Why CISOs must get better at connecting to the rest of the company

Corporate security experts need to emerge from behind their physical cubicles and their digital firewalls to ensure that new technologies don’t create new vulnerabilities that could threaten their jobs, according to two executive-focused panels Monday at the RSA cybersecurity conference in San Francisco. Firms often fail to implement security measures amid their transition to the cloud, or when they implement the accelerated software production strategy known as DevOps, because security leaders fail to communicate with other departments, panelists said. “Because [new tools] are enabling business in a more rapid fashion, CISOs need to figure out how to turn security from ‘the business of no’ into something that enables functions,” said Kurt Hagerman, an executive adviser at the consultancy firm Coalfire. “You have to tie the value of your security program to the business. And that’s a skill a lost of CISOs today lack.” Too few companies have leaders who work together […]

The post Why CISOs must get better at connecting to the rest of the company appeared first on CyberScoop.

Continue reading Why CISOs must get better at connecting to the rest of the company

A GDPR ripple effect will help bring internet privacy back from the dead, Jon Callas predicts

Despondent internet users who love the convenience smartphones have brought but regret losing control of their data have reasons to be optimistic, according to a veteran technology industry executive who left Silicon Valley to work for the American Civil Liberties Union. Jon Callas, a computer security expert who left Apple for the ACLU last year, said Monday it’s become too easy to become nihilistic about personal privacy because of the last decade of negative headlines about corporate data collection. But international rules and legislation have started to adjust for the digital age, Callas said, predicting that users will not tolerate constant location tracking and other tradeoffs made in the name of efficiency. “The good news is that the privacy situation has gotten so bad that people want to change it,” Callas said during a presentation at the RSA security conference in San Francisco. “That means that over the next five […]

The post A GDPR ripple effect will help bring internet privacy back from the dead, Jon Callas predicts appeared first on CyberScoop.

Continue reading A GDPR ripple effect will help bring internet privacy back from the dead, Jon Callas predicts

Deadline passes for companies to comply with New York’s cybersecurity regulation

Time’s up for major banks, insurers and many of the companies they work with to comply with a New York State cybersecurity regulation that requires more data protection measures than anywhere else in the country. The New York State Department of Financial Services Cybersecurity Regulation goes into full effect Friday, two years after officials began to put it in place. “The Department has provided a two year transitional period to address these risks and expects Covered Entities to have completed a thorough due diligence process on all Third Party Service Providers by March 1, 2019,” the department said in an informational page. The rules require DFS-covered entities including financial firms, mortgage brokers, charities and Health Maintenance Organizations to use encryption, multi-factor authentication and tighter third party risk assessments, such as penetration tests, to limit outsiders’ access to corporate data. Covered entities also must notify regulators about a data breach within […]

The post Deadline passes for companies to comply with New York’s cybersecurity regulation appeared first on CyberScoop.

Continue reading Deadline passes for companies to comply with New York’s cybersecurity regulation

HackerOne thinks its freelance hackers can conduct penetration tests better than actual pentesting companies

A big player in one of the buzziest areas of cybersecurity soon will begin offering penetration testing services, entering a market where firms deploy dedicated teams or use automation to perform the same tasks. Since its founding in 2012, bug bounty program provider HackerOne has made its name by building a stable of freelance security researchers that poke around on client networks. By connecting hackers with customers including GM, Starbucks and the U.S. Department of Defense, HackerOne helps more than 1,200 organizations find and fix security vulnerabilities. The San Francisco-based firm now says its expanding to offer crowdsourced pen-testing, a market CEO Mårten Mickos suggested now stands at roughly $1 billion. It’s a step up from the current bug bounty market, which he pegged at around $150 million. “Most [penetration testing] companies suck,” Mickos said during a recent interview in New York City. “Our plan is to take the market […]

The post HackerOne thinks its freelance hackers can conduct penetration tests better than actual pentesting companies appeared first on CyberScoop.

Continue reading HackerOne thinks its freelance hackers can conduct penetration tests better than actual pentesting companies

Up to 40 percent of traffic on ticket sites is automated. Here’s why that’s bad for security.

If you have rushed to score exclusive concert tickets online, the chances of you competing against a human are dwindling. According to new research, nearly 40 percent of traffic to ticketing websites is made up of bots, automated programs used by brokers and cybercriminals to do everything from denying customers inventory and scalping tickets to taking over customer accounts to commit fraud. An analysis of 26.3 billion requests from 180 websites reveals that bad bots made up 39.9 percent of ticketing traffic between September and December 2018, according to the bot mitigation company Distil Networks. Seventy-eight percent of bots evaded detection by relying on human-like behavior, and most (42.2 percent) targeted the primary ticket markets, compared to 23.9 percent that hit secondary markets. Distil suggested this kind of bot traffic hurts ticket sellers by making it more difficult to purchase tickets, which results in frustrated fans and artists complaining on […]

The post Up to 40 percent of traffic on ticket sites is automated. Here’s why that’s bad for security. appeared first on CyberScoop.

Continue reading Up to 40 percent of traffic on ticket sites is automated. Here’s why that’s bad for security.

