Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Wednesday, November 20, 2024

SSH Tool Weaponized

 One of the more interesting facets of this industry is there’s always something new to learn. The

creativeness and inventive nature shine with the new tools introduced for attacks and subsequently to

improve defenses. One area that hasn’t seen many new tools created has been with SSH. This is widely

used and continue to be a primary security method.

The new security tool is SSH-Snake. This is an open-source tool. Originally released in January 2024, the

design was to work through a network using SSH private keys. This is done automatically. The program

through its work then creates a thorough network map and its dependencies. The result allows the

security staff to understand vulnerable points where an attacker could use SSH and private keys.

You can see the usefulness of this for the company. Like any tool, there are positive and negative uses.

The negative side of the coin here is the tool was weaponized. This was modified to self-modify and

replicate itself through the network. The upgraded tool has been coded to find locations where

credentials are generally kept and analyzes the shell history files.

As an additional aspect to circumvent security, the tool is fileless. While this is newer, it allows for an

increased level of difficulty in detecting the tool and allows it a greater level of flexibility. This is still a

tool to be used to improve your network security stance. The weaponized version should be on your

radar.

Oil Pipeline Targeted

 Companies are targeted for attack for various reasons. One predominant reason continues to be

revenue. Without the possibility of a payout, there isn’t much reason for a group to spend the resources

to attack the target.

One set of high value targets are pipelines. A few years ago, there was an issue with a pipeline in the US

(i.e., Colonial Pipeline in 2021). Another pipeline has been compromised with the same form of attack,

but in Canada. In this case, the Alpha V group successfully compromised the Trans-Northern Pipeline’s

systems in three provinces and applied the standard ransomware. They were able to exfiltrate

approximately 190GB of data. The successful attack occurred in 2023.

Unlike the US attack, there were no unplanned interruption for the pipeline’s operations. Unfortunately,

not much has been published as to the attack method used, depth of network penetration, and type of

data. Portions of this information could be helpful as to how best to secure other’s networks. If any

nuances would occur with this attack.

We must continue to be ever vigilant. This includes having internal systems checked more than once

over time.

Supply Chain Lesson #587

 Bank of America is massive with branches throughout most of the nation and other countries. Being

such a large operation, the bank could not reasonably maintain all aspects of their operations from a

central hub. The vast expanse of this would increase their FTEs significantly. This standard operating

procedure is used in most industries.

One area BoA uses this is with their service providers. Infosys McCamish Systems (IMS) was

compromised on or around November 3, 2023. The next day in the chronology was November 24 when

IMS notified BoA the data with their deferred compensation plans may have been compromised. This

included for the individuals their name, address, social security number, date of birth, and financial

information (account number, credit card number, etc.). For this compromise, approximately 57,028

clients were impacted. This ransomware attacked was claimed by LockBit.

This set of data is perfect to sell and be abused. With this the attackers or whomever purchases the data

has ample people to attack.

Authentication became much more difficult

 We all understand the issues phishing has caused over the last few years. There have been countless

compromises targeting email systems and pivoting off these into other areas. When we thought, this

was starting to get controlled at some level, there’s a new wrinkle.

A finance worker of a multi-national firm attended a video conference call, just as so many of us do

every day. With this conference call, the finance worker was directed by the Hong Kong company’s

“Chief Financial Officer” to pay $25M. There were other “staff” in the call also. The message prior to the

meeting was a bit suspicious as it asked for the meeting to discuss a secret transaction.

Since other staff, who the finance worker recognized, were in the meeting, it seemed legitimate. The

$25M USD or $200M Hong Kong dollars were transferred. Well, not everything was as it seemed. The

CFO and other staff in the meeting were actually deep fakes. On the bright side, the police had arrested

six others with scams much like this.

