Cyber Readiness Institute wants to help small firms fix their authentication issues

Help is on the way for leaders at small and medium-sized businesses that have had to contend with cyberthreats that would be a challenge even for massive firms with multimillion-dollar security budgets. A program led by alumni of President Barack Obama’s cybersecurity commission was unveiled Monday, offering free tools and resources meant to help smaller companies better secure their corporate networks. The Cyber Readiness Institute was launched in July 2017 by the Center for Global Enterprise — an institution devoted to researching management practices, — to help small and medium-sized enterprises mitigate cyber risk.  The Cyber Readiness Program, which launched Monday, includes support from private sector heavyweights like Mastercard, Microsoft, ExxonMobil and General Motors. The plan is for Fortune 500 companies to pass down cybersecurity know-how to companies with only a fraction of the resources, a method that ultimately aims to stop hackers before they can use one company as […]

The post Cyber Readiness Institute wants to help small firms fix their authentication issues appeared first on CyberScoop.

Continue reading Cyber Readiness Institute wants to help small firms fix their authentication issues

Hacking campaign on nuclear, defense sectors shares Lazarus Group tools, report says

Hackers behind a new campaign of cyberattacks that have targeted international critical infrastructure facilities are using malicious code linked to North Korea, according to research published Wednesday. Researchers from McAfee said “Operation Sharpshooter” has numerous technical links to the Lazarus Group, the group of suspected North Korean government hackers blamed for the 2014 breach at Sony Pictures and other well-publicized attacks. Operation Sharpshooter used a hacking tool called “Rising Sun” to target 87 organizations, mostly in the U.S., between October and November of this year, McAfee said. The cybersecurity vendor did not flatly tie this campaign to the North Korean government. “Attributing an attack to any threat group is often riddled with challenges, including potential ‘false flag’ operations by other threat actors,” the research states. “Technical evidence alone is not sufficient to attribute this activity with high confidence. However, based on our analysis, this operation shares multiple striking similarities with […]

The post Hacking campaign on nuclear, defense sectors shares Lazarus Group tools, report says appeared first on CyberScoop.

Continue reading Hacking campaign on nuclear, defense sectors shares Lazarus Group tools, report says

China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

The U.S. government again is concerned about Chinese cyber-operations, a senior National Security Agency official said Tuesday amid ongoing news about possible vulnerabilities in widely used technology. “We have to worry about national security,” Rob Joyce, a senior adviser for cybersecurity strategy at NSA, said Tuesday at a Wall Street Journal event in New York. “We’ve been strong and consistent in saying we have some specific concerns about supply chain risks and ways nations may take advantage of that.” Joyce was referring to heightened international scrutiny around the Chinese technology giant Huawei. Canadian authorities this month arrested Meng Wangzhou, Huawei’s chief financial officer, on suspicion of violation U.S. sanctions. Officials in the U.S., U.K., Australia and elsewhere have warned that Huawei’s ties with the Chinese government, combined with widespread adoption of the company’s technology, could result in espionage opportunities for Beijing. Western officials have not revealed any evidence proving such […]

The post China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap appeared first on CyberScoop.

Continue reading China’s cyber-espionage against U.S. is ‘more audacious,’ NSA official says amid Huawei flap

Industry council urges government to prep for a cyberattack that coincides with a natural disaster

A presidential advisory council has warned the White House and Department of Homeland Security in no uncertain terms that a catastrophic months-long power outage represents a “profound threat [that] requires a new national focus.” The president’s National Infrastructure Advisory Council, a group of executives from the public and private sectors tasked with issuing advice on protecting critical infrastructure, in a December report calls on the government to enhance its efforts to prevent widespread electrical failures in the event of a natural disaster. “Significant action is needed to prepare for a catastrophic power outage that could last for weeks or months,” the report found, adding that a cyberattack timed to coincide with a natural disaster could be especially problematic. “Although emergency authorities are understood at a high-level, how they are implemented in practice is unclear,” the report states. “There is a better understanding for physical events that are more frequently practiced, […]

The post Industry council urges government to prep for a cyberattack that coincides with a natural disaster appeared first on Cyberscoop.

Continue reading Industry council urges government to prep for a cyberattack that coincides with a natural disaster

From DDoS attacks to ad fraud: Smarter bots are copying human behavior

Major websites and internet services have been caught up in an epidemic of fake traffic, an expensive problem for digital operators that also threatens to undermine trust in legitimate areas of the web. Innovative scammers located throughout the world are constantly developing new ways to falsify web traffic, directing unwitting users’ internet connections to ads that may or may not actually exist. In these ad fraud campaigns, thieves traditionally would use automated bots to artificially inflate website traffic in schemes that allowed website operators to profit from higher advertising revenue. Security teams could once easily detect bot traffic by identifying visitors engaged in anomalous behavior, such as opening and closing windows millions of times. Now, ad-fraud scammers are using more advanced technology that more closely resembles actual human activity, making it far more difficult for digital crime-fighters to stop it. Gone are the days when scammers simply would only use […]

The post From DDoS attacks to ad fraud: Smarter bots are copying human behavior appeared first on Cyberscoop.

