7 Most Common Cyber Attacks To Watch In 2020

7 Most Common Cyber Attacks To Watch In 2020

Unauthorized attempt which could expose your personal data defines cyber-attack. It could include installing spyware or phone tapping without your permission. With the increase in cyber-crimes, we witnessed some major cyber-attacks in 2020.

Common Cyber Attacks In 2020

SolarWinds

SolarWinds was one of the most talked cyber-attack. Eminent companies like Microsoft etc. were also affected by it. The server that gives access to updates of SolarWinds was compromised and thus attacked. This code allowed information modification.

Twitter

Apart from this Twitter was also in the news lately. It was observed that fraudulent information regarding bitcoin was posted. The user apparently asked the twitter account holders for Bitcoin and through this received more than $100,000. Bill Gates, Elon Musk, Kanye West etc. were some of the famous personalities that were targeted. 

Marriott

You think your data is safe with hotels? Well data of almost 5.2 million guests of Marriott were accessed. Marriott is one of the most eminent hotels throughout the world. The information included the name, birth date, phone number, address etc. 

Zoom

Zoom was another such application that was attacked by hackers. Government also released the statement that zoom was not safe to use. Also, zoom codes were not so hard to crack so anyone could join in the meeting and get access to all the confidential data of the company. However, zoom has now hired an intelligence firm to look over the safety.

Greek Banking System

All of us have heard about the Greek Banking System. A Greek travel site was hacked due to which a lot of debit and credit cards were cancelled by the 4 main banks of Greece due to security protocols. A few customers were also charged with undesirable transactions. This website was a travel website and was used to book tickets etc.

MGM

MGM was another travel related incident that was exposed to cyber-crime. Personal data of around 10.6 million guests was at risk. MGM resort is a global entertainment company accompanied by resorts and casinos. Information of Famous personalities like Justin Bieber, Jeff Bezos was also at risk. 

Finastra, was also attacked by a ransomware in which it was temporarily disconnected and thus affected servers from the internet. Though there is no evidence that the data of the employees were exfiltrated it did disrupt the operations.

Let’s Take a Look At The Statistics

Today, cybercrime has affected more than 50% of businesses. Human errors are responsible for 95% of it. It is a shame but only 5% of company’s folders are the ones which are properly protected. There were 11,762 cases  Between  January 1, 2005, and May 31, 2020

It is seen that in the first half of 2019, attacks on IoT devices have tripled. A whopping amount of $3.92 million has cost enterprises due to data breaches. Due to COVID, cybercrime has increased up to 600%.

To conclude we can say that  cyber-crime is a punishable offence. There are several laws against it. By being a little more attentive we can help in stopping the spread of cyber-crime. Cyber-crime violates basic human laws too. It is time, let us take a stand against it.

Absence of Security in System Engineering

Absence of Security in System Engineering

Building a cyber secure system is one of the fundamental objectives of software developers and system engineers and the absence of security is a severe problem. Software developers focus on building feature-rich applications and improving user interaction and user experience. Security of applications and overall systems is left out to be tackled by third parties AFTER the system is developed.

The absence of security in the initial stages of System Engineering is the single most significant cybersecurity gap and risk in modern system development. ~Linda Rawson

Assurance Approach

Researchers have proposed different approaches to secure a system. Security by Design is an assurance approach; software and hardware developers try to secure systems by adopting practices like continuous testing, authentication safeguards, and adherence to best programming practices. This approach allows you to formalize infrastructure design and automate security controls so that you can secure every aspect of IT management and administration.

Absence of Security is an Organization Thing

Security in system engineering has a lot to do with WHO is involved more than vulnerabilities. The most important thing is to get the organization on board to embrace security. No exceptions. Implementing a DevSecOps approach ensures that security, development, and IT Ops teams work toward a joint security goal. If developers are onboarded with training that teaches them how to be hackers, they will write hacker-proof code.

