Tag: Murali Urs

Barracuda Researchers discover an alarming number of attacks probing for unpatched software vulnerabilities

India, July 23, 2021: While analysing the data from the attacks blocked by their systems over the past two months, researchers of Barracuda, a trusted partner and leading provider of cloud-enabled security solutions, identified hundreds of thousands of automated scans and attacks per day, with the numbers sometimes spiking into the millions. The data also points towards thousands of scans per day for the recently patched Microsoft and VMware vulnerabilities.

First disclosed in March 2021, the Microsoft vulnerability a.k.a. Hafnium is a server-side request forgery (SSRF) vulnerability in Exchange, which allowed the attacker to send arbitrary HTTP requests and authenticate as the Exchange server. From the information publicly available, CVE-2021-26855 is used to identify vulnerable systems, and the remaining vulnerabilities are chained with this vulnerability to gain access and perform further exploitation, including dropping web shells into the exploited systems.

In March, there was an increase in probing for the vulnerabilities from time to time with regular scans across the sensors and deployments worldwide, which then dropped off to lower levels. Meanwhile, in the case of VMware, CVE-2021- 21972 and CVE-2021-21973 were released on February 24, 2021. There has been regular probing for CVE-2021-21972 with some downturn in the scanning.

Speaking on the latest findings, Murali Urs, Country Manager-Barracuda Networks India said, “Software vulnerabilities, especially hard-hitting ones, continue being scanned for and have been exploited for quite some time after the release of patches and mitigations. Attackers understand that defenders don’t always have the time or bandwidth to keep up with patches all the time, and things slide—providing them with an easy way into the network. We are expecting to see some uptick in the scans from time to time as attackers move through the list of known high-impact vulnerabilities.”

While analyzing attacks, Barracuda researchers also identified their patterns. Bots followed the course of a workday to perform their attacks, which has now shifted to workweek. Both these insights show that most attackers seem to take the weekend off, even when running automated tasks. This is likely because it is easier to hide in the crowd when attempting various activities rather than setting off alarms by going after less used systems on weekends.

Some of the most common attack types included attempts at reconnaissance/fuzzing, and attacks against application vulnerabilities (WordPress was the most popular). Typically, SQL injection attacks take place followed by command injection attacks and then any other type of attack. However, this time, command injection was by far the leader that peaked over two weeks in June and then went back down to the normal traffic levels. The remaining attacks were at more or less the expected levels, with no specific attack patterns to be called out in the different categories.

Finally, the levels of HTTPS traffic and the versions of the protocols used were analysed where the latest TLS1.3 emerged as the clear leader, followed by TLS1.2. This is good news, given that these are the most secure protocols. While there are some deployments still using plain HTTP but the traffic generated through it is higher in volume than the older and insecure SSL/TLS protocols.

“To gain protection against automated attacks taking advantage of known software vulnerabilities, organizations should look for a WAAP (Web Application and API Protection services) solution that includes bot mitigation, DDoS protection, API security, and credential stuffing protection — and make sure it is properly configured.” Urs added.

72% of COVID-19-related attacks are scamming; reports Barracuda Networks

New Delhi: Barracuda, a trusted partner and leading provider of cloud-enabled security solutions released a new report with key findings about the ways cybercriminals are adapting quickly to current events and new tactics. The latest report, titled Spear Phishing: Top Threats and Trends Vol. 5 – Best practices to defend against evolving attacks, reveals new details about these highly targeted threats, including the latest tactics used by cybercriminals and the steps you can take to defend your business.

The report takes an in-depth look at how attackers are quickly adapting to current events and using new tricks to successfully execute attacks — spear phishing, business email compromise, pandemic-related scams, and other types. It also tackles why organizations need to invest in protection against lateral phishing and other internally-launched attacks from compromised accounts, including solutions that use artificial intelligence and machine learning.

Attack trends and beyond

Barracuda’s research reveals key takeaways about how these targeted attacks are evolving and the approaches cybercriminals are using to maximize their impact.

  • Business email compromise (BEC) makes up 12% of the spear-phishing attacks analyzed, an increase from just 7% in 2019.
  • 72% of COVID-19-related attacks are scamming. In comparison, 36% of overall attacks are scamming. Attackers prefer to use COVID-19 in their less targeted scamming attacks that focus on fake cures and donations.
  • 13% of all spear-phishing attacks come from internally compromised accounts, so organizations need to invest in protecting their internal email traffic as much as they do in protecting from external senders.
  • 71% of spear-phishing attacks include malicious URLs, but only 30% of BEC attacks included a link. Hackers using BEC want to establish trust with their victims and expect a reply to their email, and the lack of a URL makes it harder to detect the attack.

