What are the Common Security Challenges CISOs Face?

0
[ad_1]
Security Challenges CISOs Face

Chief Information Security Officers (CISOs) hold a critical and challenging role in today’s rapidly evolving cybersecurity landscape. Here are the common security challenges CISOs face.

As organizations increasingly rely on technology to drive their operations, CISOs face complex security challenges that demand their expertise and strategic decision-making.

These challenges arise from the constant emergence of sophisticated cyber threats, the need to protect sensitive data, and the ever-evolving regulatory landscape.

The role of a CISO requires balancing proactive risk mitigation with the ability to respond swiftly to incidents and breaches.

This article will delve into the top challenges CISOs face, including protecting digital assets, managing security incidents, ensuring compliance, dealing with insider threats, and the relentless pursuit of cyber resilience.

By understanding these challenges, CISOs can develop robust cybersecurity strategies and lead their organizations toward a secure and resilient future.

Who is a CISO?

Chief Information Security Officer (CISO) is a senior executive responsible for overseeing and administering an organization’s information security plan.

A CISO’s primary responsibility is safeguarding the confidentiality, availability, and integrity of an organization’s information assets and systems.

They are accountable for creating and enforcing strategies, policies, and procedures to defend against cyber threats, protect sensitive data, and mitigate security risks.

CISOs play a crucial role in maintaining an organization’s security posture by establishing and enforcing security standards, conducting risk assessments, and implementing appropriate security controls.

They collaborate with other executives, IT teams, and stakeholders to align security initiatives with business objectives and ensure that security measures are integrated into the organization’s operations.

In addition to their technical expertise, CISOs often engage in risk management, incident response planning, security awareness training, and compliance with regulatory requirements.

They stay updated on the latest cybersecurity trends, threats, and technologies to address emerging risks and implement appropriate security measures effectively.

The role of a CISO has become increasingly important as cyber threats evolve in complexity and frequency.

CISOs are responsible for safeguarding the organization’s sensitive information, maintaining the trust of customers and stakeholders, and ensuring business continuity in the face of cybersecurity challenges.

CISO Guide to Balancing Network Security Risks Offered by Perimeter 81 for free, helps to prevent your network from being at Risk.

What are all the Roles and Responsibilities of CISO?

  1. Developing and Implementing Information Security Strategy: The CISO is responsible for developing and implementing an overarching information security strategy aligned with the organization’s business objectives. This includes setting security goals, defining security policies and procedures, and establishing risk management frameworks.
  2. Leading the Security Team: The CISO manages and provides leadership to the security team, including hiring, training, and supervising security personnel. They ensure the team has the necessary skills, resources, and support to carry out their responsibilities effectively.
  3. Overseeing Security Operations: The CISO oversees day-to-day security operations, including incident response, vulnerability management, threat intelligence, and security monitoring. They ensure appropriate controls, technologies, and processes are in place to protect the organization’s assets.
  4. Risk Management: The CISO is responsible for identifying and assessing security risks to the organization’s information systems and assets. They develop and implement risk management strategies to safeguard critical data and systems, including risk mitigation, transfer, and acceptance.
  5. Compliance and Regulatory Requirements: The CISO ensures that the organization complies with relevant security regulations, industry standards, and legal requirements. They stay updated on emerging regulations and ensure appropriate controls and processes are in place to meet compliance obligations.
  6. Security Incident Response: The CISO leads the organization’s response to security incidents, including data breaches, malware attacks, and other security breaches. They establish incident response plans, coordinate efforts, and collaborate with relevant stakeholders, such as legal, PR, and law enforcement agencies.
  7. Security Awareness and Training: The CISO promotes a culture of security awareness throughout the organization. They develop and deliver security awareness programs and training initiatives to educate employees on security best practices and minimize human-related security risks.
  8. Vendor and Third-Party Risk Management: The CISO assesses and manages security risks associated with third-party vendors and partners. They establish vendor security requirements, conduct due diligence, and monitor compliance with security standards and contractual obligations.
  9. Security Governance and Reporting: The CISO provides regular reports and updates on the organization’s security posture to executive management, board members, and other relevant stakeholders. They ensure that security metrics and key performance indicators (KPIs) are established to measure the effectiveness of security programs.
  10. Incident Investigation and Forensics: In the event of security incidents, the CISO oversees the investigation and forensic analysis to identify the root cause, assess the impact, and prevent future occurrences. As required, they collaborate with internal and external resources, such as forensic experts and law enforcement agencies.

