Monday, January 10, 2022

The Rise of Profit-Focused Cybercrime on the Cloud

The Rise of Profit-Focused Cybercrime on the Cloud

It is encouraging to think that the cloud may make us safer. But, it can be just as vulnerable if we do not protect it properly.

As cybercriminals look for ways to outsmart IT, they set their sights on cloud services that are still vulnerable to attack. What is making it so much easier now is the whole movement toward cloud computing—a motion that has led many businesses to hire firms that don’t specialize in that sort of security.

Cybercriminals are already exploiting this new security arrangement between cloud networks and organizations to commit fraud, steal sensitive financial data, or even launch ransomware attacks on local businesses.

In fact, there is a growing list of breaches like lost personally identifiable information (PII) and stolen credit card or banking information linked directly to cloud service providers (CSPs).

Why is Cybercrime a Growing Concern?

Researchers of Trend Micro found that popular providers like Amazon, Facebook, Google, Twitter, PayPal at some point or the other have faced the repercussions of data theft where terabytes of internal business data were up for sale on the dark web.

Cybercriminals usually sneak such data from the cloud logs where it is stored and sell them wherever profitable. The time it takes for these guys to perpetrate fraud and monetize profits has decreased from weeks to a few days or just hours.

Trend Micro further predicts that cybercrime will get even bigger; some even say it’s just beginning.

Cybercrime has reached epic proportions. According to the Kaspersky Lab, a single instance of ransomware demand (in which an attacker encrypts a computer or network and does not let go until a ransom is paid) can cost a business more than $713,000. Other associated costs can push the amount much higher. They generally include the cost of:

  • Paying the ransom
  • Cleaning up
  • Restoring a backup
  • Improving infrastructure
  • Ensuring the network is functioning
  • Repairing damage

Remember the ExPetya cyberattack that hit more than 12,000 machines in over 65 countries? Think of the downright profits criminals must have made!

Narrowing Down the Biggest Cloud Problem: Attack Vectors

Clearly, companies aren’t prepared for cyber threats, and they need to do something quickly. You need to understand exactly where your system could be at risk, and once you figure it out, you should know what you can do about it.

Multiple options to configure

Cloud computing offers many unique opportunities to deliver value to users, but it also requires an unusually high level of user competence. Different configuration mechanisms provide different levels of confidence, but they all rely on the decisions enterprises make.

When speaking of configuration, the devil is in the details. That is to say, from a few simple choices about things like storage and networking; a developer can see many problems caused by incompatibilities or invalid assumptions. Think of it like programming; it is easy to make mistakes that are almost impossible to recover from.

Attacks like Denial-of-Service (DoS)

Cybercriminals and “hacktivists” use cloud platforms for distributed denial of service attacks because they are very effective. The symmetrical nature of the cloud plays right into the hands of cybercriminals. They can rent their own botnet by using cloud computing services.

These criminals create viruses that turn the victim’s computer into part of a “botnet,” which is then rented for activities like attacking websites or sending spam. Botnets are also now available on-demand via underground forums. It means they can stop paying when they stop needing.

Lack of consistent scanning

One of the major downsides to cloud adoption at large is that it is difficult for a company to detect and orchestrate security around the new applications when they are introduced into their environment.

Since different departments are spinning up cloud applications, it is exhausting for a central management team to control what’s happening unless they have a unified line of communication. Businesses should regularly scan to ensure all data is encrypted and there isn’t any server that is accessible back doors.

Insecure interfaces and APIs

An insecure user interface (UI) or application program interface (API) is like an open door invitation for cyber attacks. Enterprises should prioritize security investments to build safe systems right from the start rather than bolted on later.

Whether it is a public cloud or a private cloud, your cyber security team must make efforts to maintain the flow of information sensibly and securely. These include parameters such as inventory management, testing, auditing, and abnormal activity protection. Businesses should also protect their API keys and avoid overusing them. In addition, they can also leverage open API frameworks like Open Cloud Computing.

Not adhering to policies

Security policies play a key role in making sure that cloud data remains reliable in a business. IT organizations must put in place a process for enforcing policies before being used to protect critical data.

It may often happen that the security team will want someone from the business to inform them about their next move. However, given that most organizations have a bunch of different account owners, it isn’t clear who to ask. On the other hand, the DevOps team may not want to do manual configuration or implementation. Besides, to pull up APIs, you must be logged in to your account.

Without the right policies and tools to monitor, track, and manage their applications and API usage, businesses cannot take full advantage of cloud benefits or protect themselves from risks like data leakage or compliance violations.

Cybercriminals to Make an Annual Profit of $10.5 Trillion by 2025

People often think of cybercrime in terms of the losses it causes, but what about its profits?

The cybercrime industry is a multi-billion-dollar business. And it’s only growing. Criminal hackers are shifting their focus from opportunistic, low-level attacks to big, high-value targets like governments and large corporations.

According to Cybersecurity Ventures, the damage is estimated to reach $6 trillion USD by 2021. If cybercrime were a country, it would be the third-largest economy in the world after the U.S. and China.

Cybercrime is inherently different from a traditional crime. These cybercriminals operate in groups or even organize themselves into syndicates, sharing information about the operation of their schemes to increase efficiency and reduce the chance of being caught.

The cybercrime economy is a dynamic market filled with disruptive start-ups. Cybercriminals are taking business models more seriously. They’re not “sewing” together spreadsheets of stolen credit cards. They’re building platforms that can compete with the legitimate economy. There’s more to the threat than you think.

Breaking Up the Trillion-Dollar Cybercrime Market

Even though cloud computing is transforming the way businesses operate, the risks are bigger than what you will be compensated for. The responsibility, therefore, lies on both cloud users and providers.

Some tips on how to become resilient and prevent the top threats in cloud computing are:

1. Secure APIs and restrict access

APIs are at the heart of cloud computing, so any developer worth their salt should know how to build them securely. This might mean restricting access across different networks or developing the API only at the edge of your infrastructure before letting it call other applications.

2. Ensure endpoint protection

Endpoint protection is similar to burglar alarms. Burglar alarms protect homes when they’re unoccupied because burglars can easily break in when no one’s there.