Speaking on the latest report, Murali Urs, Country Manager (India), Barracuda Networks said, “Cybercriminals adapt very quickly when they find a new tactic or current event that they can exploit. Their response to the COVID-19 pandemic proved it too well. As organizations in India, today are facing increasing threats from highly targeted phishing attacks, staying aware of the way spear-phishing tactics are evolving will help them take the proper precautions to protect their business and users. They must invest in technology to block attacks and provide training to help people act as a last line of defense and avoid falling victim to scammers’ latest tricks.”

Barracuda researchers detected millions of bad bots attacks on eCommerce websites during the holiday shopping season

Come holiday season and online shopping spree begins with full force, making the eCommerce websites an attractive target for cybercriminals to launch attacks. This November, Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, detected millions of bad bots attacks that were been used by the attackers to run distributed denial of service (DDoS) attacks, make fraudulent purchases, and scan for vulnerabilities they can exploit.

Barracuda researchers in the middle of the month, ran the Barracuda Advanced Bot Protection in front of a test web application, and detected a staggering number of bad bots in just a few days with millions of attacks coming in from thousands of distinct IP addresses. When viewed by the time of day, the researchers found that the bots don’t just wait until the middle of the night to attack. In fact, the bot activity peaks late morning and goes on until 5 p.m., which indicates that the cybercriminals aka “bot herders” follow a regular working day.

Bad bot personas are bots that have been identified as malicious based on their pattern of behavior. They are grouped by User-Agent, some of which are good. For example, GoogleBot, which crawls sites and adds them to search rankings, is good and should not be blocked. Cybercriminals have been using different ways to spoof good User-Agents to conduct the attacks. The bad bots spoof these known good User-Agents, which would need deeper scrutiny to tell them apart.

To identify a bot as being bad when the User-Agent claims to be a good search engine, Barracuda researchers use different methods; Injecting honeytraps like hidden URLs and JS challenges; Using rDNS (reverse DNS lookup) to verify bots coming from a claimed source; Inspecting whether the client is trying to access URLs used by common app fingerprinting attacks; and analysing further with ML, in case the methods don’t work out. HeadlessChrome, yerbasoftware, and M12bot are some of the bad bot personas that showed an increase in numbers.

Speaking on the threat, Murali Urs, Country Manager-India, Barracuda Networks, commented, “While analysing which Internet System Provider or Autonomous System Number has been the source of this bad bot activity, our researchers identified Indian mobile provider Airtel’s subnet ranges in the mix, as well as some of the big public cloud providers like Google Cloud, Amazon. This shows that even though the source of bots is international, it would depend on the bot and the site it is targeting.”

With the holiday shopping season expected to continue in full swing till the New Year, eCommerce teams should start taking necessary steps to safeguard their applications against bad bots. They must install a well-configured web application firewall as a service solution and make sure that the application security solutions include anti-bot protection to effectively detect advanced automated attacks. eCommerce websites should further turn on credential stuffing protection to prevent account takeover.

More than 1,000 schools, colleges and universities were attacked between June and September; highlight latest Barracuda Threat report

Barracuda Networks, a trusted partner and a leading provider of cloud-enabled security solutions, has detected a new wave of spear-phishing attacks targeting the education sector, as institutions continue to operate online. The researchers evaluated over 3.5 million spear-phishing attacks executed on various sectors, including those that were solely aimed at the education sector, affecting more than 1,000 schools, colleges, and universities. Spear phishing is a personalized phishing attack that targets a specific organization or individual. Over the years, cybercriminals have rapidly evolved and continue to adopt more innovative styles of attacks against different sectors, including education.

The Threat Spotlight further revealed that educational institutions are more than twice as vulnerable to a carefully-crafted business email compromise (BEC) attack than an average organization. Using this form of attack, threat actors have taken hold of schools, resulting in devastating losses. While the scale of attacks dropped by 10-14% during summer vacation (July and August), the number substantially picked up in September when students returned from holidays. The researchers also highlighted the advent of two more common types of attacks: email scams and service impersonation, against schools between July and September.