Security Challenges CISOs Face

CISOs face various common security challenges as they strive to protect their organizations’ digital assets and information. Perimeter 81 Guide helps CISOs to prevent their network from being at Risk. Some of the key challenges they encounter include:

  • Sophisticated Cyberattacks: CISOs must defend against increasingly sophisticated cyber threats, including advanced persistent threats (APTs), ransomware attacks, social engineering, and zero-day exploits. These attacks can bypass traditional security measures and require constant vigilance and adaptive security strategies.
  • Insider Threats: CISOs need to address the risks posed by insiders, including employees, contractors, or partners who have authorized access to systems and data. Insider threats can involve accidental data breaches, negligence, or malicious intent, requiring a balance between enabling productivity and implementing controls to prevent unauthorized access or data leakage.
  • Compliance and Regulatory Requirements: CISOs must ensure their organizations comply with industry-specific regulations, such as GDPR, HIPAA, PCI-DSS, or SOX, and evolving privacy laws. Navigating complex compliance requirements and maintaining a robust security posture to meet these standards can be a significant challenge.
  • Cloud Security: As organizations increasingly adopt cloud services and infrastructure, CISOs must address the unique security challenges associated with cloud computing. This includes securing data stored in the cloud, managing access controls, and ensuring the security of cloud service providers (CSPs) and their environments.
  • Security Skills Gap: CISOs often need more skilled cybersecurity professionals. The industry’s rapid growth and evolving threat landscape have resulted in high demand for cybersecurity talent, making recruiting and retaining qualified professionals challenging.
  • Third-Party Risk: Organizations rely on third-party vendors and suppliers, introducing potential security risks. CISOs must assess the security posture of third parties, establish contractual security obligations, and monitor their adherence to security standards to mitigate the risk of breaches through these external connections.
  • Security Awareness and Training: Human error remains a significant factor in cybersecurity incidents. CISOs must promote a strong security culture, provide regular training and awareness programs, and educate employees about cybersecurity best practices to minimize the risk of social engineering, phishing attacks, and other user-related vulnerabilities.
  • Incident Response and Recovery: CISOs must develop and test robust incident response plans to manage and recover from security incidents effectively. This involves identifying and containing breaches, conducting forensic investigations, and implementing remediation measures to minimize the impact and prevent future incidents.
  • Emerging Technologies: Adopting technologies like the Internet of Things (IoT), artificial intelligence (AI), and blockchain introduces new security challenges. CISOs must understand the security implications of these technologies, assess risks, and implement appropriate controls to protect against potential vulnerabilities and attacks.
  • Budget and Resource Constraints: CISOs often face budget limitations and the need to prioritize security initiatives. Balancing the allocation of resources to address immediate security needs while investing in long-term security capabilities can be a significant challenge.

What are the Security Compliance CISO Should Follow

As a Chief Information Security Officer (CISO), there are several security compliance frameworks and regulations that you should consider following, depending on the nature of your organization and its operations. Here are some of the key security compliance frameworks and regulations:

