Archive for June, 2023

Reddit To Moderators: Your Subreddits Will Not Stay Private

Posted in Commentary with tags on June 29, 2023 by itnerd

Steve Huffman is clearly desperate as he’s now made it clear that subreddits that are set to private are going to reopen their communities this week:

The company has given moderators deadlines to lay out their plans for reopening but said that they can’t stay closed. The timeframes given generally indicate a deadline of sometime Thursday afternoon. Reddit was vague about the exact repercussions but seemed to suggest this was the final warning stage. “This community remaining closed to its [millions of] members cannot continue” beyond a the deadline, the admin (Reddit employee) account ModCodeofConduct wrote in a note to one of the biggest Reddit communities that’s still private.

I am guessing that the API protests have hurt Huffman and company. Thus they’re going to the nuclear option. Seeing as Minecraft has ditched Reddit, that’s not a smart plan as this move will push more people and communities to abandon Reddit. And then what will Huffman do? I seriously think that he believes that he can bend the will of others. But that’s not the case. And he’s going to find out soon enough.

Cyware Gets $30 Million In Series C Financing

Posted in Commentary with tags on June 29, 2023 by itnerd

Cyware, the leading provider of AI-powered Cyber Fusion platforms for enterprises and MSSPs, and automated threat intelligence sharing for information sharing networks, today announced a $30 million Series C financing round led by Ten Eleven Ventures, a leading multi-stage investment firm specializing in cybersecurity. Also participating are previous investors including Advent International, Zscaler, Emerald Development Managers, Prelude (the venture practice at Mercato Partners) and Great Road Holdings.

The Series C financing comes as Cyware has experienced strong year-over-year growth propelled by robust market adoption, excellent customer retention, and extraordinarily large market access. Since Series A financing, Cyware has shown growth of 6x and consolidated its position as an industry leader for threat intelligence automation, security orchestration, and collaborative threat response solutions. Earlier this year, Cyware achieved FedRAMP Ready status for its Cyber Fusion platform and was named one of the most innovative and promising cybersecurity companies by JMP Cyber 66, as well as being recognized in the 2022 Deloitte Technology Fast 500 as one of the Fastest Growing Technology Firms in North America.

Cyware’s cloud-based platform is leveraged by top Fortune 1000 and MSSP security teams to transform their legacy SOCs into Cyber Fusion Centers. The platform seamlessly integrates the AI-powered threat intelligence platform (TIP) with data orchestration and workflow automation (SOAR), to facilitate and synchronize actions between cloud and on-premises security tools and technologies. This enables security teams to connect the dots on emerging threats by correlating actionable threat intelligence with detection, threat hunting, vulnerability management, and incident response operations. Cyware’s Cyber Fusion platform is modular, and the underlying TIP, SOAR, and Collaborative Threat Response components can be leveraged in combination or individually by security teams providing them greater flexibility in transforming conventional SOCs.

The Cyware platform has become the backbone of global Threat Sharing Networks. Almost all major ISACs (Information Sharing and Analysis Centers), ISAOs, and CERTs use Cyware’s platform to automate threat intelligence sharing, analysis, and actioning for more than 30,000 enterprise members and government entities. The platform also enables large conglomerates, industry groups, and private communities to activate and share threat intelligence with their distributed businesses, clients, and suppliers, and benefit from automated collective defense against ransomware, supply chain attacks, and zero-day vulnerabilities.

Cyware plans to leverage this new round of funding to fuel further growth and accelerate channel business and strategic alliances while expanding its global footprint.

Twitter CEO Calls For “Hand To Hand Combat” To Get Advertisers Back

Posted in Commentary with tags on June 29, 2023 by itnerd

Despite what Elon Musk says, advertisers are not returning to Twitter. Or put another way, he lied about advertisers returning to the platform when he said that here to the BBC. That’s going to be job number one for Twitter CEO Linda Yaccarino to fix. And here’s how she’s going to do that:

Linda Yaccarino told Twitter staff they need to deploy “hand-to-hand combat” to win back advertisers who abandoned the platform, the Financial Times reported.

The new Twitter CEO reportedly made these comments in a meeting with the global sales team earlier this month, where she spoke about the need for hard work to convince companies to advertise with the platform, per the FT.

“Hand-to-hand combat” apparently referred to persuading advertisers in person rather than from behind a desk, a person with knowledge of the matter told the newspaper.

This has the smell of desperation. As in the type of desperation where things are so bad, that she has to resort to rhetoric like this to try and move the needle in any significant way. That to me validates that Twitter has really been wounded by the actions and behaviour of Elon Musk. And you have to wonder what will happen next if “hand to hand combat” doesn’t work.

