Tag: Barracuda Networks

Barracuda announces threat predictions for 2022

By – James Forbes – May, Vice President, Barracuda Networks APAC

Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, revealed predictions that will shape the future of the cybersecurity and tech space in the coming year.

Ransomware will still be a problem

Ransomware would continue to dominate the news for being the most lucrative way of making money for the bad guys. However, there will be a renewed focus on the governments prioritizing cybersecurity initiatives, building alliances with vendors, and sharing data with other countries. This level of collaboration will help improve security for everyone.

In this post-breach era, ransomware attackers have been ahead of their targets since they have their hands on stolen data, including credentials. These attacks range from extortion on valuable data to penetrating the software supply chain. It has gone beyond disrupting business operations and goes as far as revealing information to discredit a corporation and destroy the trust chain. Figuring out how to slow that down by encouraging collaboration between governments and developing alliances with vendors will be critical in the year ahead.

Critical infrastructures are expected to face the greatest security challenge

The COVID-19 pandemic has shown that cybercriminals are willing to exploit the crisis to attack critical infrastructures like healthcare and the vaccine supply chain. It will be necessary for hospitals and healthcare organizations to understand the three steps of ransomware protection: avoiding credential leaks, securing access to their applications and infrastructure, and backing up their data.

In 2022, critical infrastructure will continue to face significant security challenges. This also includes everything from energy and financial services to education and healthcare. For example, there have been numerous stories about how ransomware attacks that hit hospitals affect patient treatment and even lead to deaths. Attacks on critical infrastructure have the most direct impact on people’s lives, so security will be a challenge as cybercriminals continue to focus on these vulnerable areas.

Privacy requirements will drive security decisions

In 2022, privacy will dominate the security conversation because data can no longer be leveraged without accountability. Almost 75% of countries have some type of privacy regulation. So, all businesses must protect and enrich any data they collect from customers in a way that respects their privacy requirements.

These conversations about privacy policy also come up in the context of digital transformation. Companies are adopting many SaaS technologies, downloading apps and software, but they should be aware of the privacy implications of all of the technologies that are being used. In 2022, companies will be making decisions about which products to use, based on whether or not the data compliance is sufficient for their customers.

Having the tools in place to ensure compliance will become more important as well, especially for small and mid-sized businesses. While leveraging SaaS solutions like OneDrive, SharePoint, and Teams, they would need to understand what their teams are doing and make sure they have the tools to secure the data and are also compliant.

Forensics and XDR are new skills IT security executives would need in 2022

IT security executives would need to develop the ability to understand forensics and incident response. Many large and small IT security organizations, working with a managed service provider, are still struggling with too many tools and not getting the signals to work together.

Detection and response will be the keywords to help IT security executives achieve what they need to in 2022 and beyond. Improving in this area will require an Open XDR platform or managed XDR solution through a service provider. Those tools will enable IT, security executives, to respond more efficiently than they are now.  Right now, most enterprises are investing in tools to protect multiple attack surfaces. It will be essential to capture the signals from each tool and correlate the data for actionable insights.  From prevention, detection to response, it will require forensics and security analytics skills to defend against today’s cyberattacks.  With the existing shortage of cybersecurity skillset, utilizing a managed SoC (Security Operations Center) with XDR capabilities could be the answer for all small and medium enterprises.

Data consolidation is expected to see in 2022 by the security market

Consolidation on data-driven platforms is one change that is expected to occur in 2022 as the market shifts to more of a service-driven kind of tooling, including XDR and managed detection and response.

Detection and Response, skillset many organizations are missing will get more complex. Many companies, especially SMBs or small-to-medium-sized enterprises, will need this skill set to respond efficiently and effectively to survive these cyber-attacks without investing so much in building an in-house team.  So, they will have to rely on managed security service providers. At an enterprise level, it will mean getting to know the tools being used, identifying the signals received from those tools and consolidating those signals to make detection and response easier for the team.

Security talent shortage turns into a security crisis and creates new opportunities

The small and mid-sized companies were already short-staffed and were experiencing trouble hiring the staff they needed to protect themselves from security risks. The “Great Resignation” will make those challenges even more acute, especially in tech and healthcare. This will make a tough situation worse.