Professional Services

Professional Services

Traditional Methods Need Adjusting

Security by Design helps secure the systems that were not networked initially, and security has not traditionally been considered in product design. One of the vital part goals of Security by Design is baking security into the design lifecycle, ensuring that data flows are secure, and authentication is appropriate.

Baking in Security

Baking in security is imperative as the entire IT landscape infrastructure has moved from just being client-server architecture to virtualization, cloud, a serverless environment, and containers, making it complicated for security practices. Cybersecurity should not be an afterthought; it should be baked in during the entire lifecycle of system development and deployment.

The variety of application development practices and frameworks should also be a motivation behind adopting cybersecurity. The conception, and partial reality, is cybersecurity is challenging and will slow the development cycle down. Modern software development lifecycle models have relaxed the perceived rigidity and are moving toward Agile methods.

The Waterfall model’s sequencing, emphasizing documentation at each phase before proceeding to the next phase, made it easier to include security controls at every step of the process. Baked in cybersecurity fit right into the rigid process.

Organizations are increasingly moving away from the waterfall model to rapid development cycles, where code is released monthly, weekly, daily, or even hourly.

The End Goal

Hardware and software should be treated together, integrated with cybersecurity early and frequently.

A Cyber-Resilient Organization

A Cyber-Resilient Organization

A cyber-resilient mindset is different from a cybersecurity mindset, although they are complimentary. Cybersecurity has often been an afterthought in System Engineering. It always surprises me to read through diagrams or models and discover not one mention of cybersecurity. Criminals will exploit humans and systems to bring the system to its knees and cause massive revenue loss.

Security in System Engineering has a lot to do with WHO is involved more than vulnerabilities. The most important thing for System Engineering security is in changing the culture to embrace security. No exceptions. Security must be built into the project at the beginning.

Implementing a DevSecOps approach ensures that security, development, and IT Ops teams work toward a joint security goal. ~ Linda Rawson

The People are Not the Process.

DevSecOps is agile in nature, and the people are still involved but not in the same capacity as they were in the Waterfall model. In DevSecOps, the people are not the process: The pipeline, the set of phases and tools that the code follows to reach deployment, defines the process.

The phases include Build, Test, and Deployment and prefer automation over manual methods. Build automation consists of the tools needed to grab the code and compile it. Test executes the automated test cases, while deployment drops the build into its destination. It means using static analysis tools that check the portions of code that have been changed versus scanning the entire code base.

The People Monitor the Process and Respond to Process Failures

Training hardware and software developers regularly on new cyber-attack techniques and exploitation vectors is essential to application solution security. Security and quality assurance policies need to be promulgated among the team to make development standards unambiguous and clear for everyone. Defensive Coding Practices result in more complicated code but writing code while thinking how an attacker might think, reduces vulnerabilities, and therefore reduces risk.

All Levels of Management Must Be Involved

Individuals from government stakeholders, operations, security, and development teams must be encouraged to have a cyber-resilient mindset. If you are proactive and think like a cyber attacker, you would do things differently instead of explaining why an attack occurred. In the case of an extensive enterprise system, why bank accounts were drained, or an airplane hit the ground.

Adopting Cybersecurity Practices

Adopting cybersecurity practices such as continuous integration, continuous delivery, and constant distribution has dramatically accelerated the speed at which organizations release and update applications. Security is no longer something that can be bolted on at the end of the development cycle but must be started by a proactive organization.

This blog was written by Linda Rawson, of DynaGrace Enterprises (dynagrace.com). For further information, please connect with Linda on LinkedIn, or contact her at (800) 676-0058 ext 101.

#systemengineering #cybersecurity #cybersecurityawareness #DevSecOps #infosec #security #mindset

Cybersecurity Awareness Month

Cybersecurity Awareness Month

 

With over 4.2 billion users surfing the internet, it may seem nearly impossible to protect your sensitive information from hackers and thieves. Devices connected to the internet often house our personal and professional lives. If a cyber criminal compromised this sensitive information, there could be disastrous consequences. However, the government dedicated the month of October as Cybersecurity Awareness Month in 2004 to educate internet users on how to navigate the web safely.

