Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Tuesday, June 29, 2021

Cyberattacks at Banks and Financial Services Organizations

As part of the 2021 Application Protection Report, we looked at the top reported security incidents to the #F5 SIRT for the years 2018 through 2020. Now we’re taking a deeper dive into the reported security incidents at financial organizations, sometimes referred to as #BFSI for banking, financial services, and insurance institutions. Peter Silva starts the clock for Cyberattacks at Banks and Financial Services Organizations. Read the Report!


DDoS Attack Trends for 2020

Distributed Denial-of-service, or #DDoS, is a persistent threat facing businesses of all types, regardless of geographic location or target market. DDoS tools are becoming easier to use, while the attacks themselves are becoming more complex—frequently combining many different methods in one assault. With attack data from the F5 Silverline Security Operations Center and incidents logged by the F5 Security Incident Response Team (SIRT), I start the clock to check out DDoS Attack Trends for #2020 and read the article.


2021 Application Protection Report: Of Ransom and Redemption

 Now in its 4th year, the #F5Labs 2021 Application Protection Report (https://www.f5.com/labs/articles/thre...) is our effort to boil the application security risk landscape down to put the initiative back into the hands of defenders. We analyzed more than 700 data breaches from 2020. Peter Silva starts the clock for an extended edition of some the highlights from F5Labs 2021 #APR in this episode of 90 Seconds of Security.

Get your copy of the 2021 APR


Credential Stuffing Tools and Techniques

Credential stuffing is a type of cyberattack that uses credentials obtained from previous breaches to take over accounts on other web or mobile applications. This type of brute force attack relies on the fact that many people use the same usernames and passwords on multiple sites. See how attackers use #OpenBullet​ to create a Credential Stuffing attack. Let's start the clock for #CredentialStuffing Tools and Techniques including #OpenBullet in this 90 Seconds of Security episode. And learn more at F5Labs.com


F5 SIRT’s Top Reported Security Incidents, 2018-2020

The F5 Security Incident Response Team helps customers tackle security incidents in real time. In 2020, we talked about what happened in the beginning of the pandemic based on #F5 #SIRT cases. Now we're looking back at all F5 SIRT cases from the beginning of 2018 to the end of 2020 and break down what changed and what didn’t in the cyberthreat landscape because of the pandemic. So, let’s start the clock to look at SIRT’s Top Reported Security Incidents, 2018-2020. Go to the full article


Thursday, March 4, 2021

Credential Stuffing: Why It’s Here to Stay

Over the last few years, #F5 security researchers have identified credential stuffing as one of today’s foremost threats. The value of stolen credentials has created a vicious circle: organizations suffer network intrusions in pursuit of credentials, and credential stuffing in pursuit of profits. Understanding both the supply and demand sides of the market for stolen credentials is, therefore, key to understanding the risk that cybercriminals pose to organizations today. With 5 years of data, it is definitive: credential spills are here to stay. So, let’s start the clock for some harrowing data from the 2021 Credential Stuffing Report.

Get your copy: https://www.f5.com/labs/articles/threat-intelligence/2021-credential-stuffing-report


Tuesday, January 26, 2021

How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder

 

Ransomware attacks have reached the boiling point. They’ve gone from nuisance to significant financial burden—as well as a mortal threat to critical infrastructure. Financial damage from ransomware attacks is in the hundreds of millions of dollars for some organizations. And, of course, our F5 Labs threat researchers have something to say about it. So, let’s start the clock to explore How Ransomware Has Evolved to Be Faster, Stealthier, and Strike Harder. 

Full article: https://www.f5.com/labs/articles/threat-intelligence/ransomware-how-it-has-evolved-to-be-faster-stealthier-and-strike-harder

Saturday, December 14, 2019

90 Seconds of Security: Phishing Trends for 2019

Phishing has become the number one attack vector for good reason - it requires a low amount of effort for a very high reward. 

F5 Labs (f5labs.com) released their 2019 Phishing and Fraud Report showing that there's no slowing down in the amount or number of phishing attacks. In fact, we expect phishing to occur year-round, not just around the holidays. Download the full report at: https://www.f5.com/labs/articles/threat-intelligence/2019-phishing-and-fraud-report


90 Seconds of Security: Breach Trends for 2019

F5 Labs Threat Intelligence team (f5labs.com) recently published their 2nd annual Application Protection Report and we take a look at some of the highlights. We cover PHP vulnerabilities, Formjacking, magecart attacks, and the relationship between breach causes and industry sectors. Get your copy at F5Labs.com

 

Tuesday, October 29, 2019

90 Seconds of Security: Malware Primer

My latest 90 Seconds covers the different types of malware, how infections happen and what to do if you get infected. Slightly extended edition courtesy of F5's Security Incident Response Team. https://f5.com/sirt




ps

Thursday, September 26, 2019

90 Seconds of Security: F5 SIRTs Top Tip for Keeping Your BIG-IP and Your Network Secure

Learn why locking down the Management Port is F5 SIRT’s Top Tip for keeping your BIG-IP and your network secure from intruders. From their SecOpsCave deep within F5 headquarters, the F5 SIRT (f5.com/sirt) monitors all kinds of attacks and shares the bad things that can happen, like a DDoS attack, if BIG-IP is not secure.