  1. General Data Protection Regulation (GDPR): If your organization deals with the personal data of individuals in the European Union (EU), GDPR sets requirements for the protection, processing, and transfer of personal data. It includes principles for data minimization, consent, data breach notification, and the rights of individuals.
  2. Payment Card Industry Data Security Standard (PCI DSS): PCI DSS applies to organizations that handle credit card information. It sets requirements for securing payment card data, including network security, encryption, access controls, and regular vulnerability assessments.
  3. Health Insurance Portability and Accountability Act (HIPAA): HIPAA applies to organizations in the healthcare industry that handle protected health information (PHI). It establishes requirements for the privacy and security of PHI, including access controls, encryption, risk assessments, and breach notification.
  4. Sarbanes-Oxley Act (SOX): SOX applies to publicly traded companies in the United States. It sets requirements for financial reporting and establishes controls and processes to ensure the accuracy and integrity of financial statements. While not solely focused on security, it includes provisions for protecting financial data.
  5. National Institute of Standards and Technology (NIST) Cybersecurity Framework: The NIST Cybersecurity Framework provides guidelines and best practices for managing cybersecurity risks. It covers risk assessment, security controls, incident response, and continuous monitoring.
  6. ISO 27001: ISO 27001 is an international standard that provides a framework for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). It covers various aspects of information security, including risk management, access controls, incident management, and security awareness.
  7. Federal Information Security Management Act (FISMA): FISMA applies to U.S. federal agencies and sets requirements for securing federal information and systems. It mandates risk assessments, security controls, incident response planning, and continuous monitoring.

Security Challenges CISOs Face to Manage Security Team

Managing a security team as a Chief Information Security Officer (CISO) requires effective leadership, communication, and coordination. Here are some key aspects to consider when managing a security team:

  1. Establish Clear Roles and Responsibilities: Clearly define the roles and responsibilities of each team member to ensure everyone understands their specific duties and areas of expertise. This clarity helps streamline operations and avoid confusion.
  2. Set Goals and Objectives: Define strategic goals and objectives for the security team aligned with the organization’s overall security strategy. Communicate these goals to the team and regularly track progress to ensure everyone is working towards the same objectives.
  3. Provide Guidance and Mentorship: Offer team members guidance, mentorship, and professional development opportunities. Encourage skill development, certifications, and staying up-to-date with the latest security trends and technologies—support team members in their career growth.
  4. Foster Collaboration and Communication: Promote a collaborative and open communication culture within the team. Encourage knowledge sharing, cross-functional collaboration, and effective communication channels. Regular team meetings, brainstorming sessions, and updates are valuable for aligning efforts.
  5. Support Decision-Making: Empower team members to make decisions within their areas of responsibility. Provide guidance and support when needed, but encourage autonomy and ownership in decision-making. Foster an environment where team members feel comfortable taking calculated risks.
  6. Establish Incident Response Procedures: Develop clear incident response procedures and ensure the team is well-prepared to handle security incidents effectively. Conduct regular drills, tabletop exercises, and simulations to test and improve the team’s incident response capabilities.
  7. Stay Informed and Adapt: Stay up-to-date with the latest security threats, industry trends, and best practices. Encourage continuous learning and professional development for the team. Adapt security strategies and measures as the threat landscape evolves.
  8. Collaborate with Other Departments: Work closely with other departments, such as IT, legal, HR, and executive management, to ensure security initiatives are aligned with business objectives and integrated into overall organizational operations. Build relationships and foster a culture of security awareness throughout the organization.
  9. Regularly Evaluate and Improve: Regularly evaluate the team’s performance, processes, and procedures. Collect feedback from team members and stakeholders to identify areas for improvement. Implement changes and adjustments as necessary to enhance the team’s effectiveness and efficiency.
  10. Lead by Example: Demonstrate strong leadership skills, integrity, and a commitment to security best practices. Lead by example in adhering to security policies and procedures. Encourage a positive and supportive work environment.

Final Thoughts 

CISOs face many common security challenges as protectors of their organization’s digital assets and information.

From sophisticated cyberattacks and insider threats to compliance requirements and resource constraints, these challenges highlight the complex and evolving nature of the cybersecurity landscape.

CISOs must navigate these challenges by adopting a proactive and strategic approach to security, leveraging advanced technologies, fostering a strong security culture, and collaborating with stakeholders.

To overcome these challenges, CISOs must stay abreast of emerging threats, continuously evaluate and improve their security measures, and prioritize investments in critical security capabilities.

They must also foster strong partnerships with internal teams, third-party vendors, and industry peers to collectively address security challenges and share best practices.

While the security challenges CISOs face may seem daunting, they also present opportunities for innovation and growth.