As a result, in 2022 businesses will rely more on their vendors to provide automated tools and services, like XDR and MDR. Managed services providers will become a critical resource as well. Gartner predicted 40% of mid-sized companies will leverage MDR by 2024. From a mid-market perspective, companies will need a service provider to help them successfully leverage SOC / NOC / XDR capabilities and stay secure. Increasingly, only large enterprise organizations will be able to manage their security needs internally.

The year 2022 will also see more security positions filled by people from unexpected backgrounds or with different skills. Due to the nature of the threats and the complexity of the environments, companies cannot go back to just hiring who they’ve hired before. Addressing security challenges constantly requires fresh thinking in the face of ever-changing attacks and overwhelming alerts. This is a great opportunity to bring in different perspectives and the cybersecurity or IT space that will play a prominent role in how companies secure themselves.

New security roles are expected to emerge over the next few years

Cybersecurity Champion is a new role that we will emerge in the next few years, especially in developing software. These security champions will focus on what we call shifting left because now it is about the developers, software development, and the software supply chain, including Open-Source libraries and other third-party libraries. On the very left of the entire software development lifecycle, getting that level of security attention at the developer level is where those roles will start to add value.

Security Analyst is another role expected to be at the forefront in the next few years. They will effectively detect and respond to threats by understanding the correlation of these different signals and execute on responding to these threats.

Sharing his insights on the predictions, James Forbes-May, Vice President, Barracuda Networks APAC, said, “With security now starting to be prioritized, the reporting structure will depend on the organization’s maturity and the leadership they have in place, such as if there is a CISO involved. Many of the IT teams won’t naturally be reporting to a CISO because their approach to security is event-driven. By being predictive and preventative and having the right tools and resources, one can have plans and programs to prevent incidents. So instead of having an event-driven approach to security, organizations will need to proactively shift to putting the measures and stopping those attacks from ever happening or stopping it earlier in the attack chain, so there’s less damage. Without a security practice at the very top, it will be challenging to bring this kind of change.”

Barracuda Email Threat Scanner detects millions of attacks missed by organizations’ existing protection in 2020

Barracuda Networks, a trusted partner and leading provider of cloud-enabled security solutions, announced a redesigned version of the Barracuda Email Threat Scanner, a free tool that can help businesses detect email threats getting past their email gateway. These threats include highly targeted attacks such as spear phishing, business email compromise, conversation hijacking and services impersonation, among many others.

In 2020, 4,550 organizations used Barracuda Email Threat Scanner to scan 2,600,531 unique mailboxes and found 2,029,413 unique attacks. On average, 512 attacks were found per organization, and one out of 7 mailboxes (14%) had at least one attack currently sitting inside, even if messages were scanned by an email gateway solution.

The attacks detected fall into four email threat types: phishing, scamming, extortion, and business email compromise (BEC). Of the 2,029,413 unique attacks detected, phishing was the number one threat missed by the organisations’ email security solutions (59%). Meanwhile, 39 % of the attacks were scamming followed by 9% of extortion attacks and 8% of BEC attacks, which were less prevalent. Cybercriminals tend to send these types of attacks in smaller volumes because they are highly personalised.

Each scan conducted by the redesigned Barracuda Email Threat Scanner provides a report on attacks found inside the environment, as well as at-risk domains and employees. This helps organisations identify gaps in existing email protection and assess email security vulnerabilities. The refreshed Barracuda Email Threat Scanner brings a complete user interface update to its dashboard, which includes:

A scan preview page,which allows users to monitor their scan’s progress while the scan is running.

Access to early results as Email Threat Scanner scans mailboxes and finds attacks.

Improved dashboard reporting of detected threats, making it easier to hone in on specific insights and interpret the findings.

