The recent surge in cryptomining is providing cyber criminals with more vectors to attack, at the expense of legitimate users. This year has seen a huge increase in the deployment of numerous malwares, with cryptominers as primary or secondary payloads. Cryptominers are becoming easy targets, that allow attackers to go a step further to disguise themselves as the miner in the form of a flash update. Palo Alto Networks reported a list of collected samples, some dating back to August 2018[1]. The author further adds that installers from the Adobe website were legitimate, and the malicious ones were mostly Windows…
Lateral Movement Definition: Lateral movement is a technique used by cyber attackers to infiltrate and move through a network with the intent of obtaining secure data. The Cause The term “Lateral Movement” has been around for a little over four years and was in the news when ransomware like WannaCry and APT’s like APT28 and APT29 used lateral movement techniques. Most often an attacker may not have direct access to a machine or resource on the internal network, which the attacker considers a prized trophy. The prized trophy may be the domain controller, a machine hosting confidential information, or the…
Ransomware is a form of malicious software that latches onto a system and encrypts the files within it, making them inaccessible to the user. The attackers behind this malicious activity typically demand payment in terms of currency (crypto or cash) in return for the keys to decrypt the files. A recent ransomware which has become viral since January 2018 is named GandCrab. This ransomware is believed to be distributed as a Ransomware-as-a-Service [2,3]. GandCrab initially differentiated from other ransomware by demanding a ransom in DASH [7] cryptocurrency. The developers behind GandCrab have been continuously updating and releasing improved versions, with…
Every manufacturer is concerned about the potential risks associated with cyber-crimes. If their data are stolen, it can lead to financial losses in sales, fines and monetary judgments against them; not to mention, the loss of customers and brand loyalty. In 2017, there were over 53,000 security incidents and 2,216 confirmed data breaches. This is according to the 2018 Data Breach Investigations Report (DBIR) by Verizon. The report goes on to state, the most common access among all security breaches (73 percent of breaches) are those perpetrated from outside the organizations through the wide area network (WAN). Enterprise WANs, with…
Internet links to wide area networks (WANs) are often a primary target for cyber-crime in every industry. The healthcare industry deals with particularly sensitive consumer data. Security breaches pose many risks for healthcare providers, including legal liability, revenue loss and erosion of patient trust. To minimize the threat of security incidents and breaches, IT teams are looking for preventive measures to ensure that security is an integrated part of the WAN. The preservation and safekeeping of healthcare data for doctors, clinics and hospitals, and their patients are essential elements to contemporary security posture. Patient health record protection has a direct…
Once again, recently we heard about an enterprise that succumbed to a major security breach. Shipping giant COSCO lost email and IP phone connectivity throughout their entire US network. And without finding the cause, the company shut down networks within other regions. This example, along with countless others, solidifies the point that distributed networks and security are inherently symbiotic. COSCO says the incident was a network breakdown that led to the ransomware infection. While some are arguing it was the network, others say it was a Malware security breach. The COSCO event was not only a network breakdown, it was…
Typically, WAN solution vendors talk about performance in terms of speeds and feeds. But, I like to think about performance as it relates to all aspects of connectivity. This includes speed, control, visibility, reliability, ease of deployment and monitoring, and of course security. I think about it in these terms because each of these areas are controllable by the right holistic SD-WAN architecture. Unfortunately, the accumulation of multiple disparate routing and switching devices, including firewalls, intrusion detection and threat mitigation, makes it difficult to obtain network visibility and correlate real-time events that can degrade or disrupt performance. With Secure SD-WAN,…
One of the biggest sporting extravaganza of the world is currently on in Russia. The 2018 FIFA World Cup, which commenced on the 14th of June 2018, will see 32 teams compete across 64 games and four adrenaline and emotionally packed weeks in Russia. Let’s begin with some eye-opening statistics. According to a number of sources, the 2014 World Cup was watched by 3.2 billion people worldwide, making it the largest ever in FIFA history. In total, 280 million people watched matches online or through a mobile device. Experts expect that the viewership numbers in 2018 will see an increase…
“Security by design is a mandatory prerequisite to securing the IoT macrocosm, the Dyn attack was just a practice run.” – James Scott, Sr. Fellow, Institute for Critical Infrastructure Technology. Remember the 21st of October 2016? A series of carefully mastered DDoS attacks paralyzed internet services on the East Coast, affecting the businesses of market giants like Amazon, Netflix, PayPal, Starbucks, Verizon, Visa – the actual list is longer, and pretty impressive. The US Department of Homeland Security launched an investigation and it revealed that the extremely sophisticated attack was a botnet that spread through a large number of Internet…
Like many industries, the insurance sector increasingly depends on new technologies to provide better service while reducing operational costs, with the ultimate goal of creating an exceptional customer experience. Mobile apps, cloud-based services and video chat are just some of the ways insurance companies are using technology to reach their customers and decrease their overhead. Consider, for example, the traditional method of filing a claim for an auto collision: a police report is filed, a copy of which must be forwarded to the claims department of the insurance company; photos of the damage are needed, which means the adjuster must…
Subscribe to the Versa Blog