Similarly, endpoint security protects corporate networks that are remotely bridged to a host of business-critical devices. For example, mobile employees, employees who use laptops and tablets on the road, and customers who connect to corporate Wi-Fi.

3. Encryption is key

Cloud encryption allows you to create secret texts or ciphers that are stored on a cloud. Your business data is invaluable, which is why it is important to protect your information before it gets onto the cloud. Once encrypted at the edge, even if your data is stored with a third-party provider, all data-related requests will need to involve the owner.

This way, you maintain complete control over all your customers’ information and ensure it remains confidential and secure.

4. Use strong authentication

Weak password management is one of the most common ways to hack a cloud computing system. Thus, developers should implement stronger methods of authentication and strengthen identity management.

For example, you can establish multi-factor authentication where the user needs to produce a one-time password or use biometrics and hardware token to verify their identity at various touchpoints in the user journey.

5. Implement access management

Enable role-based access to control the scope of a user’s permissions. You can also restrict a user’s capabilities by assigning only the permissions that the user is allowed to have. This way you can ensure that your users can have their work environments exactly as you wish to set up for them.

6. Backup your data

With the increasing need for data security, organizations of all sizes are turning to data centers for backup services. Modern cloud data centers offer the whole package—unmatched protection, scalability, performance, and uptime.

Every company needs a business continuity plan to ensure that their systems are safe, even if the worse happens to them. When you have a secure data center environment to back up your data, you can keep your business up and running even in the event of a ransomware attack.

7. Educate your team

Your employees are your biggest security risk element. Therefore, make security training mandatory for anyone who works in your company. When employees are active participants in protecting assets, they’re fully aware of their responsibilities when it comes to protecting data.

You can also create an internal guidebook for your employees so they know the best course of action in case of identity theft. Another option is to create an actual response protocol. This way, if your employees ever feel they have been compromised, they will always be prepared.

The Bottom Line

Anonymity is a powerful tool, and the cloud has made it easier for cybercriminals to preserve anonymity by scattering networks over different servers.

The need for cyber security is greater than ever. Cybercrime is on the rise, and it has become more sophisticated and lucrative than ever before. In addition, as companies continue to migrate their operations to the cloud, criminals increasingly view the cloud as an attractive target for profit-making criminal and espionage operations. It’s time to fight back!

The Rise of Profit-Focused Cybercrime on the Cloud

Originally published at ReadWrite

The Rise of Profit-Focused Cybercrime on the Cloud – ReadWrite
The Rise of Profit-Focused Cybercrime on the Cloud. Cyber criminals are already exploiting this new security arrangement.
The Rise of Profit-Focused Cybercrime on the Cloud

https://bit.ly/3F67kle
https://bit.ly/32WEg2J


https://guptadeepak.com/content/images/2021/12/network-g114618946_1280-1-825x500.jpeg
https://deepakguptaplus.wordpress.com/2022/01/10/the-rise-of-profit-focused-cybercrime-on-the-cloud/

Saturday, January 8, 2022

Containers in the Cloud Next on Cybercriminals’ Radar

Containers in the Cloud Next on Cybercriminals’ Radar

Over the past couple of years, containers have solved many complex issues related to the compatibility and portability of deployments. But that means they contain sensitive information that can attract the attention of cybercriminals.

Securing containers in the cloud should be a major priority for businesses to ensure a robust security environment to safeguard their crucial business information.

Digital transformation has offered endless possibilities for businesses to stay ahead of the curve by leveraging cutting-edge technologies. However, being digitally advanced doesn’t guarantee adequate security, especially in a business environment where enterprises are swiftly adopting cloud technologies.

According to a survey conducted by Statista in 2021, around 64% of respondents agreed that data loss/leakage is their biggest cloud security concern. Since more and more organizations worldwide are migrating workloads to the cloud, security concerns have become more pertinent. One major concern is the increasing risk of vulnerabilities in containers that serve as lightweight software packages containing entire runtime environments.

Securing containers in the cloud is the next step organizations should take to ensure a robust security environment and safeguard their crucial business information.

Why Containers are Vulnerable to Cyberattacks

Containers, like any other computing or software system, are made up of different interconnected components that link to other applications. These containers contain all the necessary elements to run in any environment, virtualize operating systems and run from any private data center or public cloud.

And like any other application or system, containers are vulnerable to several different types of cybersecurity threats since a defect in the overall security of these containers could allow an attacker to gain access and total control over the entire system.

Cybercriminals can leverage access to a container environment to move through you environment; exploit sensitive data and cause losses worth millions of dollars, not to mention the damage to your brand’s reputation. Businesses must detect and remediate different container vulnerabilities to mitigate cybersecurity
risks early.

Detecting Container Vulnerabilities

Enterprises leveraging containers usually follow a solid development pipeline process with planning,
coding, revision and building steps followed by rigorous testing, releases and deployments. At every phase, there’s an opportunity for the organization to detect and resolve any vulnerabilities that can create a loophole for attackers to exploit.

However, many organizations still stumble when trying to locate weaknesses in their
systems. They may consider traditional security tools or rely on conventional testing techniques that aren’t as effective in container environments. Instead, enterprises leveraging containers in the cloud should approach mitigating the risks differently.

Registry Scanning

A registry could be defined as the collection of repositories used to store container images that are
the templates used for deploying multiple instances of running containers. The registry is integral and commonplace; many vulnerability scanning tools can be configured to scan images contained inside a registry. Moreover, this method is widely used to identify container vulnerabilities since it’s a low-cost and high-value method for finding and fixing security issues. Registry scanning can help organizations quickly identify and fix the issues that can potentially reside in containers and any defective or old containers can be quickly identified and rectified.

Runtime Environment Scanning

One of the oldest and most reliable methods used to find vulnerabilities inside containers is to scan against a
running container to highlight defects. In this approach, any faulty image is replaced with a new one. This is perhaps the best way to detect and rectify rogue containers that aren’t appropriately deployed.