Continue reading From DDoS attacks to ad fraud: Smarter bots are copying human behavior

With new director, Tor seeks new funding sources and international growth

The Tor Project has been waiting for an opportunity like this. The privacy-focused organization for years has been developing technology to help web users browse the internet without prying eyes of repressive governments or Silicon Valley giants. Surveillance and the collection of personal data continues to be a fundamental problem for internet users, as evidenced by the number of data breaches in recent months involving information about hundreds of millions of people. Tor now has a new leadership team which aims to use the growing awareness about the proliferation of personal data as fuel for the privacy’s organization’s growth. That team just needs to figure out how to pay for it. The research-based nonprofit that’s responsible for the Tor browser — a free software tool that obscures a user’s location, browsing activity and other identifying data — gets funding from the U.S. government. First developed by the U.S. military to […]

The post With new director, Tor seeks new funding sources and international growth appeared first on Cyberscoop.

Continue reading With new director, Tor seeks new funding sources and international growth

Australia passes world’s first law authorizing encryption backdoors

Australia’s Parliament on Thursday passed the world’s first law requiring technology companies to give law enforcement officials access to encrypted messages and communications. The law authorizes police to compel companies to create a security vulnerability, often called a backdoor, that would give investigators access to an individual’s communication without that person’s knowledge. It marks a major milestone in the so-called “crypto wars” over the public’s ability to “go dark” via the powerful encryption available on commercial devices. Authorities in Australia, U.S., and U.K. for years have argued such access is necessary to help police combat encryption in modern technology that protects them from traditional interception techniques. Privacy advocates, technologists and businesses including Apple have criticized the Australian bill and similar proposals elsewhere, saying such plans would introduce portals for government abuse and malicious hackers alike. Companies that fail to obey the law risk being fined. “This ensures that our national security […]

The post Australia passes world’s first law authorizing encryption backdoors appeared first on Cyberscoop.

Continue reading Australia passes world’s first law authorizing encryption backdoors

Google unveils security suite, promising enhanced cloud visibility

Google Cloud users now will have more insight into what assets are connected to the platform and which ones present the most risk, the company says. The Cloud Security Command Center (SCC) is in beta mode and ready for use for Google Cloud users, the company said Wednesday, eight months after the tool was introduced. Google’s cloud business accounts for about $1 billion in revenue per quarter, it said earlier this year. The SCC inventories business data, identifies potential threats, remediates security issues and expands existing notification services, the company said. The goal is to organize diverse security information into a single web portal where enterprise security administrators can view everything at once. “If you’re building applications or deploying infrastructure in the cloud, you need a central place to unify asset, vulnerability and threat data in their business context to help understand your security posture and act on changes,” Andy Chang, […]

The post Google unveils security suite, promising enhanced cloud visibility appeared first on Cyberscoop.

Continue reading Google unveils security suite, promising enhanced cloud visibility

Symantec markets USB security to industrial facilities amid shift to enterprise sales

Cybersecurity giant Symantec on Wednesday announced a new product meant to protect industrial control networks from a pernicious threat: USB flash drives. Numerous studies have determined that roughly half the population is likely to plug a USB drive found in the parking lot into their computer, presenting hackers with an invaluable opportunity to infiltrate sensitive networks. Symantec is trying to solve that problem with Industrial Control System Protection (ISCP) Neural, a USB-scanning station meant to help energy, oil, gas and manufacturing organizations — which often use USB drives to update legacy systems — check for malicious software. ISCP Neural utilizes artificial intelligence capabilities to malware on USB drives in a way that will increase detection efficacy by up to 15 percent, the company claims. The devices are scheduled to be available for shipping in early 2019 at a rate of $25,000, the company told SecurityWeek. The product announcement comes amid internal […]

The post Symantec markets USB security to industrial facilities amid shift to enterprise sales appeared first on Cyberscoop.

Continue reading Symantec markets USB security to industrial facilities amid shift to enterprise sales

First major Kubernetes flaw enables hackers to access backend servers undetected

Researchers have uncovered the first known security flaw in Kubernetes, a popular open-source tool for managing application workloads. Developers published three security updates this week that promised to protect users of Kubernetes, a containerized application system, from a new vulnerability that could make it possible for hackers to inject malicious code or bring down an app from behind an organization’s firewall. Kubernetes runs on top of operating systems, taking commands from an administrator or developer and passing those instructions to nodes throughout an environment. This bug, the first major issue found in Kubernetes, warranted a 9.8 out of 10 severity score on because it could allow outsiders to establish a connection through Kubernetes’ trusted-application program interface to backend servers, ZDNet reported. From there, hackers can use that authentication to send arbitrary or malicious requests disguised under valid Kubernetes credentials, using that access to gain full administrator privileges. Exploiting the flaw […]

The post First major Kubernetes flaw enables hackers to access backend servers undetected appeared first on Cyberscoop.

Continue reading First major Kubernetes flaw enables hackers to access backend servers undetected