For more information about SIRT’s specialized service please visit: https://www.f5.com/sirt


Friday, August 16, 2019

Bot Management with F5'S Advanced WAF

Automated attacks are a huge threat to organizations. Half of internet traffic are bots and 30% of those are sending malicious payloads. Learn how F5's Adv. WAF helps protect your applications from automated attacks, optimizes your business intelligence and improves performance, availability, and infrastructure costs. Visit f5.com/bots to learn more.


Wednesday, May 29, 2019

90 Seconds of Security: In the Wild Malware for April 2019

A 90 second recap of 'In the Wild' Vulnerabilities, Exploits, and Malware Driving Attack Campaigns in April 2019.

Get the details at: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities--exploits--and-malware-driving-attack-campaigns-in-april-2019




ps

Tuesday, March 26, 2019

How Malware Evades Detection

Malware loves encryption since it can sneak around undetected. F5Labs 2018 Phishing & Fraud Report explains how malware tricks users and evades detection. 

Let's light up how evasion happens & get your F5 Labs 2018 Phishing & Fraud Report today.

Thursday, January 3, 2019

SSL Visibility with SSL Orchestrator

Are You Equipped to Decrypt?

Over 80% of page loads are encrypted with SSL/TLS and Attackers commonly use encryption to hide malicious payloads. If you’re not inspecting SSL/TLS traffic, you will miss attacks, and leave your organization vulnerable. I light up how SSL Orchestrator provides robust decryption/encryption of SSL/TLS traffic.



ps

Thursday, December 13, 2018

F5 Labs 2018 Phishing & Fraud Report

The F5 Labs 2018 Phishing & Fraud Report is out!

In this report, the F5 Labs team specifically investigated the rise of phishing and fraud during the 'holiday shopping season,' beginning in October and continuing through January. Fraud and phishing attempts increase 50% right now, from October to January and phishing was the root cause of 48% of the data breaches that F5Labs investigated. It's important to check out the report because it explains how phishing works, how to defend yourself against phishing attacks and the importance of training employees to recognize malicious emails.

Some of the crazy stats they found include 93% of phishing domains offered a secure (https) version of the site to appear more legitimate and 68% of malware sites used encryption certificates (https), meaning 68% of Command & Control servers use port 443. The crooks are going through the trouble of getting SSL certificates for their fake, but real looking sites.


Take a look at some of these. Do any of these web logins look familiar?


How about this one?

Or maybe this one?


If so then you need to check out the 2018 Phishing and Fraud report from F5 Labs because they were all fake. Attackers are getting so good at creating fake websites that impersonate the real thing, most people can’t tell the difference. One thing is for certain, employee click-through rates on phishing emails drop from 33% to 13% with security awareness training:
  • 33% — 1-5 training events
  • 28% — 6-10 training events
  • 13% — 11 or more training events
You can check out the Preview Video here and get your report at https://www.f5.com/labs


ps




Wednesday, November 1, 2017

Lightboard Lessons: What is DDoS?

Over the last quarter, there were approximately 500 DDoS attacks daily around the world with some lasting as long as 300 hours. In this Lightboard Lesson I light up some #basics about DoS and DDoS attacks.



ps

Related:

Wednesday, October 18, 2017

Wednesday, August 30, 2017

Is 2017 Half Empty or Half Full?

Ransomware seems to be this year’s huge trend

With 2017 crossing the half way point, let's look at some technology trends thus far.
Breaches: Many personal records are half empty due to the continued rash of intrusions while the crooks are half full of our personal information along with some ransom payments. According to the Identity Theft Resource Center (ITRC), there have been 7,689 breaches since 2005 (when they started tracking) compromising – get this – 900,315,392 records. Almost 3 times the U.S. population. In 2016, 56% of all Data Breaches began with a user clicking on a phishing email. The big story for 2017 I think, is the rise of ransomware. Kaspersky reports a 250% increase in ransomware for the first few months of 2017. From WannaCry to Petya to Fusob, criminals are holding systems hostage until a ransom is paid…or not. Ransomware seems to be this year’s big trend with backups saving some from total embarrassment.