CI/CD Pipeline Scanning

Continuous development/continuous integration (CI/CD) pipelines are crucial phases of software product development in which developers develop the code, review it and test it. Several workflow automation tools, including GitLab, Bamboo and Jenkins, are widely used to build software modules, and make for the perfect place to perform security scanning.

In this phase, any issues can be quickly identified early and remediated at la ower cost than in the later, advanced stages of development or when the product is deployed. Enterprises can leverage several vulnerability management tools that offer a flawless integration with these workflow automation tools.

Container Security Best Practices

Enterprises thinking of incorporating strategies and products for managing container vulnerabilities must consider some fundamental principles to ensure adequate container security. These include:

● Building containers with minimum base images or using distro-less images from a trusted source.
● Adding stringent layers of security through robust security mechanisms like risk-based authentication (RBA).
● Choosing a vulnerability scanning tool that aligns with the organization’s processes, existing ecosystem and DevOps practices.
● Planning to implement vulnerability scanning at every phase of development.

By following these security best practices, enterprises can secure their containers and minimize
the chances of a data breach or an intrustion into their system.

Bottom Line

Container security shouldn’t be ignored by enterprises embarking on a digital transformation journey. Since containers are prone to different vulnerabilities, organizations must incorporate rigorous testing in different software development life cycle phases to scan and highlight these vulnerabilities. The best practices mentioned above could help organizations secure their containers in the cloud and mitigate the risk.


Originally published at Container Journal

Containers in the Cloud Next on Cybercriminals’ Radar
Securing containers in the cloud can ensure a robust security environment and safeguard businesses’ crucial information.
Containers in the Cloud Next on Cybercriminals’ Radar

https://bit.ly/3zBgBRj
https://bit.ly/33k6Ef2


https://guptadeepak.com/content/images/2021/12/cloud-security.jpeg
https://deepakguptaplus.wordpress.com/2022/01/08/containers-in-the-cloud-next-on-cybercriminals-radar/

Friday, January 7, 2022

QR Codes Exploitation: How to Mitigate the Risk?

QR Codes Exploitation: How to Mitigate the Risk?

The COVID-19 pandemic has conveyed a strong message to leverage technology to its full potential, not just for convenience but to remain safe.

Although QR Codes are the new normal and help us follow COVID-19 safety regulations, bad actors of society exploit the vulnerabilities associated with this technology.

As per a survey, 18.8% of consumers in the US and UK strongly agreed with an increase in the use of QR Codes since the outbreak of COVID-19.

A recent research report on consumers revealed that 34% of respondents have zero privacy, security, financial, or other concerns while using QR Codes.

Since any kind of malware or phishing links in QR Codes pose significant security risks for both enterprises and consumers, stringent security measures should be considered to mitigate the risk.

Let’s learn how cyber-attackers exploit QR Codes and how businesses and users can mitigate the risk, especially in a world where contactless transactions are the new normal.

QR Codes Exploitation: How to Mitigate the Risk?

Cybersecurity Risks Associated with QR Codes

Since a QR Code cannot be deciphered by humans, many cases of QR Code manipulation have been reported across the globe, which increases the risk of using these Codes for processing payments.

Cybercriminals could easily embed any malicious or even phishing URL in the QR Code for exploiting consumer identity or even for monetary benefits.

The pixilated dots can be modified through numerous free tools that are widely available on the internet. These modified QR Codes look similar to an average user, but the malicious one redirects the user to another website or other payment portal.

Is there anything else attackers can do with QR Code tampering?

Yes, absolutely! Cybercriminals may also sneak into a user’s personal and confidential details, which can further be exploited.

Many businesses utilizing QR Codes have reported several instances of consumer data and privacy breaches over the past couple of years.b

Shockingly, the number of breaches has significantly surged in the uncertain times of the COVID-19 pandemic as more and more people have started using QR Codes in the new contactless era.

Here are some actions attackers can initiate by exploiting QR Codes:

1. Redirect a payment

One of the most common ways hackers exploit QR Codes is to send payments to their bank accounts automatically.

This trick works when the actual QR Code is replaced by the fraudsters in grocery stores or other areas where consumers scan the Code and pay.

On the other hand, individuals using online shopping websites may receive a phishing email containing a message that urgently requires your consent regarding your payment history on a shopping website.

They may ask you to pay for the product you purchased as your previous payment is canceled and ask you to scan a QR Code for the same.

Apart from this, many cyber-attackers cunningly replace the landing URL with the one that resembles the real one. The user may find the webpage authentic that builds trust, and the user processes the payment.

Users need to be aware of the altered QR Codes and carefully examine the preview link before clicking on it.

Checking for spelling errors or possible alterations in the domain that makes it resemble the original one can be very helpful in determining a cloned URL.

In addition to this, one should avoid scanning a QR Code embedded in an email from an unknown source to avoid being phished.

Email authentication protocols such  DMARC, DKIM, BIMI, and SPF records help add an extra protective layer to prevent phishing attacks and keep one’s domain reputation intact

2.  Reveal user’s PII

Another common way of exploiting QR Codes by attackers is to get their hands on a user’s personally identifiable information (PII).

These attackers can utilize the PII in multiple ways and for various personal benefits including, but not limited to financial benefits, online shopping, or other activities.

Once a user scans a QR Code available at any store or even on the internet, a malicious software program gets installed on the device, which quickly reveals sensitive information about the user.

Moreover, cases of duplicate contact tracing by cybercriminals have been reported in Australia, where hackers exploited consumers’ identities for monetary benefits.

According to ACCC (Australian Competition and Consumer Commission), more than 28 scams involving QR Codes have been reported with damages of over AU$100,000.

The most common attack through malicious software installed with an altered QR Code is intended to get personal details, including passport number, contact number, or even on-time-passwords for payment processing.

3. Reveal user’s current location

While the scope of exploiting QR Codes is enormous, many attackers keep an eye on a user’s real-time location.

Cybercriminals are continuously tracking some people who get attacked by malicious software installed on their device after scanning a QR Code for their numerous benefits.

Hackers may alter the original QR Code and link malicious software that automatically gets installed on a device as soon as someone opens the link after scanning the QR Code.

This software program can further access a device’s location, contact lists, or even data, which hackers exploit.