Technology will find a way around the defenses and detection tools we put in place. We’ll improve the

defenses and tools only for the cycle to continue. In these instances where the transaction may not

quite feel right, the suspicious mind should overrule natural tendency of “It should be fine.” Our staff

training needs to be updated regularly to keep us with the new technology and attacks. Granted this

nuance is difficult to filter, but the human factor is there to apply common sense.

Sunday, March 24, 2024

Autonomous Vehicles (AVs) have a Substantial Attack Surface

 This is a fantastic age to live in. We have vehicles that notify us when another vehicle is near us, when we’re too close to the vehicle in front of us or the side of the road, when we are sliding inadvertently into the next lane, and log our activities. This is a massive step from the vehicles of 10-15 years ago. The sensors installed within the vehicle offer cutting edge technology for the driver. These also have improved safety for the occupants along with others on the roadmap. Have pentested an AV, I can attest this is a delight.

While I sing the praise of the AVs, there are issues. This has potential threats to the AVs due to the platform, sensors, and OS. These are all new attack surfaces and vulnerabilities. If exploited, these provide an opportunity for disaster. The new threats come from various sources. These new machines, as they are heavily dependent on software, are open to remote attacks. If successful, modules could be compromised. Depending on which one is targeted and breached, there are varying levels of criticality. For instance, steering or brake ECUs are relatively serious.

Data is the new gold and oil. This is especially the case with vehicles. Each collects a mass amount of data from general operations and the sensors. The data may be used in multiple scenarios.

While sensors have improved vehicle operations and safety, there are potential issues here also. The sensors could be spoofed, providing false data to the vehicle and data processing. The fake data could provide a false set of data for the surroundings. This could lead the vehicle on the wrong path.

While this could provide for issues, there are preventive measures to the taken. The software may be hardened, making these more robust. Patching is also pertinent. This occurring regularly limits the attack surface. Encryption should be used with vehicles data and communication. This limits the weak points which are targets.

  

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Medical Device Connectivity

 

With our new technology advancing so rapidly on different fronts, the nuances in applications are growing. One of these is connectivity. Most of the public is aware of connectivity in vehicles. We see this as we’re driving with the infotainment system, making calls, or following a map. This is not by far the only industry embracing connectivity.

Another is the medical device field. Globally, this is estimated to triple its value by 2028. This may take the form of home health monitors, or cardiac monitors reporting data to the backend or receiving updates.

There are several factors driving this massive increase. One of these includes telehealth. Our population has endured much through the pandemic and post-pandemic. This has shaped how we shop, gather information, and utilize healthcare. The need and want for home healthcare has assisted in the growth. If the patients didn’t want it, there wouldn’t be the need or market for this. Related to this is remote patient monitoring. This may involve cardiac or other monitoring. This advance allows the patient to stay in their home while the device collects the data and uploads it to the doctor or other device.

While this works great for the patient and doctor, this also adds to the attack surface and provides another point to test. This is another area to secure, test, and maintain through the SDLC. 

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


New International Medical Device Standard

 With standards, regulations, statutes, etc., many feel this is a speedbump for their product. In the interest of the field, industry patient safety, and security these are a great idea. Without these in place, medical device cybersecurity could become like the Weld West with every entity doing their own thing, not following any guidance.

The FDA has recognized three new standards focused on medical device software security. These cover the total product lifecycle of medical device cybersecurity, data logging, software use, and reasonable software testing.

The first noted standard was ANSI/AAMI 2700-2-1. This standard is focused on medical device software’s safe usage in the integrated clinical environment (ICE). The specific usage is for data loggers to appropriately collect data in these systems. This includes the recording, data, storage, and playback for the data. The data usage would be for safety, quality assurance, and forensic analysis.

The second standard was ANSI/AAMI SW96:2023, which provides guidance on methods to manage security risks. Medical devices present a unique security risk. The standard addresses several security areas to identify threats and vulnerabilities and the controls to put in place to mitigate these.

Lastly ISO IEC IEEE 29119-1 provides guidance on germane topics in the field including software.