20-year-old pleads guilty to DDoS-for-hire scheme that netted $550,000

A 20-year-old Illinois man pleaded guilty to charges related to a scheme to launch millions of distributed denial-of-service attacks against U.S. school districts and other targets, the U.S. Department of Justice announced Wednesday. Sergiy Usatyuk and a co-conspirator gained more than $550,000 by charging subscribers for access to booter and stresser services, which typically enable attackers, using only a web browser, to launch a DDoS attack capable of knocking target sites offline. Usatyuk was involved with booter and stresser services including ExoStreeser, QuezStresser, BetaBooter Databooter, Instabooter, Polystress and Zstress. The Exostresser services alone facilitated 1,367,610 DDoS attacks which caused victims to suffer 109,186 hours of downtime, the DOJ said Wednesday. In one case in 2017, a Betabooter user launched a number of DDoS attackers against a Pittsburgh, Pennsylvania, school district that also affected 17 other organization, including the county government, prosecutors said. Usatyuk was active from around August 2015 to November […]

The post 20-year-old pleads guilty to DDoS-for-hire scheme that netted $550,000 appeared first on CyberScoop.

Continue reading 20-year-old pleads guilty to DDoS-for-hire scheme that netted $550,000

‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems

Many modern computers running Mac, Windows or Linux operating systems are vulnerable to a number of security flaws that could exploit a machine’s connection to its network cards, keyboard, computer charger or other essential peripheral devices, according to research published this week from a team of computer scientists. The vulnerabilities, which require physical access to a computer, are known collectively as “Thunderclap.” They leverage operating system design flaws in what’s known as a Thunderbolt interface, a common piece of hardware that allows outside devices to connect to a machine. Researchers revealed this week at the NDSS 2019 security conference that “all Apple laptops and desktops produced since 2011 are vulnerable, with the exception of the 12-inch MacBacBook. Many laptops, and some desktops, designed to run Windows or Linux produced since 2016 are also affected[.]” The Thunderclap vulnerability could allow an attacker with access to a machine to execute commands at […]

The post ‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems appeared first on CyberScoop.

Continue reading ‘Thunderclap’ collection of hardware vulnerabilities affects Mac, Windows, Linux systems

A researcher made an elite hacking tool out of the info in the Vault 7 leak

When WikiLeaks published a cache of more than 8,000 CIA documents in 2017 detailing U.S. hacking capabilities, security experts complained that the organization had possibly produced a technical blueprint on how to recreate the government’s elite-level tools. Wayne Ronaldson has made it a reality. Ronaldson, who looks for corporate clients’ vulnerabilities as “red team” leader at Melbourne-based offensive security company Loop Secure, pored over many of the so-called Vault 7 documents to find the Assassin program. The CIA described Assassin as an automated implant tool capable of monitoring computers running Microsoft Windows for long periods of time without detection, sending periodic updates to its operator. Ronaldson, using Assassin as the model for his own intelligence-gathering tool, studied the leaked CIA documents and consulted with industry friends about how to make his own cyber-espionage weapon. Next week, nearly 16 months after he began the process, Ronaldson plans to unveil Operation Overwatch during a presentation at the 2019 […]

The post A researcher made an elite hacking tool out of the info in the Vault 7 leak appeared first on CyberScoop.

Continue reading A researcher made an elite hacking tool out of the info in the Vault 7 leak

Third suspect in Methbot, 3ve case to plead not guilty after extradition from Malaysia

A Kazakh national accused of helping coordinate an advertising fraud scheme that fleeced companies out of tens of millions of dollars will plead not guilty when he arrives in the U.S. to stand trial, his lawyer told CyberScoop. Sergey Ovsyannikov is scheduled to be extradited to the U.S. in the coming weeks, a Kazakh consulate official told CyberScoop last week. When Ovsyannikov arrives in court, he will plead not guilty to charges that he led the 3ve botnet-based scheme to falsify billions of advertisements, costing businesses $29 million between December 2015 and October 2018, according to defense attorney Arkady Bukh. “At the arraignment, the plea will be entered as not guilty,” Bukh said. “Then we’ll go over the [evidence] and…we’ll see if the government is in a position to prove any guilt.” His presence in court will mark the third time an accused member of the 3ve/Methbot group was extradited […]

The post Third suspect in Methbot, 3ve case to plead not guilty after extradition from Malaysia appeared first on CyberScoop.

Continue reading Third suspect in Methbot, 3ve case to plead not guilty after extradition from Malaysia

For many crooks, malware is out and PowerShell attacks are in, IBM says

Digital thieves are ditching traditional forms of cybercrime in favor of more subtle techniques that apparently help them avoid detection, IBM says. Scammers are moving away from the use of malicious software, opting instead to exploit administrative tools to target business and organizations, according to a report published Tuesday by the company’s X-Force Threat Intelligence team. Nation-state hacking groups appear to have started the trend, but it seems to have spread throughout the broader cybercriminal black market. FireEye said in 2017 it detected a suspected Iranian group using similar techniques to collect reconnaissance about global critical infrastructure companies. IBM’s report says such tactics are everywhere now. Fifty-seven percent of the attacks IBM detected used common, otherwise benign applications like PsExec or PowerShell, a tool that can execute code from memory. Just 29 percent used more traditional phishing attacks. IBM says. This tactic enables hackers to evade antivirus protection and other common security controls. “PowerShell is useful in data […]

The post For many crooks, malware is out and PowerShell attacks are in, IBM says appeared first on CyberScoop.

Continue reading For many crooks, malware is out and PowerShell attacks are in, IBM says