One may not even be aware of his/her location tracking, but cybercriminals may be continuously tracking his/her location and keeping an eye on its behavior.

How to Mitigate the Risk Associated with QR Exploit: A User’s Guide

Let’s quickly learn about the ways that can help you in ensuring adequate safety while using QR Codes:

1. Scan only from trusted entities

It’s crucial to stick to the QR codes shared by trusted vendors, and users shouldn’t just randomly scan any QR Code they come across. This ensures adequate safety from malicious and phishing attacks.

A user needs to check the website and security aspects, including the SSL (Secure Sockets Layer) certificate, before proceeding with a transaction on a website after scanning a QR Code.

Ensure that the QR Code is customized by including your brand’s logo, changing the shape of the eyes, patterns, and even including gradient and a CTA to make it difficult for hackers to duplicate the QR Code.

In addition, rename the domain to your brand name so users can easily identify the source of the QR Code to avoid being phished.

SSL certificate ensures secure connections and also provides secure transactions. However, if a website doesn’t contain the SSL certificate in the domain, one should be alert and verify the source before proceeding to payment or permission.

Many people open the link just after they scan a QR Code without even checking the link. This can be pretty risky when it comes to privacy and security.

Most devices have an in-built QR scanner in their camera application, which is entirely secure, while others rely on third-party QR scanners.

It is best to use the in-built scanner (if available) and check the preview of the link. If you find anything suspicious regarding the link, it’s best to verify the source before opening it in your browser.

3. Pay close attention to details

Users need to pay close attention even to the small details while making payments or proceeding with transactions through a QR Code.

The best way is to utilize the same in a familiar and secure environment. Cybercriminals can easily replace some public QR Codes, including the fuel station or kiosks, and they may receive the benefits whenever a user pays by scanning the Code.

If you find something wrong with the QR Code or if it feels tampered with, it’s best to avoid using the same and find other modes of transactions to remain on the safe side.

4. Update your device’s security and overall defense system

Installing and regularly updating your device’s security software could help a lot in preventing a security breach.

However, QR Codes and the overall mechanism are considered secure, but your device’s first layer of defense shouldn’t be outdated.

Installing regular security updates would not only ensure you get maximum safety from malicious activity but you would be made aware immediately regarding any unnecessary or unauthorized access to your device’s data.

What Should Enterprises Do?

QR Codes help us establish a secure contactless payment option when it comes to the spread of the novel coronavirus.

But individuals and enterprises can put their best foot forward to minimize the risks associated with QR Code cybersecurity threats by ensuring adequate measures in place.

Here are some efficient ways to minimize the risks for consumers:

  1. Using multi-factor authentication
  2. Having a mobile defense system in place that blocks unauthorized downloads, phishing attempts, and repetitive login requests
  3. Enabling risk-based authentication
  4. Improve enterprise password security

Final Thoughts

With the rise in QR Code exploits, both the users and enterprises offering contactless payment options need to take crucial steps.

Users should be aware of the latest QR frauds that not only could lead to financial losses but eventually can cause a threat to an individual’s privacy and sensitive data.

On the other hand, enterprises must have best security practices in place that helps them secure sensitive information and prevent transaction frauds. Enterprises must design their websites keeping this in mind, and expert web development companies can help the implementation of a robust security architecture.

The aforementioned aspects can be quite helpful in minimizing the risks for individuals and organizations that are striving to protect consumer identities and data.

Adequate device security measures like mobile threat defense systems can also be a game-changer for mitigating security threats associated with QR Code exploits.


Originally published at Beaconstac

QR Codes Exploitation: How to Mitigate the Risk?
With the rise in QR Code exploits, how can businesses and consumers decipher what a QR Code holds before scanning and mitigate the risks of a malicious QR Code? Find out how!
QR Codes Exploitation: How to Mitigate the Risk?

https://bit.ly/3eYrToW
https://bit.ly/3EXQeG8


https://guptadeepak.com/content/images/2021/12/AdobeStock_409315615.jpeg
https://deepakguptaplus.wordpress.com/2022/01/07/qr-codes-exploitation-how-to-mitigate-the-risk/

Tuesday, January 4, 2022

The Future of Cyber Attacks

The Future of Cyber Attacks

The need for cybersecurity has existed ever since the emergence of the first computer virus. The ‘creeper virus’ was created in 1971 and could duplicate itself across computers. Also, the threat landscape is emerging with the evolution of new technologies such as AI, Immersive Experience, Voice Economy, Cloud computing, and others. Threat actors upgrade their tools and tactics by designing new strategies to perpetrate their nefarious aims.

Cyberthreats are growing in both scale and complexity, and the need to secure critical infrastructure by businesses and public organizations has never been as urgent as now.

This article examined how cyberattacks have evolved in the past 12 months, the big lessons, what threats will look like in the future, and strategies companies can deploy to secure their endpoints and data against cyberattacks.

Key Cyberattacks in the last 12 months

1. Phishing attack in the era of Covid-19

Threat actors send a message to deceive people into downloading or clicking a malicious link. During the Great Lockdown of 2020, many people were working from home. Cybercriminals leverage this opportunity as businesses and communication entirely depend on the internet. A report by the FBI revealed phishing to be the most popular form of cybercrime in 2020, and the incident reported nearly doubled ( 241,324) what was recorded in 2019, which was 114,702.

2. The Notorious Ransomware Attack

The ransomware attack was profitable for threat actors in the last 12 months. Ransomware locks files on the victims’ system and redirects them to a page to pay a ransom to have their files returned. A notable example was the Cyrat ransomware which was masked as software for fixing corrupted DLL files on a computer system. According to Reuters, over 1500 businesses have been affected so far.

3. Attacks on IoT and IIoT

The adoption of the Internet of Things(IoT) and the Industrial Internet of Things at both the individual and industrial levels also leads to concerns around cybersecurity. These connected devices make our lives easier, and when not properly configured and secured, they could also leak our sensitive data to the bad guys.

In 2020, an IoT botnet employed vulnerable access control systems in office buildings. As a result, someone accessing the building by swiping a keycard may be ignorant that the system has been infected.