Place your bets now.

Researchers Discover A New GuLoader Malware Campaign

Posted in Commentary with tags on June 29, 2023 by itnerd

Morphisec Threat Labs has discovered and documented a new GuLoader malware campaign. Here’s the key points that they found:

  • Since April, researchers have been tracking a campaign predominantly targeting legal, healthcare and finance organizations.
  • The analysis comes on the heels of dozens of confirmed attacks across Morphisec’s customer base where this GuLoader technique bypassed the customer’s EDR and next-gen A/V.
  • Researchers note that GuLoader is appearing more frequently as a malware loader in phishing campaigns and is now one of the most advanced downloaders in use.

You can read the full analysis here: https://blog.morphisec.com/guloader-campaign-targets-law-firms-in-the-us

Critical Insight Introduces PartnerFirst Program

Posted in Commentary with tags on June 29, 2023 by itnerd

Critical Insight, the Cybersecurity-as-a-Service provider specializing in helping critical organizations Prepare, Detect, and Respond in today’s threat environment, announced today the Critical Insight PartnerFirst Program, which has evolved with new features and significant enhancements to recognize and reward partners’ expertise ensuring partners feel supported and invested at each level of the program.

The cybersecurity landscape continually evolves, demanding organizations equip themselves with partners that invest in people, technology, and domain expertise to remain at the forefront of threat detection and management. Purpose-built for today’s security ecosystem, Critical Insight’s Cybersecurity-as-a-Service (CaaS) offers affordable, comprehensive cybersecurity services.

New features of the Critical Insight PartnerFirst Program include:

  • The updated pricing structure for Critical Insight’s Managed Services Providers (MSPs) channel.
  • Every partner is assigned a Sales Team, including an Account Director, Customer Service Manager, and Security Strategist, to help enable, train, and work through opportunities together.
  • Co-marketing opportunities.
  • Improved PartnerFirst Portal for registration, news, events, training, and co-branded documentation.

Agents, distributors, MSPs, MSSPs, system integrators, and Value Added Resellers (VARs) are included in the PartnerFirst program based on differing contract vehicles for Resellers versus Referral agreements across all industries, particularly healthcare, education, manufacturing, utilities, and the public sector.

The PartnerFirst program established an innovative tiering framework that provides partners access to various financial and business benefits. The program has evolved to ensure partners feel supported and invested, whereby every partner is assigned a sales support team directly responsible for helping partners increase opportunities and win deals.

Partners enter at the Base Tier and, based on aggregate licenses across their customer base, can achieve dramatic pricing discounts, and new incentives in the year’s second half.

Critical Insight is dedicated to partner success that is customer-centric, effortless to do business with, and provides compelling value to address cybersecurity best practices, proactively monitor, and enable fast remediation.

For more information on the Critical Insight PartnerFirst Program, please visit https://www.criticalinsight.com/about/partners.

Reddit Has A New Problem… Minecraft Makers Ditch Reddit

Posted in Commentary with tags on June 29, 2023 by itnerd

Steve Huffman must be rethinking his life choices at this point as his problems with the API protests that he started are growing. Today’s problem is that the makers of Minecraft have decided to ditch Reddit for greener pastures:

The makers of the popular game Minecraft say they will no longer share official content on Reddit following the changes being pushed through by the site’s management.

And:

Now it seems Mojang—the Microsoft-owned developer of Minecraft—is siding with the strikers. “As you have no doubt heard by now, Reddit management introduced changes recently that have led to rule and moderation changes across many subreddits,” reads a post made by Mojang’s Java Tech Lead.

“Because of these changes, we no longer feel that Reddit is an appropriate place to post official content or refer our players to.”

Mojang previously used to post technical detail such as game changelogs to Reddit, which list new features or bug fixes made during game updates. Mojang is now encouraging players to instead visit the Minecraft feedback site or pay attention to other social media channels.

Minecraft’s popularity is sure to make this a big story. Which means that this will be a big headache for Steve Huffman. The question is how Huffman will react to this. That will be interesting to watch as he doesn’t come across as a very rational person.

The Petro Canada Cyberattack Could Cost The Company In Multiple Ways… And Who’s Behind This Cyberattack?