There was another stunning revelation in the report. Gmail accounts were the primary medium for cybercriminals to launch the aforementioned attacks – accounting for 86% of all BEC attacks on the education sector. Cybercriminals prefer to use well-known email providers like Gmail because they are free, easy to register and have a higher reputation in the market. They customized malicious email addresses using terms like ‘principal’, ‘head of the department’, ‘school’, and ‘president’ to make them look realistic. In fact, attackers even used convincing subject lines to quickly grab the victim’s attention and thus create a sense of urgency. Some of them include COVID-19 New Updates, COVID-19 School Meeting, COVID-19 Update, and Follow Up Right Now, among others.

Surprisingly, as per the analysis, of the total number of malicious messages detected (both inbound and outbound), 1 in 4 messages was sent from internal email accounts. This percentage was significantly higher for the education sector, with 57% of infectious emails sent from internal accounts. This means accounts in the education industry were used to send more attacks than they actually received. Since there was a high degree of trust associated with these compromised accounts due to their legitimacy, it was incredibly valuable for criminals who used them as a perfect launchpad for attacks.

Murali Urs, Country Manager-India, Barracuda Networks, said, “As schools and colleges continue to teach students remotely, it makes both the parties vulnerable to cyberattacks. Spear phishing has many forms as we saw in our latest threat report. While online teaching and learning is a crucial part of the new normal, it is also important for students and teachers to act mindfully before, during and post the online classes. Neither every system has updated antivirus protection, nor everyone is aware of how to respond to these attacks. Investing in the right cybersecurity solutions along with gaining proper knowledge on prevention methods is, therefore, the need of the hour.”

Prevention measures

To begin with, schools and colleges need to prioritize email security that leverages artificial intelligence to identify unusual senders and requests. This additional layer of defence on top of traditional email gateways will provide substantial protection against spear-phishing attacks for both staff and students. They must also invest in technology that will enable them to identify suspicious activities and potential signs of account takeover.

In addition, institutions should educate both staffers and students about email threats and how to recognize them, understand their nature, and finally report them. Security awareness training is all the more critical now because of the increasing reliance of educators and learners on email and other digital tools for communication and educational purposes.

On top of that, institutions must also establish and regularly review company policies to ensure that personal and financial information is handled safely, especially during wire transfers and payment changes. In-person/telephone confirmation or approval from multiple authorities for financial transactions can work wonders.

71% Indian Organisations say security has taken back seat with remote working despite increasing threats; New Study by Barracuda Networks

Barracuda, a trusted partner and leading provider of cloud-enabled security solutions, today released key findings from a report titled “Brave the new normal: How companies in India are overcoming security challenges in a remote workplace”. The research revealed that 53% of organizations surveyed in India do not have an up-to-date security strategy or solutions covering all the vulnerabilities posed by remote working, while 71% admitted that security has taken a back seat in the shift to this mode of working.

The market report was commissioned by Barracuda and conducted by independent research firm Censuswide in July 2020. 1,055 business decision-makers in Australia, New Zealand, Singapore, Hong Kong and India were surveyed to gain insights into their current mindset about the future of work trends resulting from the COVID-19 pandemic.

“While organizations are riding a wave of digital transformation to support the shift to remote working, many have been impacted by major security concerns that have emerged. Despite this, security has taken a back seat in many organizations due to budget and resource constraints. Threat protection must get the attention it deserves to avoid causing reputational and financial damage at a time when most companies can least afford it,” said Murali Urs, Country Manager India, Barracuda Networks.

The report revealed that 62% of Indian organizations surveyed cut their cybersecurity budgets to save costs as they responded to the pandemic. In addition, 42% lacked IT resources or time to upgrade their IT infrastructure in the shift to a remote working model. This highlights the need for organizations to find ways to prioritize spending on critical controls, whether that involves consolidating vendors, investing in SaaS-based tools or assessing how automation could help free budget and resources for security.

This is critical given employees may often be more distracted when working remotely, coupled with a lack of protection on home devices and networks, making them more susceptible to cybersecurity attacks. 66% of organisations surveyed reported at least one data breach or cybersecurity incident since shifting to remote working, with 67% reporting that employees had experienced an increase in email phishing attacks. 70% are concerned about unknown threats that will cause business disruption in the next 6 months.

According to the report, 61% of respondents said their employees are not properly trained in the cyber risks associated with remote working. In addition, 54% are not confident in the security of their web applications, which is another major target for malicious third parties seeking to access corporate data.

The good news is that most Indian decision-makers are aware of the problems relating to their remote working security posture and have a clear idea of how they can improve it. 85% believe that cross-industry collaboration is key to improving security standards. 92% said that they will need to upgrade their IT infrastructure to improve visibility and productivity. 87% plan to provide improved online cybersecurity training and awareness for remote working staff.