4. Password Compromise

A security survey conducted by Google revealed that about 52% of people reuse passwords across different sites. It means a cybercriminal can successfully access all accounts by breaching a single account. As a result, password attacks remain a top attack vector for most organizations. In the same survey, 42% of the people ticked security breaches due to a password compromise.

A notable example was a list of leaked passwords found on a hacker forum. It was said to be the most extensive collection of all time. About 100GB text file which includes 8.4 billion passwords collated from past data breaches.

You can type your details in https://bit.ly/3zqlSL6 to know if your email or password has been breached.

5. Identity Theft

Cases of Theft doubled from 2019 to 2020 based on a report by the Federal Trade Commission of the United States. The commission received around 1.400.000 cases. Most cases include threat actors targeting individuals affected by the pandemic financially. Cybercriminals also leveraged the unemployment benefits reserved for those affected by the pandemic. The fraudsters claimed these benefits using information stolen from thousands of people. Suppose we merge this with what recently occurred on Facebook and Linkedin, where users’ data were scraped off public APIs by malicious actors. In that case, one could imagine how privacy is becoming a subject of concern for both individuals and companies.

6. Insider Threat

Insider Threat is a form of attack that is not as popular as others yet affects both small and big businesses. Anyone familiar with a company’s internal operations and structure can be a suspect. A Verizon report of 2019 revealed about 57% of database breaches are caused by insiders.

One of the best approaches to limiting the impact of this threat is restricting the privileges of staff to critical areas.

What Are The Lessons From The Biggest Cyberattack?

The attacks mentioned above and others have consequences and lessons to avoid a repeat. Let’s explore some of them:

1. There’s nothing new about the threats

There was a similar attack like Wannacry, which affected Sony in 2014. With regular patching and firewall, organizations can still prevent infiltration or exploitation.  Interestingly, the actual patch of the vulnerability exploited by Wannacry was released two months before the event, but many organizations failed to patch it. Those who did not patch had their critical infrastructures impacted by the attacks.

2. Several organizations are unbelievably vulnerable

NotPetya cyberthreat exploited Microsoft vulnerability (SMB-1) by targeting businesses that failed to patch. As a result, organizations have to develop cyber-resilience against attacks by constantly downloading and installing patches across their systems.

3. Prioritize Data Backup

Even if you lose your critical data to a ransomware attack, a backup will help you keep your operations running. Therefore, organizations must back up their data outside of the network.

4. Develop an Incident Response Plan

Proactive response to incidents and reporting enabled most companies to halt the spread of Wannacry even before the incident. Regulators expect companies to issue warnings within 72 hours or get penalized.

5. Paying Ransom only create an opportunity for more attacks

While it is easier to pay the ransom with the expectation of having your files restored, as long as the communication link is maintained, the threat actors will always come back. Also, it is like empowering them to continue the chain of attacks.

What Would Cyberattacks Look Like In The Future?

Cybersecurity experts predicted the financial damages caused by cyber threats to reach $6 trillion by the end of 2021.  Cyber Attack incidents are also expected to occur every 11 seconds in 2021. It was 19 seconds in 2019 and 40 seconds in 2016. In the future, we would have cyberattacks possibly happening every second. As a result, we would see a surge in frequency and significant financial damages to victims.

Deepfake and Synthetic Voices

Deepfake trended in 2019 as threat actors innovate means of improving their tools and technologies for malicious and entertaining purposes such as illegal pornography featuring. In the future, cybercriminals will call into customer call centers leveraging synthetic voices to decipher whether organizations have the tools and technologies to detect their operations. One of the major sectors that will be targeted will be the banking sector.

Conversational Economy Breach

As companies begin to deploy voice technology and individuals adopt digital assistant technologies like Alexa and Siri, fraudsters will also not relent in discovering the potential opportunities locked up in the voice economy. According to Pin Drop Statistics, 90 voice attacks took place each minute in the United States. 1 out of 796 calls to the call center was malicious. Now that we are all migrating to Clubhouse, we should also expect voice data breaches around voice-based applications.

Some challenges companies would have to deal with include protecting voice interaction, privacy concerns, and supporting call centers with tools and solutions for detecting and preventing fraud.

Security Cam Video Data Breach

In March 2021, Bloomberg reported a breach of surveillance camera data. The breach gave the hackers access to live feeds of over 150,000 security cameras located in companies, hospitals, prisons, police departments, and schools. Major companies that were affected include Cloudflare Inc. and Tesla Inc. Not only that, the hackers were able to view live feeds from psychiatric hospitals, women’s health clinics, and offices of Verkada. These Silicon Valley Startup sourcing data led to the breach.

This scenario paints a vivid picture of what a security cam video data breach looks like and the consequences- privacy breach.

Apple/Google Pay Fraud

Cybercriminals are utilizing stolen credit cards to purchase via Google and Apple pay. Recently, over 500, 000 former Google+ users had their data leaked to external developers. Google offered to pay US$7.5m in a settlement to address a class-action lawsuit against it.

3 Things To Do To Stay Protected

If you are concerned about the growing rates at which these cyber-attacks occur, here are three important things you can do:

Secure Your Hardware

While it is exciting to acquire the latest equipment, securing them with the best cyber threat prevention measures is also essential. For instance, you can use a complex password and reset the default passwords established by the hardware manufacturers. After setting up a password, it is also essential to set up two-factor authentication as an additional security layer. You can also use strong endpoint security tools to secure your systems and network.

Encrypt and Backup Your Data

A formidable cyberthreat prevention measure incorporates two elements: Blocking access to confidential data and rendering the data useless peradventure it falls into the hand of cybercriminals. The latter can be actualized by encrypting the data. Encryption is one of the best solutions to protect against data breaches. Ensure you encrypt your customer information, employee information, and other essential business data.

Educate Your Employees

While banning your staff can be a security measure five years ago, the pandemic and the adoption of remote working have necessitated the “bring your own device(BYOD) approach. And security has to be fashioned in the light of this new development. One best way to achieve this is to plan a simulation on detecting and avoiding phishing links and fake websites.

It is also vital to foster a security culture in the workplace. For example, “If you see something —  say something.”

