Cisco Learning Network Store Promotions Page
Showing posts with label Cisco. Show all posts
Showing posts with label Cisco. Show all posts

3.31.2016

FBI issues warning over MSIL/Samas ransomware

 
The FBI has began seeking the assistance of companies in the US to streamline its investigation on an increasing ransomware threat in the country.
 
The FBI is looking into a strain of ransomware called MSIL/Samas, which has been encrypting data across entire networks rather than single computers, Reuters reports. The ransomware infects machines before encrypting data and asking for money in return of the access.
 
The investigating agency found that the group behind MSIL/Samas used Jexboss, a publicly available security program, to scan for vulnerable versions of the JBoss software, which will be followed by a malware attack on the vulnerable network, according to information Reuters has gathered.
 
To the dismay of companies, the malware, called Peyta, also finds and deletes the back-up files firms could use to restore data by overwriting a key Windows system file called the Master Boot Record, and includes ransomware variants that use different methods to lock up systems and force victims to pay.
 
IT firm Cisco said it saw Samas targeting firms involved in healthcare, wherein early versions of the malware charged a ransom of one bitcoin (£300) for every machine hit. This amount was later increased later to 1.5 bitcoins.
 
Cisco security analyst Nick Biasini said: "It is likely the malware author is trying to see how much people will pay for their files. They even added an option for bulk decryption of 22 bitcoin (£6,600) to decrypt all infected systems".
 
Published under license from ITProPortal.com, a Net Communities Ltd Publication. All rights reserved.
 
Photo Credit: bahri altay/Shutterstock
  
~ Phoebe Jennelyn Magdirila

2.18.2016

Cisco announces Firepower Next-Generation Firewall

 
Cisco has released a new firewall solution which aims to completely change how security services tackle cyber-threats.
 
The new product, Cisco Firepower Next-Generation Firewall (NGFW), is built to detect threats on a system, and not keep the system on a lockdown. Here’s how Cisco explains the new product
 
"Think of it as legacy NGFWs protecting 'homes' by securing windows and doors, whereas Cisco’s approach is to identify, detect and protect against would-be burglars no matter how they try to gain access to a property", Cisco says NGFW is the first product in the industry to link contextual information about the usage of apps with threat intelligence.
 
To complement the firewall, the company has also unveiled the new Cisco Firepower 4100 Series appliances, for high-performing business apps. These dense, compact units are capable of 40GbE network connectivity. They will be managed through the Cisco Firepower Management Center, also a new Cisco product. The Center will serve as a 'nerve center', providing a rich, unified management console.
 
"Attackers are getting bolder and coordinating their efforts. The industrialization of hacking is putting businesses on the defensive against a growing group of adversaries that steal information for profit", said David Goeckeler, senior vice president and general manager at Security Business Group, Cisco.
 
"In the last three years, Cisco has spent billions in strategic cybersecurity acquisitions and internal innovations to help stay ahead of the world’s most malicious attacks that threaten organizations. For businesses to get real value and manage risk as they implement digital operational models, their security platforms need to integrate into the business and support growth opportunities. This means taking a threat-centric approach, with protection from the mobile endpoint to the cloud", added Goeckeler.
 
Published under license from ITProPortal.com, a Net Communities Ltd Publication. All rights reserved.
 
Image CreditKatherine Welles / Shutterstock
 
~ Sead Fadilpašić

1.20.2015

Users and IT teams are part of the security problem says Cisco

 
Careless user behavior and targeted malware campaigns are putting many industry sectors in danger from security breaches with the pharmaceutical and chemical industries at highest risk.
 
This is among the findings of the latest Annual Security report from networking specialist Cisco. It also finds that attackers are adapting their methods to make their campaigns harder to detect.
 
Among the changes are the rise of 'snowshoe spam' which involves sending low volumes of spam from a large set of IP addresses to avoid detection, and the use of less common exploit kits so as not to attract attention. There's also an increase in malicious combinations, sharing attacks between two files, for example Flash and JavaScript to make them harder to detect.
 
Users are the main target though and may also be unknowingly aiding cyber attacks. Throughout 2014, Cisco threat intelligence research has revealed that attackers have increasingly shifted their focus from servers and operating systems as more users are downloading from compromised sites leading to a 280 percent increase in Silverlight attacks along with a 250 percent increase in spam and malvertising exploits.
 
Users are increasingly targeted using web browser add-ons as a medium for distributing malware and unwanted applications. This approach too is proving successful because many users inherently trust add-ons or simply view them as benign.
 
"Attackers have become more proficient at taking advantage of security gaps. At any given time, we should expect for one percent of high-urgency vulnerabilities to be actively exploited while 56 percent of all OpenSSL versions are still vulnerable to Heartbleed," says Jason Brvenik, Principal Engineer, Security Business Group at Cisco. "Despite this, we see less than half of the security teams surveyed using standard tools like patching and configuration management to help prevent security breaches. Even with leading security technology, excellence in process is required to protect organizations and users from increasingly sophisticated attacks and campaigns".
 
The report also reveals that while many defenders believe their security processes are optimized, and their security tools are effective, in truth, their security readiness likely needs improvement. It concludes that corporate boards need to take a role in setting security priorities and expectations.
 
It sets out some basic principles for achieving security which include that security must be transparent and informative, that it must enable visibility and appropriate action and that it must be viewed as a 'people problem'.
 
A complete copy of the report is available from the Cisco website.
 
Image Credit: watcharakun/Shutterstock
 
~ Ian Barker