By effectively addressing these challenges, CISOs can enhance their organizations’ security posture, safeguard critical assets, and instill confidence in customers and stakeholders.

Ultimately, the role of a CISO requires a comprehensive and adaptable approach to cybersecurity, where staying one step ahead of threats and continuously improving security measures are paramount.

By embracing these challenges, CISOs can help shape a secure and resilient future for their organizations in an increasingly interconnected and threat-filled digital landscape.

CISO Guide to Balancing Network Security Risks Offered by Perimeter 81 for free, helps to prevent your network from being at Risk.


[ad_2]
Source link

Brazilian Hackers Hit Portuguese Banks in Malware Attack

0
[ad_1]

The researchers have noticed that Brazilian hackers are deploying PeepingTitle malware in their attacks against at least 30 Portuguese financial institutions.

According to the latest report from SentinelLabs, more than 30 Portuguese banks have become victims of targeted hacking by cybercriminals based in Brazil. These institutions were targeted in what seems to be a financially motivated campaign that was launched in 2021 but became active in early 2023.

Most of the attacks occurred last month, and the main targets are financial institutions in Portugal, wrote SentinelOne researchers Tom Hegel and Aleksandar Milenkoski.

Reportedly, the hackers implant information-stealing malware to hijack credentials and user data, including personal information, and leverage it for malicious activities apart from financial gains.

In a blog post, SentinelOne stated that it started tracking the campaign, dubbed Operation Magalenha, in early 2022. The researchers noted that the intrusions led to deploying two variants of the PeepingTitle backdoor, which greatly enhanced the attack potential.

The attack starts with phishing emails and websites hosting bogus installers of popular software. Once downloaded on a device, it launches a Visual Basic Script, which executes the malware loader. This loader then downloads/executes the PeepingTitle backdoors. The backdoor starts monitoring users’ web browsing activities.

The backdoor quickly captures screenshots when a user accesses a financial institution’s website or logs into their account. It connects with the attacker’s remote server to launch new malware executables.

“With the first PeepingTitle variant capturing the entire screen, and the second capturing each window a user interacts with, this malware duo provides the threat actor with a detailed insight into user activity,” researchers noted.

Brazilian Hackers Hit 30 Portuguese Banks in New Malware Attack
PeepingTitle window title monitoring (Credit: Sentinelone.com)

This campaign initially exploited cloud service providers such as Dropbox and DigitalOcean. But the hackers had to change course as these platforms tightened their security practices. Now, hackers are relying on Russian web hosting services provider, TimeWeb.

Both backdoors are simultaneously deployed, giving the hackers exceptional control over the compromised devices. Through PeepingTitle, attackers can track window interactions, terminate system processes, capture screenshots, and deploy data exfiltration tools and other malware.

Operation Magalenha indicates Brazilian hackers’ persistent nature and the evolving feature of their campaigns. Researchers wrote that Brazilian groups consistently update their malware tools and tactics, which is why their campaigns are so effective.

Moreover, researchers believe that the attackers have shown considerable understanding of local financial institutions and are ready to invest resources and time to develop targeted campaigns.

Regarding how researchers determined it was the work of Brazilian hackers, Hegel and Milenkoski wrote that the attackers used the Brazilian-Portuguese language in the artefacts they detected.

Moreover, the malware source code shares similarities with the Maxtrilha banking trojan, first discovered in 2021. It is written in Delphi programming language and grant hacker complete control over the infected hosts, capture screenshots, and drop new payloads.

  1. Ransomware Gang Leaks Medibank Data on Dark Web
  2. NATO data stolen in cyberattack on Portugal armed forces
  3. DDoS Attacks Hit Denmark Central Bank and 7 Private Banks
  4. Hacker leaks 73M records from Indian HDFC bank subsidiary
  5. IT Army of Ukraine hit Russian banking giant with DDoS attack

[ad_2]
Source link

More Galaxy A series devices get Samsung’s May 2023 update

0
[ad_1]

Samsung‘s May 2023 update has reached a couple more Galaxy devices. The company is rolling out the latest security patch to the Galaxy A42 5G and Galaxy A20s. These two Galaxy A series models follow dozens of other devices, including Galaxy S series flagships, Galaxy Z series foldables, and more in receiving the May SMR (Security Maintenance Release).