Conclusion

As new technologies continue to emerge, so will the sophistication of cyberattacks be. Trends such as hackers snooping on a conversation with Siri, Alexa will increase significantly. They can manipulate IoT devices and recruit them into an army of weaponized bots to take critical assets down, or shut down smart homes and cities. Threat actors can also leverage deep fake technology and synthetic voices in social engineering and various scams.

Thus, enterprises that want to stay protected always need to prioritize their people’s cybersecurity, data, and infrastructure.


Originally published at ReadWrite

The Future of Cyber Attacks – ReadWrite
Cyberthreats are growing in both scale and complexity and the need to secure critical infrastructure by businesses and public organizations has never been as urgent as now.
The Future of Cyber Attacks

https://bit.ly/3qL9bH8
https://bit.ly/3pPV5VE


https://guptadeepak.com/content/images/2021/12/Cyber-Attack-825x500.jpg
https://deepakguptaplus.wordpress.com/2022/01/04/the-future-of-cyber-attacks/

Thursday, December 30, 2021

3 Steps to Maintain Total Data Visibility

3 Steps to Maintain Total Data Visibility

We live in an era where data is progressively becoming the essential and the only fuel for thriving business success. And the rapidly growing volumes of data have raised several security concerns that can’t be overlooked. Though managing the in-house data stored locally wasn’t really a tough nut to crack, cloud computing has made data visibility and monitoring a more significant dilemma.

Undoubtedly, cloud monitoring is trickier than monitoring local data centers and private cloud environments, since the sheer volume of data from diverse sources can’t be easily monitored to derive valuable insights.

Hence, today’s security leaders should put their best foot forward to improve data security and enhance overall efficiency by following best data visibility practices. Let’s have a look at some of these fruitful practices.

What Is Data Visibility? Why Is It Important?

Before we inch towards understanding the aspects of data visibility best practices, let’s first understand what data visibility is.

Data visibility can be defined as the ease of monitoring, analyzing, and displaying data from different sources. Gaining data visibility within an organization is quite beneficial for multiple reasons since the gathered data can be easily used to make more informed business decisions.

Moreover, data visibility helps organizations improve capacity planning and identify the risks associated with data thefts and security breaches.

Apart from this, data visibility and monitoring also help remove network performance-related issues that further prevent application outages.

How to Maintain Total Data Visibility in Your Organization

Now that we understand what data visibility is and what its significance is, let’s look at three ways to maintain data visibility of business data.

1. Real-Time Data Reporting

Most legacy systems and programs are designed to deliver monthly or annual reports that offer valuable insights regarding the performance of the data stored in diverse areas.

However, reporting and analytics should be real-time since your business collects, processes, and stores data in real time.

A reliable analytics system can be deployed on your cloud servers to monitor data storage and provide real-time details related to data access to ensure your data isn’t in the wrong hands.

Once a business has complete control over data stored in different areas, it helps create winning strategies to ensure that consumer data is secure and organized.

2. Robust System

Admit it: The more users, the more data storage there will be, and hence the slower the systems will be.

The market is flooded with several reporting systems that work flawlessly for multiple users, but there’s a catch. Most of them weren’t designed in a way to meet the ever-surging needs of enterprises.

So, the need for a robust system increases quickly. Businesses must consider deploying a modern data analytics solution that seamlessly accommodates company-wide use systems and multiple end-user devices, including mobile, tablets, and laptops.

This would surely help in fetching better insights from data without hampering the overall user experience since the system is designed to scale even if the demand increases automatically.

3. Third-Party Tools

Unlike in-house deployment, enterprises can leverage third-party tools that can offer the deepest data visibility, which helps information security professionals to track every movement of their sensitive data, including business information and consumers’ details.

A number of tools can help organizations secure and monitor data stored on local servers or in the cloud and eventually report the IT administrators regarding any unauthorized access or movement of data in real time.

Moreover, these tools also offer protection against malware and other malicious attacks to ensure the highest level of security.

Final Thoughts

In a digitally advanced world where security breaches are becoming more common and sensitive information is being distributed across multiple servers, total visibility over the enterprise’s data becomes the need of the hour.

Since a small loophole may compromise crucial information, businesses should immediately consider choosing a reliable system or third-party tool that keeps track of data stored in diverse locations.

The ones relying on robust security systems can always ensure maximum security for their consumer data and their organization’s critical information.

The aspects mentioned above can help businesses secure their data and ensure their sensitive information isn’t compromised during storage and transit.


Originally published at Dataversity

3 Steps to Maintain Total Data Visibility – DATAVERSITY
Maintaining data visibility should be the biggest priority for any business embarking on a journey to secure data storage for the cloud.
3 Steps to Maintain Total Data Visibility

https://bit.ly/3mLQnWT
https://bit.ly/3FJDynm


https://guptadeepak.com/content/images/2021/12/AdobeStock_321999244.jpeg
https://deepakguptaplus.wordpress.com/2021/12/30/3-steps-to-maintain-total-data-visibility/

Wednesday, December 29, 2021

In-Store Tracking: Is It A Threat To Consumer Privacy?

In-Store Tracking: Is It A Threat To Consumer Privacy?

The amount of data/information collected by retailers is anticipated to surpass 175 zettabytes by 2025, according to Deloitte. With this much data being collected, the complications from even a fraction of this data and information being leaked or compromised by cybercriminals are severe.

Today, cybercrimes have increased to unprecedented levels. As digital crimes surpass a 600% increase, Deloitte warned that a single security incident that exposes even 5% of a retailer's data and information could result in complications such as $5 billion to $10 billion in civil fines apart from recovery costs and any other legal complications, in accordance with the CCPA. Retailers must implement safe data-collection measures that do not violate shoppers' privacy and do not pose any implications in the case of a data breach.

Implications Of Using In-Store Tracking Platforms

The tracking of retail shoppers is increasing at a rapid pace as retailers continue to leverage advanced tracking and monitoring technologies to record and study the behaviors of shoppers. Face analysis software, in-store high-tech cameras and sensors equipped with facial recognition technologies, as well as smart tracking systems that capture the voices of shoppers and track their geo-locations are some of the methods by which major retailers are capturing and tracking consumer behavior analytics and data.

