Know & Fight Cyber Crime

Know & Fight Cyber Crime Cyber Crime Investigation is done to reach Cyber Criminals

24/04/2022
25/02/2020

How to defend against CLOP ransomware attack?

Organizations need to ensure they have updated their operating systems, applications, firmware and BIOS to the latest security patches. Building a robust firewall configurations, cybersecurity awareness to the employees, data backup protocols, and data security configurations can reduce the probability of being hit by CLOP ransomware.

However, these measures don’t mean you are a hundred percent secured. Being proactive is a key to reducing the chances of being attacked. However, please ensure you do have reactive measures like log management, SIEM, threat detection and more to identify the attack immediately.

25/02/2020

INA Group (belongs to MOL group) is a Croatia’s biggest oil company and consists of many petrol stations for its operations. On Feb14th, at 10:00 pm local time the company became victim to a ransomware attack and has infected its systems. However, the company has confirmed its petrol delivery to customers and payments aren’t affected.

10/02/2020

Steps You Should Take If You Are a Victim of a Cyberstalker:

Save all evidence:

– print out any harassing emails (along with the full email header).

– print out and save any harassing instant messages and private messages.

– save any harassing text messages (don’t delete them).

– note dates and times of all harassment on paper.

– keep any harassing and threatening letters and make copies of the letters.

– keep any harassing and threatening voice-mail messages and phone numbers (don’t delete them).

– save and print out any harassing messages or defamatory messages about you on social networking sites (e.g., Twitter, Facebook, etc.)

– if applicable, write down & also bookmark the username and profile URL of person harassing you via social networking website(s).

Be proactive and take action by filing a report with your local law enforcement agent or file a complaint.

Talk to someone so you don’t go through this alone; seek support from a trusted friend, family member, or a professional counselor.

14/06/2019

The 'powerful' digital assault caused some of the app's 200 million users to suffer serious 'connection' issues.

08/04/2019

91 percent of IT and security professionals feel vulnerable to insider threats, and 75 percent believe the biggest risks lie in cloud applications.

22/02/2019

As Mentioned in Infosecurity Magazine:

It’s no secret that the security industry suffers from a severe skills shortage. Amongst the many cybersecurity positions companies are currently challenged to fill are pe*******on testers’ roles. However, of all the skills that are in high demand and short supply, pen testing shouldn’t be one of them. Pen testers are the rock stars of infosec – everyone wants to be a pen tester. Moreover, companies clearly recognize the need for pen testing skills. So, what is the problem?

According to joint research conducted by the Enterprise Strategy Group (ESG) and the Information Systems Security Association (ISSA), 23% of organizations report having a shortage of pen testers, ranking pe*******on testing fourth on the list of cybersecurity skills where they suffer the largest shortage.

However, the problem isn’t a lack of qualified candidates; the problem is how companies approach pe*******on testing. On the one hand, some companies are inadvertently turning away qualified candidates while, on the other, they simply aren’t willing to put in the effort to develop pen testing skills internally.

Calling All Pen Testing ‘Experts’
Companies demand productivity. They want to fill open positions with people who can hit the ground running, but when it comes to IT skills, HR has unreasonable expectations for how productivity translates to experience.

An ‘expert’, so far as HR is concerned, has at least 10 years of experience in a given area. That is a problem when you are hiring for tech skills. A hiring manager tells HR that they want an ‘expert’ in a programming language – say, Swift – and that immediately gets translated into 10 years of experience. Swift was introduced in 2014. The company will be lucky to find a candidate with three years of experience.

You can see how the exacting demands recruiters place on job capabilities and requirements artificially constrains the supply of qualified pen testers. Qualified candidates don’t even get past keyword filters on job sites. As a result, candidates who could quickly come up to speed are passed over. Companies need to lower their expectations when posting job requirements, or be willing to take a shot at someone who exhibits the foundational skills and characteristics of a good pe*******on tester.

Growing Your Own Pen Testers
Pe*******on testing skills are available – if you’re willing to put in the time and effort to nurture them.

IT professionals are in ample supply, and their skillset serves as a strong foundation for network pe*******on testing skills. Businesses should look for individuals in their IT department who are willing to cross-train. Someone who has hands-on experience actually running systems, not someone from the help desk. Five-to-seven years of IT admin experience is preferable, as it indicates that the person is functional enough to hold down professional work, and they won’t need to be broken out of bad academic habits.

Besides the years of experience, it is important to understand the technical knowledge of the candidates. For example, while IT admins might know how to configure a firewall or router, a successful pen tester also needs to have an understanding of the inner workings of how a firewall actually works (in terms of its development). We all know there are encryption algorithms, but a pen tester ‘wanna-be’ should also know the inner workings of some of those algorithms. That hunger for understanding things in detail will drive the curiosity to think about broader situations where most security problems arise. Having software development background is another important skill, especially for those pen testers that will also assess applications. Not only will the development background provide inner workings on how machines and frameworks work, but it will also provide the foundations for understanding how to assess applications from a security standpoint.

Candidates should also have a track record for being fast learners and being adaptable. No two pen tests are alike, and no two systems are alike. Pen testers usually need to be able to develop and customize tools, so adaptability and programming knowledge are a must. Good pen testers have the ability to problem solve on their own and are used to learning and thinking independently.

The ideal pen tester also exhibits a healthy dose of deviancy. Some people are so bound by the rules of a system that they can’t think beyond it. They can’t fathom the failure modes of a system. Future pe*******on testers should have a natural inclination toward pushing the boundaries – especially when they are told, in no uncertain terms, not to do so. These are the people who learn best by doing.

It’s also important to understand that you won’t get instant results. You can’t send your IT admin to a weekend bootcamp and turn them into a pen tester. It takes time to develop pen testing skills. However, organizations can facilitate the process by setting up a proper apprenticeship.

The apprenticeship model was once used to train professionals of all trades because it worked. People learn well by doing alongside an expert. It was only fairly recently that society abandoned the apprenticeship model for mass education, but the apprenticeship model is tried-and-true, and it really works for pen testing.

It’s critical that organizations change their approach to hiring pen testers or invest the time to nurture pen testing skills in their IT professionals. The alternative – suffering a data breach due to a weak infrastructure – is unacceptable today; 70% of cybersecurity professionals reported to the ESG and ISSA that the global cybersecurity skills shortage has impacted their organizations. Pe*******on testing doesn’t have to be one of them.

Chris Sullivan oversees all aspects of Core’s security principals, strategy and posture, and the overall technology strategy across business lines and partnerships. In addition, Chris helps drive CoreLabs, a center for cyber security research and innovation, which maximizes collaboration between developers and cyber defenders across all security domains.

Previously, Chris held positions as General Manager of Core Security’s Intelligence/Analytics business, and VP of EMEA Operations, Advanced Solutions, Customer Solutions and Professional Services. He also serves as Chairman of the Access Risk Benchmarking Committee for ISACA and is a frequent speaker at industry conferences including the European Identity Conference, the Gartner Catalyst Conference, the MIT International Science and Technology Initiatives (MISTI), the IT GRC Forum and the ISACA ISRM conference. Chris received a Bachelor of Science degree in Computer Science from Northeastern University.

Five Reasons Why You Need a Cloud-Native Web Application Firewall
22/02/2019

Five Reasons Why You Need a Cloud-Native Web Application Firewall

DDoS attacks, bad bots, web server vulnerability exploits…the number of threats to websites and internet-facing applications is growing every day.

Address

Andheri
Mumbai
400053

Alerts

Be the first to know and let us send you an email when Know & Fight Cyber Crime posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share