 

Cybersecurity Awareness Month

NASDAQ Marks National Cyber Security Awareness Month

NASDAQ Marks National Cyber Security Awareness Month
The Boeing Company via Flickr

During October, the United States Department of Homeland Security and the National Cyber Security Alliance provide easily accessible information and tips to all netizens on how they can protect themselves online. The campaign is vital because it gives everyone in the cyberspace tools and knowledge to thwart cybercriminals. Although society is quickly shifting to a more digitalized world, it is surprising that the majority of users are blissfully unaware of the threats they can encounter online. Sharing too much information on social media sites, sending unencrypted personal information electronically, and making purchases on unsafe websites are common ways that criminals gain access to sensitive information.

“While the speed at which technology and information move can expose us to new risks online, it also enables a level of sharing and cooperation that can make us more resilient to cyber threats… National Cybersecurity Awareness Month isn’t just about understanding the risks, but also emphasizing our collective power to combat them.” – FBI Cyber Division Assistant Director Matt Gorham.

Furthermore, basic cyberattacks on personal devices can give criminals access to large businesses and organizations. For example, a hacker gained access to an employees computer information that eventually led to a cybersecurity breach against the United States Office of Personnel Management. The attack cost the company $21.5 million. Therefore, it is imperative that every individual takes proper cybersecurity precautions.

 

Results

As the government further educates internet users on cybersecurity risks, people are installing more security software. The number of software downloads increased significantly since 2004. Additionally, more cybercriminals are being reported and convicted. For example, the government arrested a cyber criminal who attempted to access university databases, 74 arrests of members of the overseas transnational criminal networks and a North Korean regime programmer who conspired to conduct multiple damaging cyber attacks resulting in extensive data and money loss, hardware destruction, and the loss of other resources.

With increased awareness, internet users can stay safe and protect their private information. Cybersecurity is a responsibility that lies on everyone’s shoulders. If we all fulfill our duty, we can significantly decrease the number of information breaches.

 

For more information about cybersecurity, visit our website https://dynagrace.com/.

 

Resources: https://www.normantranscript.com/opinion/happy-cyber-security-awareness-month/article_2864473b-205f-51c1-b06a-a793e2ffb5c9.htmlhttps://www.fbi.gov/news/stories/ncsam-2018https://www.army.mil/article/211977/keep_info_safe_during_cyber_security_awareness_monthhttps://www.wombatsecurity.com/cybersecurity-awareness-month?utm_term=%2Bcyber%20%2Bsecurity%20%2Bawareness%20%2Bmonth&utm_campaign=Security+Awareness+Month&utm_source=adwords&utm_medium=ppc&hsa_acc=8253056476&hsa_net=adwords&hsa_cam=1566723829&hsa_ad=295401163184&hsa_kw=%2Bcyber%20%2Bsecurity%20%2Bawareness%20%2Bmonth&hsa_grp=60967832564&hsa_mt=b&hsa_ver=3&hsa_src=g&hsa_tgt=kwd-368130389969&gclid=Cj0KCQjw6rXeBRD3ARIsAD9ni9DBJ8oOpYn7F2kz2M5GzZfQUn5qnX-DKgeh8mJkvHtEdgtNDSPMCfQaAvIeEALw_wcB

Picture Resources: Featured Image: https://www.flickr.com/photos/79061493@N04/10442488614/in/photostream/https://www.flickr.com/photos/conquest-uk/30363339915/https://www.flickr.com/photos/theboeingcompany/8090236600/

 

U.S. Weapons System Vulnerable to Cyberattacks

U.S. Weapons System Vulnerable to Cyberattacks

In a digitalized society, the importance of having top-notch cybersecurity has never been more crucial. Cyber-attacks can destroy businesses, reveal sensitive information, and drain your finances. Additionally, according to a new publication, they can also cause mass destruction and death. Recently, an audit by the Government Accountability Office (GAO) of the U.S. military’s newly developed weaponry systems revealed that they have critical cyber vulnerabilities. These security holes allow hackers easy access to control all of the U.S.’s computerized weapons systems. Furthermore, these findings indicate that, while the military prioritized the development of weapons, they failed to focus on the cybersecurity.