The latest update for the Galaxy A42 5G is currently available in Europe. Samsung is widely rolling out the May SMR to the 2020 mid-range smartphone in the region. The new firmware build number for the device is A426BXXU5DWE1 (via). While the build number suggests more than just a security patch, Samsung’s official changelog doesn’t mention anything else. Maybe there are some system optimizations hidden here, but don’t expect any new features.

The Galaxy A42 5G may or may not receive the May SMR in other regions. That’s because the device is only eligible for biannual security updates (two updates in a year), so Samsung may skip this release in some markets. It could push one of the future security releases to the phone in other markets, such as the US. The handset will receive security patches at least until the end of 2024. November 2024, to be precise.

Interestingly, the Galaxy A42 5G is still running Android 12 in Europe and most parts of Asia where it was sold. It has already picked up Android 13 in most other regions, including the US, Samsung’s home country South Korea, and Hongkong. The handset debuted with Android 10 and isn’t eligible for Android 14. We will let you know if and when Android 13 rolls out to Galaxy A42 5G users in the remaining markets.

The Galaxy A20s is also getting Samsung’s May update

The Galaxy A20s is another Samsung phone that is now receiving the latest security patch. The Korean firm has begun the rollout in select Asian countries, namely India, Sri Lanka, Bangladesh, and Nepal. The device is picking up the firmware build number A207FXXS5CWE1 with this update. This device is also only eligible for biannual security updates, so there’s no guarantee that users in other regions will get the May SMR.

This update doesn’t bring anything notable to the Galaxy A42 5G and Galaxy A20s but fixes some series security issues. Samsung revealed earlier this month that the May SMR patches at least six critical flaws across the Galaxy lineup. It also patches more than 50 high-severity flaws and a few less severe ones. In total, this month’s security patch contains more than 70 fixes, around 20 of which are Galaxy-specific.


[ad_2]
Source link

Meta begins another round of mass layoffs, third in three months

0
[ad_1]

Meta has reportedly begun another round of mass layoffs. This is the third and final round of a massive job cut announced in mid-March. Facebook‘s parent company has laid off around 10,000 employees across these three rounds. It previously cut more than 11,000 jobs in November last year, taking the total layoffs to over 21,000.

According to Reuters, the latest round of mass layoffs at Meta mostly affect non-engineering roles. The report states that employees across marketing, site security, enterprise engineering, program management, content strategy, and corporate communications have lost their jobs this week. In a separate report, the publication said that this job cut affected around 490 jobs at the company’s international headquarters in Dublin, Ireland. That’s almost 20% of its Irish workforce.

Meta hasn’t officially announced these layoffs. But the company said in March that it will let go of more than 10,000 employees over the next few months and freeze hiring for around 5,000 open positions globally. Following some job cuts in March, it fired around 4,000 employees in April. A few thousand more are now being let go. As said earlier, this comes after an even bigger layoff in November last year when Meta laid off more than 11,000 employees.

The latest mass layoffs reduce Meta’s global workforce by 25% in six months

A total of 21,000 job cuts by Meta means that the company has reduced its global workforce by about 25% over the past six months or so. CEO Mark Zuckerberg said in November that the goal is to “become a leaner and more efficient company” amid a challenging economic situation. The social network behemoth is also shrinking its real estate footprint, “transitioning to desk sharing for people who already spend most of their time outside the office”.

It hasn’t scaled back investments in the metaverse and AR/VR technologies, though. Zuckerberg has said that Meta will prioritize growth for certain products over others in these challenging situations.

Of course, Meta isn’t the only tech biggie feeling the heat of this global economic downturn. Pretty much every other firm has announced massive job cuts over the past few months to reduce their operational costs. Amazon fired around 27,000 employees across two rounds of mass layoffs in January and March of this year.