Speaking on the redefined email threat scanner, Murali Urs, Country Manager-India, Barracuda Networks, said, “In 2021, we foresee the threat landscape to become more challenging and sophisticated attackers will continue to take advantage of the widespread discussion on COVID 19, which indicates that spear phishing threats will become more dangerous than ever. While organisations have invested in protection against email threats, many of these attacks seep through gateways, landing on users’ inboxes. The attack numbers prove that traditional email gateways are not enough and customers should also use API-based inbox defenses to maximise their protection.”

Barracuda Sentinel integrates directly into Office 365 to find threats inside your mail system that security gateways can’t see. Visit https://www.barracuda.com/products/sentinel to get more information.

What service providers are saying:
“It’s critical to help our customers assess and understand email security vulnerabilities. The Barracuda Email Threat Scanner helps us quickly and effectively find social engineering attacks that might be going undetected in mailboxes and help close the gaps in those areas for our customers. The Email Threat Scanner makes the ‘invisible’ security threats visible, so that our customers see what they are up against and act to put a Barracuda solution in place quickly.” — Chris Riley, Director, System Source

“Many email threats slip past the email gateway. Threats like spear phishing and business email compromise put companies at significant risk. Barracuda Email Threat Scanner detects these threats and helps us uncover additional ways we can help customers protect their people and data.” — Kristian Connor, Director, Xitenys

“Using Barracuda Email Threat Scanner we’ve helped our customers uncover serious threats hiding in their Office 365 environment in a fast, free, and safe way. Not only does this make our customers more secure, but it helps us show the value of the solutions we offer them.” — Troy Radloff, General Manager, Alliance Business Tech

Resources:

Get more information about Barracuda Email Threat Scan: https://www.barracuda.com/email_scan

Get more information about Barracuda Sentinel: https://www.barracuda.com/products/sentinel

Get more information on the 13 email threat types: https://www.barracuda.com/13-email-threat-types

Read the blog post: What’s new in the redesigned Barracuda Email Threat Scanner: http://cuda.co/43276

Read the blog post: CIO Q&A: Why Meaden & Moore choose Barracuda Total Email Protection: http://cuda.co/43247

Watch the video: http://cuda.co/etspv

72% of COVID-19-related attacks are scamming; reports Barracuda Networks

New Delhi: Barracuda, a trusted partner and leading provider of cloud-enabled security solutions released a new report with key findings about the ways cybercriminals are adapting quickly to current events and new tactics. The latest report, titled Spear Phishing: Top Threats and Trends Vol. 5 – Best practices to defend against evolving attacks, reveals new details about these highly targeted threats, including the latest tactics used by cybercriminals and the steps you can take to defend your business.

The report takes an in-depth look at how attackers are quickly adapting to current events and using new tricks to successfully execute attacks — spear phishing, business email compromise, pandemic-related scams, and other types. It also tackles why organizations need to invest in protection against lateral phishing and other internally-launched attacks from compromised accounts, including solutions that use artificial intelligence and machine learning.

Attack trends and beyond

Barracuda’s research reveals key takeaways about how these targeted attacks are evolving and the approaches cybercriminals are using to maximize their impact.

  • Business email compromise (BEC) makes up 12% of the spear-phishing attacks analyzed, an increase from just 7% in 2019.
  • 72% of COVID-19-related attacks are scamming. In comparison, 36% of overall attacks are scamming. Attackers prefer to use COVID-19 in their less targeted scamming attacks that focus on fake cures and donations.
  • 13% of all spear-phishing attacks come from internally compromised accounts, so organizations need to invest in protecting their internal email traffic as much as they do in protecting from external senders.
  • 71% of spear-phishing attacks include malicious URLs, but only 30% of BEC attacks included a link. Hackers using BEC want to establish trust with their victims and expect a reply to their email, and the lack of a URL makes it harder to detect the attack.

Speaking on the latest report, Murali Urs, Country Manager (India), Barracuda Networks said, “Cybercriminals adapt very quickly when they find a new tactic or current event that they can exploit. Their response to the COVID-19 pandemic proved it too well. As organizations in India, today are facing increasing threats from highly targeted phishing attacks, staying aware of the way spear-phishing tactics are evolving will help them take the proper precautions to protect their business and users. They must invest in technology to block attacks and provide training to help people act as a last line of defense and avoid falling victim to scammers’ latest tricks.”