These standards provide additional guidance and a framework to further the safety and security for the products. By adding these into our security tools, the attack surface is decreasing, and potential attacks are mitigated.

 Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


IoT Devices Need Cybersecurity Attention

 IoT devices have evolved and expanded into commercial, and consumer uses. These appear throughout people’s homes with refrigerators, ovens, thermostat, light bulbs, and many other pieces of equipment.

Smart thermostats have become more prevalent in residences in the last few years. These are a nice addition in that these are trained to learn your optimal temperature, when you on average are in the house, and other useful assists.

While these have beneficial aspects with this, let’s not forget about detriments. When smart thermostats have not included cybersecurity through their dev cycle and SDLC, you can be answering many questions from clients, federal agencies, and other interested persons and stakeholders when something goes wrong (i.e., a significant compromise).

Recently two models for smart thermostats have been noted to have multiple security vulnerabilities. When successfully exploited, the bad actors would be executing the code they wanted on the device. The device could be weaponized with modified or rogue firmware.

The vulnerability allows an unauthenticated connection from a local network. The attack point is the WIFI microcontroller. This acts as a network gateway. This has been corrected, but only after the vulnerability had been known and open. This emphasizes the need for cybersecurity to be applied through the dev cycle, with security being at each gate. This also requires staff being comfortable in working with embedded systems, and all the nuances associated with these. Embedded systems require a different set of skills, different than the traditional IT.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


 

Standards Assist with Medical Device Cybersecurity

 The technology expansion is pushing the options for medical device connectivity. The options and configurations used to be relatively limited. Connectivity continues to grow in its different forms. While this is great for the industry, doctors, and patients, applied cybersecurity also needs to be addressed in every step of the way.

These connected devices connect to the network using Bluetooth, BLE, or WIFI for communications. If configured correctly and cybersecurity being incorporated throughout the process, generally this should work well. To assist with this and provide guidance there are standards for medical devices (e.g., IEC 62304, ISO 14971, and FDA guidance). These provide directed guidance. The key though is documentation. The documents need to show not only you have secured these standards but have implemented them. Part of the plan and implementation includes the product’s risk analysis. I mention this specifically is the risk analysis or TARA is the bedrock for risk analysis. When thorough this will show the vulnerabilities, which need to be addressed. This system’s review will build a solid cybersecurity plan and product for your customers.

 Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511



Saturday, March 9, 2024

Energy Sector's Criticality

 

The attacks on the energy sector have been increasing. This is a critical vulnerability for the nation. A successful attack on, for example, the electrical grid would be a disaster from every view. I still remember the time when the grid in the NE region of the US went down in the early 2000s. This was unintentional yet if you lived in the region and was out of power, both consumers and commercial clients, the effect was devastating.

Looking to recent events, there have been attacks that continue to show the vulnerabilities and the effects from these, both financial and human. We can remember the 2021 Colonial Pipeline ransomware attack. The company experienced large financial losses and disrupted their operations. On the attacker’s side, they removed without authorization (i.e., stole) approximately 100GB of data and received $4.4M. A significant portion of this was retrieved, however overall, this had direct negative impacts on the business.

This isn’t a US issue, but global. In 2022, European oil refining ports and storage facilities were targeted. This included 17 terminals. This industry needs the blue team cybersecurity attention. Without this, we will have direct issues affecting our daily lives. 



Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Hyundai works through breach

 

From the published accounts, there seems to be an uptick in attacks against the automakers. This could be focused on their sales platform, data warehouse, R&D, or other areas holding some form of data. Nissan was a recent victim as Hyundai India is.

Recently the automaker published a breach through their defenses. The breach allowed the attacker(s) in and allowed them to find data or other useful (e.g., expensive) data. The attacker’s focus for this successful attack had been sensitive customer information (i.e., names, addresses, email addresses, telephone numbers, vehicle specifics, and other client data points) for Hyundai India customers only. A portion of the data is very useful. Other data (e.g., registration numbers, colors, engine numbers, and mileage) could also be used for fraud or other cases of misuse.