Cloud Computing: RightScale 2017 State of the Cloud Report notes that Hybrid Cloud Is the preferred enterprise strategy, with 85 percent of enterprises have a multi-cloud strategy (up from 82 percent in 2016) and Cloud Users Are Running Applications in Multiple Clouds. An interesting stat from the report says, cloud users are running applications in an average of 1.8 public clouds and 2.3 private clouds. We got hybrid cars, hybrid corn, hybrid cats and hybrid clouds but The Cloud is Still just a Datacenter Somewhere so no need to freak out. Cloud seems to be more than half full as the security and expertise challenges decline.

DNS: I’ve said it before and I’ll say it again, DNS is one of the most important components of a functioning internet. With that, it presents unique challenges to organizations. 2016 saw record-breaking DNS-based attacks and outages, which thrust DNS management into the spotlight as both a vulnerability and a critical asset. In 2016 DNS provider Dyn experienced a huge DDoS attack taking out many popular websites and internet cameras. And a new attack uncovered this year, DNSMessenger, uses DNS queries to conduct malicious PowerShell commands on compromised computers – a technique that makes the remote access trojan difficult to detect on targeted systems. The need for DNS continues to be half-full with the influx of IoT devices so it’ll continue to be a valuable target for riff-raff.

IoT: What can I say? The cup runneth over…again. Gartner has identified the Top 10 IoT technologies that should be on every organization's radar for 2017 and 2018. They include things like new security risks and challenges to the IoT devices themselves, their platforms and operating systems, their communications, and even the systems to which they're connected. Analytics to understand customer behavior, to deliver services and improve products. Device management, device processors, operating systems, platforms, standards and even the networks IoT devices use are all areas of attention. IoT is really three-quarters full both with the opportunities and potential risks. And the risks can be deadly when monitoring vital information like human vital signs.

Mobile: We are mobile, our devices are mobile and the applications we access are mobile. Mobility, in all its iterations, is a huge enabler and concern for enterprises and it'll only get worse as we start wearing our connected clothing to the office. 5G is still a couple years away but AT&T and Verizon have already lined up trials of their 5G networks for 2017. Mobile is certainly half full and there is no emptying it now.

That's what I got so far and I'm sure 2017's second half will bring more amazement, questions and wonders. We'll do our year-end reviews and predictions for 2018 as we all lament, where did the Year of the Rooster go?

There's that old notion that if you see a glass half full, you're an optimist and if you see it half empty you are a pessimist. I think you need to understand what state the glass itself was before the question. Was it empty and filled half way or was it full and poured out? There's your answer!

ps


This article originally appeared on F5.com.

Tuesday, September 27, 2016

Lock Down Your Login

Last week we talked about WebSafe and how it can help protect against phishing attacks with a little piece of code. This is important since malware can steal credentials from every visited web application from an infected machine. This time we’re going to look at how to protect against credential grabbing on a BIG-IP APM login page with WebSafe encryption layer.

You’ll need two modules for this, BIG-IP APM and of course, WebSafe Fraud Protection Service. The goal is to protect the laptop from any malware that grabs sensitive login credentials. In this case, the malware would be configured to grab the login page along with the username and password parameter fields. Command and control could also be set to retrieve any credentials from the infected machine at certain intervals, like every 5 minutes.

The first goal would be to encrypt the password. Within your BIG-IP admin GUI, you would navigate to Security>Fraud Protection Service> Anti-Fraud Profiles>URL List. APM’s logon page usually ends with ‘/my.policy’.


Create then click that URL to open the configuration page and enable Application Layer Encryption.


And select the Parameters tab to configure the fields you want to protect. In this case it is password and username.


In the screen grab, you can see ‘Obfuscate’ is selected and to both ‘Encrypt’ and ‘Substitute Value’ for the password field.

Now when the user goes to the page, a bit a JavaScript is injected in the page to protect the specified fields. If you run a httpwatch or wire shark on the page, you’ll see that the values for those parameters are obfuscated. This makes it incredibly difficult for the bad actor to determine the correct value.


And if the malware also grabs the password, since we set that to encrypt, all they get is useless information.

At this point, the BIG-IP will decrypt the password and pass on the traffic to appropriate domain controller for verification. This is a great way to protect your login credentials with BIG-IP. If you’d like to see a demonstration of this, check out F5’s Security Specialist Matthieu Dierick’s demo video. Pretty cool.

ps