Barracuda Networks Threat Predictions 2021 reveal that there will be an increase in denial of service (DDOS) attacks, ransomware, business email compromise and malware-based attacks

India:  Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, revealed predictions that will shape the future of enterprise security in the coming year. It indicated that the threats of today will continue to target the weakest link in the chain, which normally is the human element. Year 2021 will witness many of the key trends in 2020 to continue.

  • Distributed enterprises and remote workers

Considering that in a span of a few weeks, companies went from 10% of workers being remote to over 90% of workers moving to remote, by 2021 we will see many of them slowly bringing back some key workers to their facilities and adopting measures that will give their employees flexibility if they can maintain productivity. While many companies had some experience of setting up temporary and limited remote access for contractors and vendors, every company will need to make sure they have clear processes and controls for managing a large percentage of their employees remotely for extended periods. Every company will need to have policies and procedures for managing remote access.

  • Accelerated migration to cloud adoption

Meanwhile, there will be an accelerated adoption of cloud services. First, new applications are being delivered as Software as a Service (SaaS) instead of on-premises implementation. Second, and more importantly, existing on-premises applications are also migrating faster to the cloud. 2020 was that inflection point for many with the cloud. COVID-19 forced many companies to significantly accelerate their migration to cloud services to address shutdowns and remote workers. IT executives will need to understand whether and how the assets and services delivered in the public cloud are adhering to compliance regimes as more and more capabilities are now delivered as cloud services. In addition, as more and more companies are exposed to threats that impact the privacy of their customers or enterprises, the risk of breaches will require IT security executives to be able to effectively communicate and execute plans that encourage and require other teams to enforce compliance.

  • Shortage of key resources to help mitigate growing security issues that will take advantages of the new reality

There will be a continued shortage of cybersecurity talent to help mitigate security issues, despite the recession and COVID-19 job losses. Attacks will also increase to take advantage of the new reality like distracted workers, global pandemic, cost pressures from the recession, remote access, accelerated adoption of cloud services. Each of these alone would be cause for concern for cybersecurity professionals. All these macro trends happening simultaneously demands the highest level of vigilance against those who would take advantage of these situations.

However, security executives will need to achieve the same level of security or more with tighter budgets due to the economic recession. There will be a growing need for security executives to get fully comfortable with novel cloud-centric security architecture. Additionally, 5G adoption will start to get more tangible in many regions of the world. IT security executives will need to come up with a more holistic understanding of risk and adequate protection measures as it pertains to the entire corporate network, including OT and industrial IoT environments

  • Zero Trust Network Access solutions are the way forward for enterprises to keep risks at bay

The COVID-19 pandemic has transformed work habits, which means corporate endpoints will be predominately used outside the perimeter of the corporate network in work-from-home environments. This will require organizations to review their current endpoint security and compliance enforcement approaches. As more consumers and businesses are becoming aware of the data breaches, there will be increasing discussion about the role of trust in security. While the concepts like Zero Trust and micro-segmentation are emerging as ideal ways to decrease attack surfaces, these solutions will be part of a broader approach that will leverage social graphs and machine learning to identify issues and enforce trust relationships.

Speaking on these security predictions, Hatem Naguib, COO, Barracuda Networks said, “In 2021, we foresee the threat landscape to become more challenging and COVID-19 will continue to impact security in many ways. Every industry needs to make sure it is prepared to deal with security issues. IT security executives should make sure these plans include security compliance checks that are straightforward and quick to implement without having a long-term impact on productivity. In addition, thorough and comprehensive backup and recovery solutions will be critical. Any business that has customers, employees, and transactions is a target. Healthcare, infrastructure (utilities), and government are more vulnerable than normal as they have stretched resources and will continue to be target-rich environments for those who would use simple methods like spear phishing, malware, and ransomware to create the most damage.”

Emerging security technologies in 2021

There is no reason to believe the threats of today will not be the threats of tomorrow. There will just be more of them, and they will be more effective and continue to see a proliferation of distributed denial of service (DDOS) attacks, ransomware, business email compromise, and malware-based attacks. These attacks will be more successful as companies deal with a series of events that have changed the attack surface.