Google parent Alphabet has cut 12,000 jobs while Microsoft has let go of around 10,000 employees. Disney (7,000), Dell (6,650), Twitter (more than 6,000), IBM (3,900), and PayPal (2,000) are a few other firms that have cut multi-thousand jobs in recent months. Samsung, Apple, and others have also announced small-scale layoffs.


[ad_2]
Source link

Samsung ASLR Bypass Flaw Is Actively Exploited – Warns CISA

0
[ad_1]

US CISA recently issued an alert, warning Samsung users about an ASLR bypass flaw being under attack. The attackers are reportedly exploiting this vulnerability to deploy spyware on target devices. Since Samsung has patched the flaw, users only need to ensure updating their devices with the latest system updates to receive the fix.

Samsung ASLR Bypass Vulnerability Under Active Attack

The tech giant Samsung patched a severe kernel vulnerability affecting its smartphones and related devices.

Identified as CVE-2023-21492, Samsung has described the flaw as a kernel pointers exposure in log file without sharing many details in its advisory.

Yet, while confirming a patch release with May 2023 updates, Samsung mentioned the issue as an ASLR bypass flaw that allowed local privileged attackers to access sensitive data. The tech giant also admitted having detected active exploitation of the flaw.

Nonetheless, it still marked the vulnerability as a moderate severity issue that affected the devices with Android versions 11, 12, and 13.

The US CISA has warned users of this vulnerability while listing it in its Known Exploited Vulnerabilities Catalog.

Although, neither Samsung nor CISA elaborated on the vulnerability, probably, given its exploitation in the wild. However, numerous entities have already detected and disclosed the abuse of this vulnerability in recent spyware campaigns.

For instance, Google’s Threat Analysis Group reported in March 2023 about numerous vulnerabilities actively exploited by the threat actors to deploy mercenary ransomware. From the several zero-days and n-days, Google TAG researchers also found the ASLR bypass under attack during these campaigns. The report also stated about informing the matter to Samsung officials.

Likewise, Amnesty International also published a detailed post about mercenary spyware campaigns actively targeting Android and iOS devices. Those campaigns also involved the exploitation of ASLR bypass for Samsung devices.

Given the patch has already been released, users need not worry about possible exploitation. But for that, they must promptly update their devices with the latest releases.

Let us know your thoughts in the comments.


[ad_2]
Source link

Google Play Games for PC beta is now available in 56 countries

0
[ad_1]

The Google Play Games for PC beta is rolling out to users in Europe this week. Expanding Google’s feature to Microsoft’s operating system for harmonious gaming fun in more places than ever.

Prior to the expansion, this feature was only available for users in 14 countries. None of those countries are in Europe. Access included the US, Canada, Mexico, and Brazil for North and South America. It also included multiple countries in Southeast Asia such as Indonesia, Malaysia, the Philippines, Singapore, Taiwan, and Thailand. The remaining countries included Hong Kong, South Korea, Japan, and Australia.

Now, the beta is available in a total of 56 countries when you factor in all the new countries who now have access.

Google Play Games for PC beta expands to Europe and New Zealand

The Play Games for PC beta is a great way for users to access their favorite Android games on their Windows PC. But it’s less exciting if you’re region isn’t included in where the feature can be enjoyed.

Now users in New Zealand as well as numerous countries in Europe can download the Google Play Games for PC beta and try things out for themselves. In addition to New Zealand, users in the UK, Austria, Belgium, France, Germany, Poland, Sweden, Norway and many others in Europe can now download the app as well. The full list of countries can be found here.

To access the beta you’ll still need to meet some minimum requirements. For starters you need to be on Windows 10 (v2004) or Windows 11. You’ll also need to have an SSD with at least 10GB of storage and at least 8GB of RAM. Google also suggests at least an Intel UHD Graphics 630 GPU or similar. Though it shouldn’t be too hard to meet that requirement these days. If you live in a supported region and want to check out the beta for yourself, you can grab it from the button below.

