Tag Archive for: Mitigate

OIG: DHS Can Better Mitigate the Risks Associated with Malware, Ransomware, and Phishing Attacks


A new report from the Office of Inspector General (OIG) contains several recommendations aimed at improving the Department of Homeland Security’s (DHS) mitigation of risk related to malware, ransomware, and phishing attacks. 

Threats of cyberattacks have been increasing during the past two decades. According to a joint announcement from DHS, the Department of Defense, and the Department of Justice on August 3, 2020, the Chinese government has been using malware to target government agencies, private sector entities, and think tanks since 2008. Phishing groups used voter registration–related lures to trick people into accessing fake government sites and giving away personal data in the days prior to the 2020 presidential election. And in a March 21, 2022 statement, the U.S. President reiterated his warning to the Nation about the possibility of Russia conducting malicious cyber activity against the United States. Microsoft observed close to 40 destructive attacks on hundreds of Ukrainian systems from February 23 to April 8, 2022, with 32 percent of these attacks directly targeting Ukrainian government organizations at various levels.

In recent years, several DHS components have also been victims of cyberattacks. In May 2019, photos of more than 100,000 travelers coming into and out of the country were stolen during an attack on a U.S. Customs and Border Protection (CBP) subcontractor’s network. Similarly, on October 4, 2020, United States Coast Guard personnel discovered that a database for the Coast Guard Auxiliary had been subject to a malware attack, resulting in the exfiltration of contact information for 59,149 individuals who had expressed interest in joining the Coast Guard Auxiliary. 

OIG’s audit found that DHS implements multiple layers of defense against malware, ransomware, and phishing attacks to protect its sensitive information from potential exploitation. In addition, DHS has implemented specific tools and technologies to further detect and prevent security events on component systems and to help protect DHS’ network communication and data. 

However, the watchdog said DHS can better protect its sensitive data from potential malware, ransomware, and…

Source…

What businesses can do to anticipate and mitigate ransomware threats


In this Help Net Security video, Kevin Holvoet, Cyber Threat Intelligence Instructor, SANS Institute, discusses ransomware and Ransomware as a Service (Raas) attacks, and illustrates how preparedness with a proper top-down response is critical for business continuity in case of an attack.

Source…

Kubernetes Ransomware Challenge: How to Mitigate and Recover – thenewstack.io



Kubernetes Ransomware Challenge: How to Mitigate and Recover  thenewstack.io

Source…

NetWitness® Ransomware Defense Cloud Services Helps Enterprises Avoid and Mitigate the Impact of Ransomware Attacks | Business


BEDFORD, Mass.–(BUSINESS WIRE)–Aug 4, 2021–

NetWitness, an RSA business ( @RSAsecurity ), a globally trusted partner for some of the world’s largest and most security sensitive organizations, today unveiled NetWitness ® Ransomware Defense Cloud Services, a managed cloud service that monitors endpoints without traditional deployment and administration requirements. Ransomware Defense Cloud Services also includes detection intelligence developed from in-depth ransomware research and development, combined with experienced threat hunting in enterprise environments. This unique offering enhances both prevention and preparedness for organizations concerned about the scourge of ransomware.

Ransomware has become an expensive and disruptive force within organizations. Increasingly, the industry is seeing businesses suffer loss of data, a halt to business operations and damages to reputation. These incidents are costly and labor-intensive to remedy if not detected quickly. At the same time, businesses are looking to streamline their IT processes and infrastructures. Security teams specifically require forensic value from technology solutions without bearing full administrative workload. NetWitness Ransomware Defense Cloud Services addresses these needs by providing expert intelligence in a cloud solution backed by ransomware specialists, experienced threat hunters, and ongoing research and development.

“The ransomware threat is becoming more persistent and sophisticated with every passing day. New ransomware variants, novel attacks, and ransomware-as-a-service (RaaS) mean that no organization can ignore the potential for attack or delay taking proactive steps to prepare for when they happen,” said Dr. Zulfikar Ramzan, Chief Technology and Product Officer of NetWitness. “Preventing and limiting damages from these attacks require a mix of technology, research, analysis, and threat hunting. NetWitness Ransomware Defense Cloud Services combine various areas of NetWitness expertise to help enterprises avoid headline-making ransomware incidents and are delivered through the cloud for rapid deployment.”

NetWitness Ransomware Defense Cloud…

Source…