Considering the enterprise security trends, it is clear that there will be a sharp increase in the demand for cybersecurity talent next year. Solutions that move security closer to the edge (people, places, and things) will become much more popular in 2021.

  • Classic gateway-based solutions will be augmented by CESS solutions

In email protection, classic gateway-based solutions will be augmented by Cloud Email Supplemental Security (CESS) solutions that leverage API access and social graphs/artificial intelligence/machine learning to mitigate messaging-based attacks. More such solutions will be used to address the threats on collaboration-based tools such as Zoom, Slack, and Teams. These platforms have become very popular tools for collaboration and are susceptible to the same type of attacks that we see with email.

  • SD-WAN solutions have become more prevalent

Secure Software-Defined Wide Area Network (SD-WAN) solutions have become more prevalent. As public cloud adoption increases, many companies have started to leverage Azure, Google, and Amazon backbones as a delivery vehicle for their own WAN. This makes sense as more applications and services are delivered on these cloud services and their points of presence continue to expand worldwide.

  • Zero Trust is the new standard in secure remote access

With remote workers and cloud-delivered services becoming a de facto part of every business, solutions that manage access at the highest level of granularity with the least level of complexity to setup and manage, will become more popular in 2021. Trust-based solutions that implement Zero Trust and other trust-based solutions will be effective mechanisms to manage privileged access to services. Traditionally, customers used complicated solutions like NAC or VPN. In 2021, we will see great adoption of lightweight solutions that quickly and effectively manage access at the device and individual level.

To this, Klaus Gheri, VP, Network Security, Barracuda Networks added, “Cybercrime will go where money can be made. By 2021, the market will start adjusting to the major and lasting shift that COVID-19 has caused in corporate work environments. Security products and architectures will be under increasing pressure to be flexible to deploy and operate, minimally invasive to the users, and as effective as possible without conflicting with the privacy legislation in various regions of the world.”

In addition, the physical world is expected to respond to concerns about privacy and security with increased local legislation to ensure companies are implementing and maintaining the highest level of protocols to protect themselves. There will be a continued sharp increase in the demand for cybersecurity talent into 2021 as every company will have to implement measures and augment their resources to manage and monitor solutions for addressing the COVID-19 mayhem.

Barracuda researchers detected millions of bad bots attacks on eCommerce websites during the holiday shopping season

Come holiday season and online shopping spree begins with full force, making the eCommerce websites an attractive target for cybercriminals to launch attacks. This November, Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, detected millions of bad bots attacks that were been used by the attackers to run distributed denial of service (DDoS) attacks, make fraudulent purchases, and scan for vulnerabilities they can exploit.

Barracuda researchers in the middle of the month, ran the Barracuda Advanced Bot Protection in front of a test web application, and detected a staggering number of bad bots in just a few days with millions of attacks coming in from thousands of distinct IP addresses. When viewed by the time of day, the researchers found that the bots don’t just wait until the middle of the night to attack. In fact, the bot activity peaks late morning and goes on until 5 p.m., which indicates that the cybercriminals aka “bot herders” follow a regular working day.

Bad bot personas are bots that have been identified as malicious based on their pattern of behavior. They are grouped by User-Agent, some of which are good. For example, GoogleBot, which crawls sites and adds them to search rankings, is good and should not be blocked. Cybercriminals have been using different ways to spoof good User-Agents to conduct the attacks. The bad bots spoof these known good User-Agents, which would need deeper scrutiny to tell them apart.

To identify a bot as being bad when the User-Agent claims to be a good search engine, Barracuda researchers use different methods; Injecting honeytraps like hidden URLs and JS challenges; Using rDNS (reverse DNS lookup) to verify bots coming from a claimed source; Inspecting whether the client is trying to access URLs used by common app fingerprinting attacks; and analysing further with ML, in case the methods don’t work out. HeadlessChrome, yerbasoftware, and M12bot are some of the bad bot personas that showed an increase in numbers.