Retailers using such tracking technologies to capture consumers' data usually justify the in-store customer tracking and data/information collection by giving reasons like:

• Learning more about the needs and wants of the shoppers.

• Understanding the behaviors of shoppers in order to develop more personalized and intimate relationships with them.

• Tailoring a customized/individualized shopping experience according to the preferences of each shopper.

• Enhancing the service delivery experience.

• Making the store operations more efficient.

In-store data and information collection may benefit retailers in many ways. However, the growing consumer privacy concerns as well as tightening privacy laws and regulations are posing a myriad of complications for retailers. A past Forrester survey that Quartz referenced (subscription required) revealed that roughly half of the respondents reported they would discontinue shopping in stores that track their behaviors. Deloitte also found that 55% of shoppers believe that retail stores are selling their data/information to third parties. The study also revealed that not all shoppers are tech-savvy and understand how retail stores use advanced technologies to track their behaviors and collect their data. This results in violating many data/privacy laws and regulations, as the collection of some data and information requires the consent of the individuals.

Many retailers also lack transparency about what type and how much data and information is being collected from shoppers and how it is being used. Lack of privacy policies, personalized marketing and notifications, lack of data/information usage transparency and other similar aspects can cause many implications for retailers.

Examples of such implications can include:

• Loss of customers' trust.

• Declining in-store shoppers' rate.

• Loss of revenue.

• Legal complications and fines by regulatory authorities.

• Reputation damage.

Key Data And Privacy Tips For Safer Data Collection

Retailers need to implement a comprehensive data protection strategy that includes appointing internal cybersecurity representatives, training employees across departments, vetting third-party partners, safely transferring data and deleting unnecessary consumer data. Here are some key tips for retailers to implement safer data collection.

• Secure payment methods. Setting standards and conventions for payment methods and third-party suppliers is essential for businesses. Due to the fact that customer payment information is regularly the target of data breaches in the retail business, retail firms are implementing more secure payment systems.

• Default encryption in transit and at rest. Data in transit, such as between a server and a mobile phone, is vulnerable to retail security hazards. Using data encryption, the data is protected while traveling and can only be decrypted at the endpoint with the decryption key. A delicate balance must be struck between privacy and simplicity of use while using encrypted data.

• Mandatory security training. Employees might also be the source of a data breach. Security training is often lacking in the workplace due to carelessness in the handling of sensitive data, team member incompetence and/or laziness. Customers' credit card data should likewise be restricted to employees, and employees should not be providing financial information via email. Additionally, corporations need to incorporate cybersecurity awareness into the culture of their organizations in order to avoid common threats like phishing emails.

• Enforce zero-trust security. Employees need to be verified, authorized and continuously evaluated for security configuration and posture before being permitted access to apps and data. As a result, a zero-trust architecture necessitates constant user and device monitoring and verification to ensure that the proper privileges and attributes are being used. Aside from that, retailers must periodically check on their staff members regarding how they handle file data and avoid malware. Moreover, employees should have limited access to websites outside of their everyday activities in order to reduce the risk of allowing a hacker to gain access.

As data/privacy laws and regulations become more strict and consumer-focused, retailers must implement fair and anonymous modes of data/information collection that do not raise privacy concerns and do not creep out the shoppers. Today's internet users are more aware and concerned about their data and privacy; therefore, retailers must respect shoppers' privacy and must cultivate a data-safe environment to boost business profitability and consumer loyalty.


Originally published at Forbes

Council Post: In-Store Tracking: Is It A Threat To Consumer Privacy?
The tracking of retail shoppers is increasing at a rapid pace.
In-Store Tracking: Is It A Threat To Consumer Privacy?

https://bit.ly/3pA7GMv
https://bit.ly/348gkJV


https://guptadeepak.com/content/images/2021/12/https---specials-images.forbesimg.com-imageserve-61af659747abf8fcb93e57db-3d-rendering-Neon-Colored-wavy-Abstract-background--futuristic-texture-design-for-960x0.jpg-fit-scale-1.jpeg
https://deepakguptaplus.wordpress.com/2021/12/29/in-store-tracking-is-it-a-threat-to-consumer-privacy/

Cookie-based vs. Cookieless Authentication: What’s the Future?

Cookie-based vs. Cookieless Authentication: What’s the Future?

Securing communications between a client and a server often requires credentials to identify both parties. That is where the different authentication techniques comes in. Two popular authentication methods are cookie-based and cookieless authentication. However, choosing any one of them depends on the organization's requirements. Both come with their benefits and challenges. This article will give a quick walkthrough of cookie-based and cookieless authentication along with their advantages and disadvantages.

Cookies are pieces of data used to identify the user and their preferences. The browser returns the cookie to the server every time the page is requested. Specific cookies like HTTP cookies are used to perform cookie-based authentication to maintain the session for each user.

The entire cookie-based authentication works in the following manner:

  1. The user gives a username and password at the time of login. Once the user fills in the login form, the browser (client) sends a login request to the server.

The server verifies the user by querying the user data. If the authentication request is valid, the server generates the following:

  • A session by utilizing the user information
  • A unique ID, known as the session IDThe server then passes the session ID to the browser that keeps it. The server also keeps track of the active sessions.
  1. The browser has to submit this generated session ID while sending a subsequent request. Every time the server validates the session ID. The session ID helps the authentication process identify the user and provides access accordingly.
  2. When the user logs out of the application, the session gets destroyed from both client (browser) and the server. It discontinues the authentication process from happening again through the respective session ID.
  • Availability: In cookies-based authentication, cookies can be made available for an extended period, maintaining a session for a long time.
  • Easy Configuration: Websites can deliver cookies by configuring them as per requirement. For example, a website can send cookies that will expire as the users close the browser tab. It is also possible to configure cookies for a specified length of time on the client-side.
  • User-friendly: Cookie-based authentications are simple, and the cookies used in this method are user-friendly. Users can choose what to do with cookie files that have kept user credentials. All modern browsers come with settings to clear the cookies. Users can find cookies in the hard drive and delete them manually.
  • Vulnerable to CSRF: Cookie-based authentications are prone to Cross-site Request Forgery (CSRF) attacks. Hence, they often require additional security postures for protection.
  • Less Mobile-friendly: Cookie-based authentication does not work well with all native applications.
  • Limitations: There are certain limitations and concerns such as size limit (not more than 4KB of information per cookie), browser limitations on cookies, user privacy, etc., come with cookies and cookie-based authentication.
  • Less Scalable: Cookie-based authentication is less scalable, and the overhead rises when the user count increases on a particular site.