Posted in Commentary with tags on June 28, 2023 by itnerd

We are now in day six of the Petro Canada/Suncor cyberattack. The app is still down, and stations are still only accepting cash. While the company admits that there has been attack, few details beyond what I have had outlined are available. Though there are rumours that it is worse than what we know. Whatever is going on, it’s going to cost them a lot in multiple ways:

  • It will cost them in terms of their reputation: Petro Canada is the nation’s largest gas station. And people not being able to fill up in their stations because of this cyberattack will negatively affect their reputation the longer this goes on. And many will likely going to think twice about using Petro Canada after this situation is resolved. Whenever that is. On top of that, many will be wondering if their personal information is safe. At this time it isn’t clear if their customer’s personal information is at risk or not. That’s really bad from a reputation standpoint.
  • It will cost them in lost sales: You have to wonder how many people did what I did which is to go elsewhere because Petro Canada doesn’t accept credit and debit cards? The longer that this goes on, people will get used to going to a gas station other than Petro Canada. And the harder it will be for Petro Canada to get them to return to their stations and spend their gas money there.
  • It will cost them in terms of spending to fix this: IBM put out a study that says that the global average cost to companies of a data breach hit an all-time high in 2022 of US$4.35-million. And in the United States, the average cost of a data breach in 2022 was US$9.44-million. That’s not cheap. The same report said that in 2022, it took an average of 277 days for companies to identify and contain a breach. The bottom line is that this is going to get expensive in a hurry.

Another question that has surfaced in recent days is who is behind this and what is their motivation. To give you some views on this question, I sought the commentary of a variety of experts:

Mike Hamilton, Former CISO of the City of Seattle and former Vice-Chair of the DHS State, Local, Tribal, and Territorial Government Coordinating Council (SLTTGCC) and CISO of Critical Insight

This is not the first time a Canadian energy sector company has been recently compromised. A pipeline company was compromised earlier this year, and a recent intelligence report stated that Russian actors are actively seeking to disrupt Canada’s energy infrastructure. Rather than being victims of opportunity, these events seem to be strategic acts of nation-state actors and not cyber criminals looking for a score.

About a year ago Canada announced that it would boost oil and gas production to assist the European Union cut its use of Russian energy. Notably, and in at least one of the incidents, actors were able to manipulate the operational technologies (OT) and did so. This suggests that the tools and tactics being used were more sophisticated, making these events significantly different than the ransomware attack against the IT (not OT) network of Colonial Pipeline.

According to the intelligence report, these events will likely continue for the duration of the war in Ukraine and are intended to produce psychological impacts in the population and yes, the United States is also a target for this activity. Whereas the actual destruction or permanent disruption of this infrastructure would constitute an act of war, temporary disruptions to energy generation and transmission are likely to proliferate and insofar as possible create the perception that it’s a criminal act. (Note that disrupting distribution is the domain of domestic nutjobs.)

Ron Brash, VP of Research and critical infrastructure software security firm, aDolus Technology

In the respect of comparing Suncor and Colonial, they are not the same and are not really in the same business.  Had Suncor been Enbridge, this would have been a vastly different story, but based on POS outages, rewards programs and corporate AD/credentials – it appears again to be more of a Honda-like event and some operations affected. Given the size and nature of Suncor/Petroncan,  it’s more likely that cardlocks, volume tracking and maybe metering/pos on pumps were affected. Some warehouse activities such as product management and shipping may have been stalled or degraded, but like downstream retail – they can often be run with a clipboard, measuring stick, calculator and an alternative form of payment (all except cardlock of course).

This could be a focused event because of Canada and other allies’ stance on the war in Ukraine, but evidence points to more of an inconvenience vs being a major incident or an organization such as a significant pipeline.   It may have been entirely opportunistic, and dressed up under a guise. However, more accurate details are needed before a true impact assessment can be surmised. 

Ron Fabela, field CTO at cybersecurity firm XONA Systems

It’s incredibly difficult to tie any intention to the Suncor cyber event with geopolitical actions or threats.  This very loose hypothesis comes from reports of “A pro-Russia hacktivist group claims to have breached the network of a Canadian gas pipeline company in February and caused damage that resulted in loss of profits, according to a document found among a tranche of US classified intelligence assessments leaked online recently.” (source Kim Zetter https://zetter.substack.com/p/leaked-pentagon-document-claims-russian).  Note that at the time, this breach and impact was communicated in the past tense, meaning an event that already occurred earlier this year.Even so, impacts reported by Petro-Canada (and parent Suncor Energy) indicate a potential standard ransomware attack against point of sale systems and supporting backend systems  (Nothing close to the reported “[…]show their access to the Canadian facility and indicating that they had the ability to increase valve pressure, disable alarms, and initiate an emergency shutdown of the facility” (source again from Kim Zetter).)At this time, there’s no indication that this event is having Colonial Pipeline-like impacts on Canadian infrastructure or customer confidence. However any cyber event, whether a direct APT attack or opportunistic ransomware, that affects critical infrastructure operations should be taken seriously and as a recipe for what’s ahead. The prevalence of ransomware targeting remote access services like with Colonial Pipeline or exposed vulnerable technologies such as MoveIT is only going to continue to have secondary impact on the safe and reliable operations of critical systems. Regardless of geopolitical intent this continues to be a concern for not just the US, but critical infrastructure organizations around the world. My advice: create plans around incident response, implement technologies that support visibility and zero trust architectures, take those first concrete steps into preventing future attacks instead of waiting for them to strike close to home.