This has been corrected; however, the events do provide guidance for us. Even if the business is large and global, there is still the need for SAST and DAST. There are areas and dependencies the programmers will do their best to account for and state it’s good, but it just takes one or two vulnerable areas in all the code to create an issue and RUE (Resume Updating Event). 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Capital Health Breached

 

No CISO wants to receive the urgent call from the SOC informing them of an issue. This may take the form of a request to make a missed vendor payment by month end or there’s a user that keeps on clicking on the internal phishing campaign emails. The conversation you don’t really want revolves around the defenses being breached. That is clear and immediate project.

Capital Health (NJ) had such an occurrence. LockBit 3.0 claims to have compromised the defenses and liberated over 10M files or over 7TB of confidential medical data. The estimated value of this was $250k. The group did have a bit of their conscious during the attack. They didn’t encrypt the data which quickly would have interfered with the patient care. It’s notable though LockBit 3.0 did not post evidence to document this. While this is the case, there were network outages near the end of December due to a cybersecurity incident. This is not a new event, as too many medical facilities have experienced this on some level.

There have been minimal details as to this which is the standard model. This does highlight the need for this industry to be hyper vigilant and maintain your info cybersecurity toolsets. Periodically when your contract is nearing renewal for the tools, scan the other vendors for their offerings and pricing. Running a PoC and going through the vendor vetting can take time, but it may be well worth it. 


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Product Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) |

Supply Chain Cybersecurity Review 

Reverse Engineering


 charles.parker@mielcybersecurity.net 810-701-5511


Wednesday, February 14, 2024

Cybersecurity Costs

 

I have consulted with a company recently. They were reviewing the ISO27001:2022 certification. This, depending on the circumstances, could be a heavy lift or not too bad. This is entirely dependent on the environment. After the initial review and recommendation, the first comment was the business didn’t have the budget for the tools, staffing or anything. This left me a bit confused, as the certification process is not inexpensive.

This reminded me of the budget process. The C-level and senior management don’t at times understand security’s role. They instead think like an accountant and try to arrive at an ROI (Return on Investment). This has the propensity to be very difficult. When you try to commoditize this, there are problems.

When I hear this, my thoughts run to how much would a network compromise cost with the additional ransomware thrown in for good measure, even with cybersecurity insurance? How much would it cost for your connected medical devices to be breached and malicious code put in the firmware, with three or four patients feeling the effects?

There are the direct costs, of course, but also the indirect cost of reputational risk. These are a few things to think through. 

Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) 


 charles.parker@mielcybersecurity.net 810-701-5511



Security by Obscurity

 

During the budgeting cycle, departments may ask for increases in their respective budget, padding it or to accommodate capital purchases. When the senior management does not recognize the importance of security, the thought may float through their mind of what if we do nothing? After all, nothing has happened.

Well, nothing has happened…yet. The healthcare industry is targeted for many reasons and there are many options as to the individual targets, methods of attack, and other facets. A breach in this environment is horrific operationally with systems shut down for days or weeks, ERs shut down, patient data exfiltrated, etc. There is also the potential for patient mortality being directly attributable to the breach. Financially this can be a nightmare as the healthcare provider has to quickly address the issues and contract with a forensic firm to review the breach, what was accessed, and everything else with the issue. This is not cheap.

By ignoring cybersecurity and thinking you can get through the next cycle without adequately addressing this, the healthcare provider is doing everything they can to set themselves up for failure on the business, functional, and patient care side.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture


Red Team Pentesting   |   HW & SW BoMs  |   CBoM  | 

Vulnerability Management   |   Tabletop Exercises (TTX)   | 

Embedded Systems Architecture   |   Threat Intelligence   | 

TARA (Threat Assessment and Remediation Analysis) 


 charles.parker@mielcybersecurity.net 810-701-5511