What is Cookieless Authentication?

Cookieless authentication, also known as token-based authentication, is a technique that leverages JSON web tokens (JWT) instead of cookies to authenticate a user. It uses a protocol that creates encrypted security tokens. These tokens allow the user to verify their identity. In return, the users receive a unique access token to perform the authentication. The token contains information about user identities and transmits it securely between the server and client. The entire cookieless authentication works in the following manner:

  1. The user logs into the service by providing their login credentials. It issues an access request from the client-side by sending the credential and API key (public key) to the application server.
  2. The server verifies the login credentials that checks the password entered against the username. Once approved, the server will generate a unique session token that will help authorize subsequent actions.
  3. This access token is sent back to the client via URL query strings, post request body, or other means. The server-generated signed authentication token gets assigned with an expiration time.
  4. The token gets transmitted back to the user's browser. On every subsequent request to the application server or future website visits, the access token gets added to the authorization header along with the public key. If there is a match from the application server against the private key, the user can proceed. If a given token expires, a new token gets generated as an authentication request.

Benefits of Cookieless Authentication

  • Scalable and Efficient: In cookieless authentication, the tokens remain stored on the user's end. The server only needs to sign the authentication token once on successful login. That makes the entire technique scalable and allows maintaining more users on an application at once without any hassle.
  • Better Performance: Cookie-based authentication requires the server to perform an authentication lookup every time the user requests a page. You can eliminate the round-trips with tokens through the cookieless authentication technique. In cookieless authentication, the access token and the public key are added to the authorization header on every page request.
  • Robust Security: Since cookieless authentication leverages tokens like JWT (stateless), only a private key (used to create the authentication token) can validate it when received at the server-side.
  • Seamless Across Devices: Cookieless authentication works well with all native applications. Tokens are much easier to implement on iOS, Android, IoT devices, and distributed systems, making the authentication system seamless.
  • Expiration Time: Usually, tokens get generated with an expiration time, after which they become invalid. Then a new token needs to be obtained for reauthentication. If a token gets leaked, the potential damage becomes much smaller due to its short lifespan.

Challenges with Cookieless Authentication

  • Single-key Token: One of the significant challenges with cookieless authentication is that these access tokens rely on just one key. Tokens that use JWT leverages a single key for authentication. If the developers/administrators handle the key poorly, it can lead to severe consequences that can compromise sensitive information.
  • Data Overhead: Storing a lot of data increases the overall size of the token. It slows down the request impacting the overall loading speed. This slowing down ultimately hampers the user experience. Thus proper development practices need to be followed, regulating minimum but essential data into the token.
  • Vulnerable to XSS and CSRF: Cookieless authentications are susceptible to XSS and CSRF attacks. So, the best practice is to have a short expiration time for access tokens. Keeping a longer expiration time might allow the attackers to hijack the access token and use it to gain unauthorized authentication.

How does LoginRadius have Native Support for Cookieless Authentication?

LoginRadius provides multiple methods to implement a cookieless login workflow leveraging industry and security best practices. As a consumer-centric Identity platform, LoginRadius ensures that modern implementation methodologies comply with the changing security landscape. The cookieless authentication workflows detailed below are systems that LoginRadius has developed support for even before the recent browser-based privacy policies and are a core part of the LoginRadius platform.

LoginRadius APIs

The LoginRadius API has been architected and designed to function as a cookieless authentication system. Once authentication occurs, a session token gets returned to the requesting client in the form of an access token which can be leveraged to take further authorized actions against the Consumer account. It is a core part of the LoginRadius authentication workflows, and APIs developed based on Oauth 2.0 protocols.

These APIs provide flexibility in generating access tokens based on consumer authentication requests and are automatically validated and signed leveraging the LoginRadius API Key and Secret. Detailed API documentation is available here.

JSON Web Tokens

In addition to the LoginRadius APIs, JWTs are a standard method to handle cookieless login. Once authentication is completed and verified, a signed token can be generated(leveraging LoginRadius APIs) to pass the consumer session to the client.

JWTs are a standard industry mechanism leveraged by various service providers and tools, making them ideal for interoperability with multiple applications. Find additional details on how to use JWT as part of your authentication workflows here.

Additional Options

In addition to the above two options, LoginRadius provides flexibility and support for various authentication and authorization standards that support a cookieless authentication approach. Outbound authentication workflows such as OIDC and Oauth 2.0 allow for a modern standardized approach to authentication.

These are industry-recognized and recommended authentication and authorization protocols that comply with security and privacy best practices, including supporting a cookieless authentication approach. Check out our dedicated documentation on outbound workflows.

Conclusion

Cookieless authentication can facilitate more secure and scalable authentication. You should decide how to authenticate consumers considering your requirements and the benefits and challenges of cookie-based and cookieless authentication.


Originally published at LoginRadius

Cookie-based vs. Cookieless Authentication: What’s the Future?
Understand how cookie-based and cookieless authentication methods work. And learn their major differences, advantages, and disadvantages.
Cookie-based vs. Cookieless Authentication: What’s the Future?

https://bit.ly/3pzQWF0
https://bit.ly/3eyPsoi


https://guptadeepak.com/content/images/2021/12/coverImage-1.png
https://deepakguptaplus.wordpress.com/2021/12/29/cookie-based-vs-cookieless-authentication-whats-the-future/

Palo Alto Networks + CyberArk: The $25 Billion Deal Reshaping Cybersecurity

Deal Overview Transaction Details : Palo Alto Networks announced on July 30, 2025, its agreement to acquire CyberArk for $45.00 in cash ...