February 8, 2011

Identity Theft: Good News-Bad News Edition

So which would you like first? 

Javelin Strategy & Research said identity theft incidents were down 28% in 2010 (vs. 2009) according to their latest consumer survey.  This is the lowest level since 2007 and about 3 million less victims than in 2009.  They partially attribute this to a decline in industry reported data breaches going from 604 (221 million exposed records) to 404 (26 million exposed records) in 2010 along with economic conditions, better security measures and busts by law enforcement playing a major role.  If you have an existing credit card account, there’s good news on that front also – fraud from existing credit cards was down 38% ($14 billion) compared to 2009 ($23 billion).  New account fraud, where the victim might not have any idea than an account was opened in their name, took top honors in types of fraud with $17 billion siphoned.  ‘Change in physical address’ was the No. 1 method of account takeover reported by victims.

Don’t drop the confetti yet, however.  While the overall numbers look encouraging, the devil is in the details as the cliché goes.  Even thought the overall numbers are down, the consumer out-of-pocket expense to resolve ID fraud went from $387 per incident to $631 in 2010 – a 63% increase.  Because criminals are using more clever ways to steal you data, you have to spend more time fixing the issue and the costs can grew.  Your friends and family are also sticking it to ya. ‘Friendly Fraud,’ when someone you know steals your info, increased 7% with 41% of this batch saying their SSN was stolen.

They also found a correlation between retail sales and identity fraud.  When sales are up, fraud is down and when sales are down, fraud goes up, says James Van Dyke, founder of Javelin Strategy & Research.  He feels that when the economy is doing well and people can make purchases with their own money, they are less likely to steal.  Add to that, better security measures are in place and people are more aware of identify fraud, thus they keep a better eye on questionable transactions.  Another bad sign is that while credit card fraud has dropped, debit card fraud went from 26% to 36% in a year.  This could be due to more people using debit cards rather than credit for purchases but also due to debit’s lower level of protection when it comes to fraud. Some would question the validity of the survey since it is a ‘self-report’ telephone survey and bank data would argue that fraud is actually up in many areas.  There are many more intriguing tidbits in the report and you can check out Javelin’s report with a couple interesting charts here.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach

Wednesday, December 15, 2010

2010 Year End Security Wrap

Figured I’d write this now since many of you will be celebrating the holidays over the next couple weeks and who really wants to read a blog when you’re reveling with family and friends.  It’s been an interesting year for information security, and for me too.  I started the year with New Decade, Same Threats? and wondered if the 2010 predictions of: social media threats, smarter malware/botnets, using the cloud for crime, financial DDoS, rogue software, Mac and Mobile malware, more breaches and a whole host of others would come through.  And boy did they. 

Social media was a prime target for crooks with the top sites as top targets.  Users were tricked to accepting and sharing friends that really weren’t friendly and social networks became a new hotbed for malware distribution.  As for malware, while many botnets and spam outfits got taken down this year, Stuxnet was certainly the most sophisticated piece of malware researches have seen in a while.  Targeting industrial & utility systems along with the ability to reprogram itself, no longer was it my single laptop or a company’s system that had a bull's-eye, although the initial infection is with those systems, it was nuclear facilities, oil refineries and chemical plants that were the ultimate objective. For Cloud Computing, was it Cloud 9 or Cloud Crime when it came to using the cloud for nefarious activities?  Many people thought that with the cloud offering a slew of computing power, that it would be a prime way to initiate an attack.  We really didn’t see much pertaining to ‘cloud breaches’ even though almost every survey throughout the year indicated that security in the cloud was everyone’s ichiban concern.  I covered many of these surveys in my CloudFucius Series, now playing in a browser near you.  This article talks about that, the reason we might not have seen much in the way of cloud specific breaches is that many of the data loss repositories do not differentiate between a cloud based and non-cloud attack.  In addition, cloud providers are not that willing to spill vulnerabilities that have led to crimes.  Share please. 

Banks and financial institutions were certainly targets this year, why wouldn’t they be, that’s where all the money is.  In one incident, about $3 million was stolen from various banks around the world using viruses and more than 100 crooks suspected of running the global cybercrime ring were arrested in the US and UK this September.  A 16 year old Dutch kid was arrested last week for a Distributed Denial of Service attack on the MasterCard and Visa websites.  And, merging malware, mobile and money stores, the ZeuS Trojan could infect a desktop, capture the user’s bank credentials next time they logged in to their financial institution, popped a dialogue box for the user to ‘include’ their mobile phone for SMS payments, send the phone a fake message & certificate for acceptance and then installed another Trojan on the phone to monitor messages via SMS.  Lots of trickery and luck to be successful but still a very scary exploit.  And if you think those mobile banking apps are secure, think again.  Just last month, a number of those apps were found to have serious vulnerabilities, flaws and holes.  Many of those apps have been patched in light of the research but as with any ‘new-ish’ type technology, mobile banking must be locked down before the masses adopt.  Too late now.

I wrote about corporate espionage both in Today’s Target: Corporate Secrets (2010) and The Threat Behind the Firewall (2009) and this year did not disappoint.  Social engineering or convincing someone to give up their info is alive and well but throughout 2010, employees stole secrets from the companies they worked for: Former Goldman Programmer Found Guilty of Code Theft, Greenback engineers guilty of corporate espionage, Ford secrets thief caught red handed with stolen blueprints, and SEC Bares Text of Inept Suspects As They Sold Disney Earnings Info To FBI AgentsThese insider events can often be more costly than an external breach.

This is by no means an exhaustive list of the breaches, attacks, vulnerabilities, hijacks, frauds, or other cybercriminal activities from 2010.  I’d probably be writing through the holidays to get them all.  These were just some of the things I found interesting when looking back at my initial blog entry for the year.  With 2011 being the Year of the Rabbit, just how much will cybercrimes multiply?

ps

Resources:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1]  o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, infrastructure 2.0, integration, cloud connect, Pete Silva, security, business, education, technology, application delivery, intercloud, cloud, context-aware, infrastructure 2.0, automation, web, internet, cybercrime, security, holiday shopping, identity theft, scam, email, data breach