Google Play Games for PC beta


[ad_2]
Source link

Verizon is laying off 6,000 employees amidst restructuring efforts

0
[ad_1]

It’s no secret that in this post-pandemic economy, many companies have resorted to job cuts as a way to save operational costs and stay afloat. Now, just days after revamping its wireless data plans, Verizon is reportedly laying off over 6,000 of its customer service employees as part of its efforts to restructure and streamline its operations.

The company announced this decision in a meeting with all of its employees, and while Verizon has promised to provide further details on May 25th, affected employees will reportedly have two options: accepting a severance package based on their years of service, which offers two weeks of pay per year of tenure, or exploring potential new positions within Verizon that focus on customer experience, loyalty, and technology. However, it’s important to note that the second option does not guarantee a job, and employees will need to wait until June 23rd to learn about their future at Verizon.

Moving the customer service team overseas

After the layoffs, Verizon reportedly plans to outsource its customer service and after-sales assistance operations to foreign companies. The rationale behind this decision is that by outsourcing to countries where labor costs are significantly lower, Verizon can achieve greater cost-effectiveness and operational savings. And this is the reason why the company reduced domestic hiring for customer service positions.

This decision of laying off employees comes shortly after Verizon fell short of Wall Street expectations in its Q1 ’23 earnings, reporting a loss of 127,000 postpaid net new phone subscribers. Additionally, the company’s recent decision to replace premium services like Apple Music and the Disney Bundle with a $10 monthly charge for every service chosen may also impact customer satisfaction as subscribers adjust to paying for previously included services. However, in an effort to expand the reach of 5G technology and attract new users, Verizon has plans to introduce the C-band spectrum in more areas over the next few months.


[ad_2]
Source link

In time for WWDC, the Apple Developer app is updated to allow iPhone users to follow the action

0
[ad_1]
The Apple Developer app is available from the App Store (tap on this link) and Apple calls it “your source for developer stories, news, and educational information — and the best place to experience WWDC.” With the latter in mind, and with the knowledge that WWDC 2023 is just 11 days away (the event kicks off on June 5th), Apple has updated the app to make it easier for those with an iPhone to follow the event from home, work, or play.
With the update, the Developer app will now support videos, sessions (via videos and transcripts), labs, forums, activities, and more. When you open the Apple Developer app, tap on the WWDC tab at the bottom of the display. In the release notes for the update Apple writes, “Explore all WWDC23 has to offer, including session videos, activities in Slack, 1-on-1 labs, and more.” It also says that it has fixed bugs and added other enhancements that it didn’t name.

To make sure that you have the latest version of the Apple Developer app, open the App Store and tap the profile picture or your initials in the upper right corner. Near the bottom of the display will be a list of apps that are ready to be updated; look for the Apple Developer app and tap on the “Update” pill. Or you can just tap the “Update All” link in blue.

Besides the Keynote, which will start streaming on Monday, June 5th, at 10 am PDT (1 pm EDT), the State of the Union will stream starting at 1:30 pm PDT. As for “Sessions,” new videos and transcripts will be posted daily from June 6th through June 9th.

The Keynote should include a preview of iOS 17 and of course, everyone is eager to see the introduction of Apple’s expensive mixed reality AR/VR headset. The device, rumored to come with a $3,000 price tag, takes an already available product to a brand-new level. In a way, you might compare it to Macworld on January 9th, 2007 when Steve Jobs introduced the iPhone. In other words, you might not want to miss the WWDC Keynote on June 5th.

[ad_2]
Source link

GuLoader Uses Google Drive to Download Payloads

0
[ad_1]
GuLoader via Google Drive

Antivirus products continuously advance to combat evolving threats, prompting malware developers to create new bypassing techniques like “packing” and “crypting,” GuLoader is a notable service employed by cybercriminals to avoid detection by antivirus software.

The cybersecurity researchers at Check Point affirmed that GuLoader employs a range of evasion techniques and stands out for its encrypted payload being uploaded to a remote server, enabling attackers to utilize a securely protected shellcode-based loader that downloads, decrypts, and executes the payload in memory without storing decrypted data on the hard drive.

Besides Google’s diligent attempts to impede the encrypted malicious payloads of GuLoader, most instances still witness GuLoader successfully retrieving payloads from Google Drive.