For the sake of Petro Canada and Suncor, I hope that they’re making every effort to address this because the longer it goes on, the more likely that it won’t end well for them. On top of that, I hope that there’s a focused effort to find who did this and bring them to justice.

Trend Micro joins the Canadian Cyber Threat Exchange

Posted in Commentary with tags on June 28, 2023 by itnerd

Trend Micro, a global leader in cybersecurity solutions, has joined the Canadian Cyber Threat Exchange (CCTX) to contribute knowledge assets and threat insights and to help support cyber resilience across the country. The CCTX is Canada’s national cyber threat sharing and collaboration hub. 

By becoming a CCTX member, Trend Micro is joining forces with a diverse community of organizations, professionals, and government institutions to collaborate, share, and discuss useful information regarding cyber threat actors, their campaigns, TTPs (tactics, techniques, and procedures), trends, research, and processes. Collaborating on current risks and exchanging best practices, techniques, and insights is critical to increasing preparedness and developing security responses that can protect organizations across multiple fronts.

Building cyber resilience is an important focus area considering a recent Trend Micro report showed Canadian organizations struggle to profile and defend their expanding attack surface. Over the past year, 56 percent of Canadian organizations have had customer records compromised at least once. Moreover, another report found the average total cost of a data breach for Canadian companies was $4.50 million (USD).

The CCTX was created to build a secure Canada where all organizations, both private and public, collaborate to increase cyber resilience using a two-pronged approach: 

  • CCTX Collaboration Centre is a trusted forum for cyber professionals to solve problems by exchanging best practices, techniques, and insights.
  • The CCTX Data Exchange compiles, analyzes and shares cyber threat information to provide actionable cyber threat intelligence to its cross sectoral membership. Data is received from its members, the Canadian Centre for Cyber Security and other Canadian and international cyber threat sharing hubs.

As a leading global voice in the fight against cybercrime, Trend Micro is proud to support collaborative hubs, partnerships, and law enforcement internationally by sharing strategic and tactical threat intelligence with different countries worldwide, including Canada.

To learn more about Trend Micro please visit: www.TrendMicro.com

To learn more about CCTX, please visit: https://cctx.ca/

Rezilion Report Finds World’s Most Popular Generative AI Projects Present A High Security Risk

Posted in Commentary with tags on June 28, 2023 by itnerd

Rezilion, an automated software supply chain security platform, today announced a new report, “Expl[AI]ning the Risk: Exploring the Large Language Models (LLM) Open-Source Security Landscape,” finding that the world’s most-popular generative artificial intelligence (AI) projects present a high security risk to organizations.

Generative AI has surged in popularity, empowering us to create, interact with, and consume content like never before. With the remarkable advancements in LLMs, such as GPT (Generative Pre-Trained Transformers), machines now possess the ability to generate human-like text, images, and even code. The number of open-source projects that integrate these technologies is now growing exponentially. By way of example, since OpenAI debuted ChatGPT seven months ago, there are now more than 30,000 open-source projects on GitHub using the GPT-3.5 family of LLMs. 

Despite the booming demand for these technologies, GPT and LLM projects present various security risks to the organizations that are using them, including trust boundary risks, data management risks, inherent model risks, and general security concerns.

Rezilion’s research team investigated the security posture of the 50 most popular generative AI projects on GitHub. The research utilizes the Open Source Security Foundation (OSSF) Scorecard to objectively evaluate the LLM open-source ecosystem and highlight the lack of maturity, gaps in basic security best practices, and potential security risks in many LLM-based projects.

The key findings highlight concerns, revealing very new and popular projects with low scores:

  • Extremely popular, with an average of 15,909 stars 
  • Extremely immature, with an average age of 3.77months
  • Very poor security posture with an average score of 4.60 out of 10 is low by any standard. For example, the most popular GPT-based project on GitHub, Auto-GPT, has over 138,000 stars, is less than three months old, and has a Scorecard score of 3.7.

