“For success, attitude is equally as important as ability.”
-Harry F. Banks
Android/Simplocker could be the first Android ransomware to encrypt files
http://www.scmagazine.com/androidsimplocker-could-be-the-first-android-ransomware-to-encrypt-files/article/350070/
http://www.securityweek.com/new-ransomware-encrypts-android-files-eset
http://www.infosecurity-magazine.com/view/38716/experts-discover-fileencrypting-android-ransomware/
C-IT Recommendation
- Perform an asset inventory of all company owned Android devices using company provided cell phone service. Your company should have a configuration management database to show which devices have which operating systems versions.
- Ensure anti-malware service is deployed on all company owned Android devices. If you have a mobile device management solution, enable the company webfiltering option where applicable and force the cellular devices to pass through the company webfilter/proxy before accessing the internet.
- Provide mobile device security awareness informing your employees not to visit suspicious sites. Also, instruct employees not to apps from unofficial stores.
If you do not have a mobile device management solution in a BYOD model, Strongly recommend users to install the security updates. Failure to do so may result in your employees devices compromising your company information and/or costing the employees or your organization a ton of money
Article Resources
ESET Simplocker Explanation
http://www.welivesecurity.com/2014/06/04/simplocker/?utm_source=dlvr.it&utm_medium=twitter
US-CERT Security Tip: Cybersecurity for Electronic Devices
https://www.us-cert.gov/ncas/tips/ST05-017
Hackers distribute banking malware through Buffalo site in Japan
http://www.csoonline.com/article/2359426/hackers-distribute-banking-malware-through-buffalo-site-in-japan.html
C-IT Recommendation
If your company is hosting files
- Ensure your company is using a strong Web Code review process before publishing sites
- Use a software code security analysis tool to check your website for potential vulnerabilities
- Require your security team to perform penetration testing after any code changes to your externally facing websites.
- If websites are deemed vulnerable after penetration testing, require through policy that the web development teams roll back to the previous version of the website until vulnerabilities are resolved
- Review your security measures for the storage of files available for public download. Consider having an alerting mechanism when any changes are made to files in storage repositories available to your customer base
If your company downloads files:
- Ensure your anti-malware solution scans files for malicious software upon download of a file
Article Resources
The complete list of malicious downloads is:
airnavi2_160.exe
airnavilite-1330.exe
airnavi-1272.exe
airnavi-1040.exe
airnavi-1030.exe
kokiinst-160.exe
drivenavi_cbu2_100.exe
ls_series-168.exe
hp6v131.exe
bsbt4d09bk_21630.exe
NIST Publishes Second Draft of Federal IT Supply Chain Risk Management Guidelines
http://www.securityweek.com/nist-publishes-second-draft-federal-it-supply-chain-risk-management-guidelines
C-IT Recommendation
- Find out if your Information Technology organization has Security embedded into the Software Development Life Cycle. This is regardless if your organization does in house development or not. There should be no new systems released to the public or deployed in your organization that has not undergone a security review.
- Verify your IT organization has controls to protect the integrity of the software products you are selling to or using on behalf of your customers.
- Verify your organization has a Release management process that requires input from the information security organization. Release management is the process intended to oversee the development, testing, deployment and support of software releases.
- Verify your organization has a Change management process that requires approvals from the information security organization. Change management is the process of ensuring no one can make system modifications without the modifications being reviewed and approved by a group of authorized individuals who have vetted the change and identified the risks associated with the changes to be acceptable.
Article Resources
Microsoft Updated Cybersecurity Papers on Supply Chain Security and Critical Infrastructure Protection
http://blogs.technet.com/b/security/archive/2014/05/06/revised-cybersecurity-papers-on-supply-chain-security-and-critical-infrastructure-protection.aspx