Malware Delivered using Google Drive

Conclusive evidence uncovered by researchers indicates that GuLoader is presently being employed as a distribution mechanism for the subsequent malware strains:-

  • Formbook
  • XLoader
  • Remcos
  • 404Keylogger
  • Lokibot
  • AgentTesla
  • NanoCore
  • NetWire

Earlier iterations of GuLoader were VB6 applications that utilized encrypted shellcode to handle essential tasks like loading the encrypted payload, decrypting it, and executing it from memory, while the current prevalent versions rely on:-

GuLoaded attack chain

Techniques Followed by GuLoader

Both the NSIS and VBS variants of GuLoader utilize the same version of shellcode, which incorporates numerous anti-analysis techniques similar to previous versions.

Here below, we have mentioned the techniques used:-

  • Sandbox evasion techniques
  • Anti-debugging techniques

While previous versions of GuLoader could be bypassed using a debugger during dynamic analysis, security analysts face significant challenges in the new version due to a technique that hampers both debugging and static analysis.

Since late 2022, GuLoader’s shellcode has incorporated a novel anti-analysis method involving generating numerous exceptions that disrupt the code’s regular execution flow, with control subsequently transferred to a dynamically calculated address through a vector exception handler.

The storage method for the payload decryption key mirrors that of the encrypted strings, yet the key remains unencrypted distinctively. Typically, the key length falls within the range of 800 to 900 bytes.

To evade automated analysis, GuLoader employs a deceptive tactic by using a different size, not the one stored with the key, which poses a challenge for decryption as only the initial 843 bytes of the payload can be decrypted accurately, leaving the remaining data fragmented.

From previous versions of GuLoader, the payload decryption algorithm remains unchanged, with the initial 64 bytes of the downloaded data skipped.

GuLoader obtains the final key by assuming that the first 2 bytes of the decrypted payload are “MZ” and calculates a 2-byte XOR key (rand_key), which is used to XOR the payload decryption key.

By employing encryption, omitting headers, and separating payloads from the loader, threat actors render their malicious payloads undetectable by antiviruses, enabling them to utilize Google Drive as a storage medium and circumvent its antivirus safeguards, with some download links to these payloads persisting for extended durations.

Shut Down Phishing Attacks with Device Posture Security – Download Free E-Book


[ad_2]
Source link

Wasserstein unveils a stand for the Pixel Tablet stand (you read that right)

0
[ad_1]

The Pixel Tablet is set to start shipping before too long, and we’re all excited to see how it will perform. While Google has its first-party accessories for the device, Wasserstein just unveiled a third-party add-on for the tablet, according to Cision. This one is an interesting one.

If you want to know more about the Pixel Tablet, then you can read here. We explain what you need to know about this tablet. Also, if you’re looking to put in your pre-order, you can click here. It’s a quick guide to make the process that much easier.

Wasserstein unveils the stand for the Pixel Tablet charging stand

The main selling feature of the Pixel Tablet stand is the charging stand. You can attach your tablet to it so that it can enter docked mode. This will turn it into a smart display. Also, the stand will charge the tablet and act as a speaker.

The only issue is that you’re stuck with only one angle. It’s a comfortable angle, but it’s not for everybody. This is where Wasserstein comes in with its Pixel Tablet Speaker Stand. This is an add-on that will let you adjust the angle of your tablet.

Wasserstein Pixel Tablet Stand 2

It’s an external stand that you’ll place your Pixel Tablet and dock inside of. The Wasserstein stand will tilt up and down so that you can choose your preferred angle. It’s perfectly crafted to fit the charging dock, so you won’t need to worry about it falling out.

When your tablet is in the stand, just know that it will be rather tall. If you’re planning on getting this stand, then you’ll want to keep that in mind.

Not only can you tilt it, but you can also rotate it. This makes it much easier to move and adjust your Pixel Tablet. If you’re thinking about picking one up, it’s currently on sale for $24.99 ($15 off). Normally, this stand goes for $39.99. You can order it below.

Wasserstein Pixel Charger Stand


[ad_2]
Source link