The Audit

The government conducted an audit from 2012 to 2017 that focused on their developing weaponry systems. They utilized skilled, friendly hackers to probe the Pentagon’s online networks for security holes and weaknesses. After releasing their findings this past Tuesday, the results are shocking. The hackers discovered carelessness and negligence in nearly all developing weapons systems. These security vulnerabilities allowed them to easily access the country’s military weapons through online means. Furthermore, in their reports, they stated that they were able to take control of entire systems, view the operator’s computer screens, and delete and add data. As a joke, they even flashed pop-up messages on the operator’s computer screens telling them that they needed to insert quarters before proceeding.

Moreover, while these results are startling, the agency warned that the reported problems represented a small fraction of the overall cyber vulnerabilities in the Defense Department.

What Caused the Security Vulnerabilities?

The GAO listed negligence to fundamental cybersecurity practices as the primary cause of the vulnerabilities. One typical example they saw was using default passwords. In one instance, the team of hackers took a total of nine seconds to guess an administrator’s security password.

“Due to this lack of focus on weapon systems cybersecurity, DOD likely has an entire generation of systems that were designed and built without adequately considering cybersecurity. . . Bolting on cybersecurity late in the development cycle or after a system has been deployed is more difficult and costly than designing it in from the beginning.” –GAO report

Past Reports

This report remains one of many warning the government of deficient cybersecurity. In 1996, the GAO brought cybersecurity vulnerabilities to the public’s attention. Additionally, in 2004, they notified the Pentagon that connecting military systems through the Internet also opened the door to hackers.

Furthermore, while the Pentagon issued a report that they are improving their security standards in response to the audit, many people question their sincerity. In one of the past assessments, the Pentagon only corrected 1 out of 20 identified vulnerabilities.

Threats of Digitalization

As a society, we tend to transition physical objects onto online networks so they can be controlled and operated online. In the government’s case, they digitally transitioned the control of weapons and spent approximately $1.6 trillion developing the new system. While online controls are convenient for us, it also opens the door to the possibility of hackers gaining control of these objects and using them to hurt or kill others.

On the other hand, digitalizing the weaponry system has allows the Pentagon to increase their military capabilities beyond what they could have imagined. For example, the F-23 Joint Strike Fighter is connected to millions of digital coding lines that allow it to activate and target areas. While using multiple codes as a safeguard is a great idea, it only truly protects others if it has cybersecurity against hackers.

 

For more information about cybersecurity, visit our website https://dynagrace.com/.

Resources: https://www.washingtonpost.com/business/2018/10/10/nearly-all-new-us-weapons-systems-have-critical-cyber-security-problems-auditors-say/?noredirect=on&utm_term=.9da3d54db4ffhttps://www.washingtonpost.com/business/economy/defense-industry-grapples-with-cybersecurity-flaws-in-new-weapons-systems/2018/10/14/b1de3bae-ce36-11e8-a360-85875bac0b1f_story.html?utm_term=.c77ebadd1d0ehttps://sputniknews.com/us/201810141068879069-us-cyber-security-pentagon-risks/https://thehill.com/policy/cybersecurity/411232-watchdog-exposes-pentagons-cyber-struggles?amp

Picture Resources: Featured Image: https://pixabay.com/en/f-35a-lightning-ii-fighter-jet-2657514/https://pixabay.com/en/pentagon-washington-dc-military-80394/https://pixabay.com/en/internet-cyber-network-finger-3589685/https://pixabay.com/en/internet-security-password-login-1952019/

Pin It on Pinterest