The following best practices and guidance is recommended for the secure deployment and operation of generative AI systems: educate teams on the risks associated with adopting any new technologies; evaluate and monitor security risks related to LLMs and open-source ecosystems; implement robust security practices, conduct thorough risk assessments, and foster a culture of security awareness. 

An alarming amount of time is dedicated to security – especially when it comes to software. Rezilion’s automated software supply chain security platform helps customers to manage their software vulnerabilities efficiently and effectively. Maintaining a detailed and current database on the latest software vulnerabilities and the strategies to mitigate them remains paramount to customers’ success in navigating this complex security landscape. Rezilion provides its users with the same OpenSSF scorecard insights as part of the product offering for customers to make more informed decisions regarding adopting and managing any open-source project. 

I also got some commentary Yotam Perkal, Director of Vulnerability Research at Rezilion who authored this report.

What was the most concerning finding from the survey and why? 

The most concerning finding from the survey is the inadequate maturity and security posture of the open-source ecosystem surrounding LLMs. As these systems gain popularity and adoption, it is inevitable that they will become attractive targets for attackers, leading to the emergence of significant vulnerabilities. This finding raises concerns about the overall security of LLMs and highlights the need for improved security standards and practices in their development and maintenance.

What should organizations know about LLM risk before integrating Gen AI tools? 

Organizations should be aware that integrating Generative AI tools, including LLMs, comes with both unique challenges and general security concerns. They need to address the specific risks associated with LLMs, such as data privacy, protection against attacks on the models, and securing the infrastructure involved in their deployment. Additionally, organizations must consider broader security implications and ensure that industry security standards are followed to promote ethical and responsible use of generative AI technology.

How can they prepare for this risk and who is responsible for this? 

Organizations can prepare for LLM risks by adopting a secure-by-design approach when developing Generative AI-based systems. They should leverage existing frameworks like the Secure AI Framework (SAIF), NeMo Guardrails, or MITRE ATLAS™ to incorporate security measures into their AI systems.  It is also imperative to monitor and log LLM interactions and regularly audit and review the LLM’s responses to detect potential security and privacy issues and update and fine-tune the LLM accordingly. Responsibility for preparing and mitigating LLM risks lies with both the organizations integrating the technology and the developers involved in building and maintaining these systems.

What are some other risks GPT and LLMs can pose to organizations? 

The risks associated GPT and LLMs can pose are varied and can affect all aspects of the CIA triad (Confidentiality, Integrity and Availability). These risks can lead to bypass of access controls, unauthorized access to resources, system vulnerabilities, ethical concerns, potential compromise of sensitive information or intellectual property and more.

How will this risk through LLM to organizations evolve in the next 12-18 months?

Over the next 12-18 months, the risk through LLMs to organizations is expected to evolve as the popularity and adoption of these systems continue to grow. Without significant improvements in the security standards and practices surrounding LLMs, the likelihood of targeted attacks and the discovery of vulnerabilities in these systems will increase. Organizations must stay vigilant and prioritize security measures to mitigate evolving risks and ensure the responsible and secure use of LLM technology.

To download the full report, please visit: https://info.rezilion.com/explaining-the-risk-exploring-the-large-language-models-open-source-security-landscape

Guest Post: Microsoft Edge hits nearly 300M users after ChatGPT integration

Posted in Commentary with tags on June 28, 2023 by itnerd

Web browsers serve as our virtual entryway in the vast landscape of the digital world, allowing us to explore the internet easily.

According to the calculations by the Atlas VPN team, the Microsoft Edge browser is closing in on a total of 300 million users. The browser’s number of users grew by 50 million months after ChatGPT was implemented. Despite that, Google Chrome and Safari continue to dominate the browser market share.

Google Chrome has nearly 3.4 billion users and stands firmly as the most popular browser. Chrome’s success is due to its strong features, user-friendly interface, and seamless integration with Google services.

Apple’s Safari browser reached over 1 billion users last year and this year continued to grow to 1.1 billion users. Since April 2022, the Opera browser has grown its user number by 40%, from 109 million to 152 million users.

Firefox’s browser user number stands at about 150 million. Samsung Internet browser has a user base of nearly 135 million people.

​​Cybersecurity writer at Atlas VPN, Vilius Kardelis, shares his thoughts on browser market share:

“The growth of Microsoft Edge has sparked a wave of innovation among its competitors. A notable example is Google’s integration of its Bard AI into Chrome, a clear response to Edge’s success. Such a competitive environment promises a bright future for web browsing.”

To read the full article, head over to:

https://atlasvpn.com/blog/microsoft-edge-hits-nearly-300m-users-after-chatgpt-integration