Speaking on the threat, Murali Urs, Country Manager-India, Barracuda Networks, commented, “While analysing which Internet System Provider or Autonomous System Number has been the source of this bad bot activity, our researchers identified Indian mobile provider Airtel’s subnet ranges in the mix, as well as some of the big public cloud providers like Google Cloud, Amazon. This shows that even though the source of bots is international, it would depend on the bot and the site it is targeting.”

With the holiday shopping season expected to continue in full swing till the New Year, eCommerce teams should start taking necessary steps to safeguard their applications against bad bots. They must install a well-configured web application firewall as a service solution and make sure that the application security solutions include anti-bot protection to effectively detect advanced automated attacks. eCommerce websites should further turn on credential stuffing protection to prevent account takeover.

More than 1,000 schools, colleges and universities were attacked between June and September; highlight latest Barracuda Threat report

Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, has detected a new wave of spear-phishing attacks targeting the education sector, as institutions continue to operate online. The researchers evaluated over 3.5 million spear-phishing attacks executed on various sectors, including those that were solely aimed at the education sector, affecting more than 1,000 schools, colleges, and universities. Spear phishing is a personalized phishing attack that targets a specific organization or individual. Over the years, cybercriminals have rapidly evolved and continue to adopt more innovative styles of attacks against different sectors, including education.

The Threat Spotlight further revealed that educational institutions are more than twice as vulnerable to a carefully-crafted business email compromise (BEC) attack than an average organization. Using this form of attack, threat actors have taken hold of schools, resulting in devastating losses. While the scale of attacks dropped by 10-14% during summer vacation (July and August), the number substantially picked up in September when students returned from holidays. The researchers also highlighted the advent of two more common types of attacks: email scams and service impersonation, against schools between July and September.

There was another stunning revelation in the report. Gmail accounts were the primary medium for cybercriminals to launch the aforementioned attacks – accounting for 86% of all BEC attacks on the education sector. Cybercriminals prefer to use well-known email providers like Gmail because they are free, easy to register and have a higher reputation in the market. They customized malicious email addresses using terms like ‘principal’, ‘head of the department’, ‘school’, and ‘president’ to make them look realistic. In fact, attackers even used convincing subject lines to quickly grab the victim’s attention and thus create a sense of urgency. Some of them include COVID-19 New Updates, COVID-19 School Meeting, COVID-19 Update, and Follow Up Right Now, among others.

Surprisingly, as per the analysis, of the total number of malicious messages detected (both inbound and outbound), 1 in 4 messages was sent from internal email accounts. This percentage was significantly higher for the education sector, with 57% of infectious emails sent from internal accounts. This means accounts in the education industry were used to send more attacks than they actually received. Since there was a high degree of trust associated with these compromised accounts due to their legitimacy, it was incredibly valuable for criminals who used them as a perfect launchpad for attacks.

Murali Urs, Country Manager-India, Barracuda Networks, said, “As schools and colleges continue to teach students remotely, it makes both the parties vulnerable to cyberattacks. Spear phishing has many forms as we saw in our latest threat report. While online teaching and learning is a crucial part of the new normal, it is also important for students and teachers to act mindfully before, during and post the online classes. Neither every system has updated antivirus protection, nor everyone is aware of how to respond to these attacks. Investing in the right cybersecurity solutions along with gaining proper knowledge on prevention methods is, therefore, the need of the hour.”

Prevention measures

To begin with, schools and colleges need to prioritize email security that leverages artificial intelligence to identify unusual senders and requests. This additional layer of defence on top of traditional email gateways will provide substantial protection against spear-phishing attacks for both staff and students. They must also invest in technology that will enable them to identify suspicious activities and potential signs of account takeover.

In addition, institutions should educate both staffers and students about email threats and how to recognize them, understand their nature, and finally report them. Security awareness training is all the more critical now because of the increasing reliance of educators and learners on email and other digital tools for communication and educational purposes.

On top of that, institutions must also establish and regularly review company policies to ensure that personal and financial information is handled safely, especially during wire transfers and payment changes. In-person/telephone confirmation or approval from multiple authorities for financial transactions can work wonders.