News: 1674196033

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Miscreants sure do love ransacking cloud networks, more so than before

(2023/01/20)


As enterprises around the world continue to move to the cloud, cybercriminals are following right behind them.

There was a 48 percent year-over-year jump in 2022 in cyberattacks on cloud-based networks, and it comes at a time when 98 percent of global organizations use cloud services, or at least that's what Check Point researchers say they've noticed.

The increases were experienced in various regions, including Asia (with a 60 percent jump), Europe (50 percent), and North America (28 percent), the infosec bods wrote in a [1]report this week.

[2]

"The rise in attacks on the cloud was driven both by an overall increase in cyberattacks globally (38 percent overall in 2022, compared to 48 percent in the cloud) and also by the fact that it holds much more data and incorporates infrastructure and services from large amounts of potential victims, so when exploited the attacks could have a larger impact," Omer Dembinsky, data group manager at Check Point, told The Register .

Cloud incorporates infrastructure and services from large amounts of potential victims, so when exploited the attacks could have a larger impact

Human error is a significant factor in the vulnerability of cloud-based networks, as are "the built-in characteristic that a cloud-based network should be accessible from outside the network," Dembinsky said.

Check Point researchers noted examples in recent years that highlight the dangers of attacks on networks hosted in or managed from the cloud, including a security breach of AIS, a cellular network in Thailand, in which 8 billion internet activity records were accidentally [3]exposed . It may cost AIS as much as $58 billion to resolve the disaster, some say.

[4]

[5]

And, we're reminded by Check Point, in November a state-sponsored Iranian crew exploited the high-profile [6]Log4j vulnerability to infiltrate an unpatched VMware Horizon server within the US federal government and deploy an XMRig cryptominer.

What that specific server compromise has to do with cloud networking is not quite clear to us vultures but anyhow, the exploitation of the Log4j flaw highlighted another data point observed by Check Point: the use of newer CVE-labeled vulnerabilities, or those disclosed since 2020. According to the infosec shop's numbers, 22.9 percent of attacks on on-premises networks involved these newer flaws, compared with 27.4 percent of assaults on cloud-based networks.

[7]

Another way of looking at it is that the majority of bugs exploited by miscreants are years and years old, likely targeting forgotten or neglected systems that haven't been patched.

[8]How Intel and AMD hope to win the cloud security game

[9]Microsoft tries again to ignite interest in DevOps cloud security

[10]If you're wondering why Google blew $5b on Mandiant, this may shed some light

[11]AWS strains to make Simple Storage Service not so simple to screw up

Meanwhile, a [12]vulnerability that could be abused to achieve remote code execution (RCE) on compromised VMware Workspace systems had a greater "impact" on cloud networks, Check Point said. By greater impact, we'll read that as: exploitation of this flaw against a cloud target caused more damage and disruption or more data to be stolen than what you'd typically see with on-prem systems.

That makes sense because, as we said, targeting cloud-hosted systems can affect a greater number of people due to the concentration of data and resources.

Other programming blunders that had a greater impact against cloud systems when exploited include a Microsoft Exchange Server RCE flaw, a Text4shell RCE, and a F5 Big IP bug. Check Point said it came to these conclusions after studying stats from its IT defense products.

"In cloud-based networks, some of this patching is done by the cloud providers, but it is still up to the network and security admins to make sure all their infrastructure is not vulnerable," Dembinsky said.

[13]

And all that info of yours accessible via the cloud is too valuable for crooks to ignore, Tom Kellerman, senior vice president of cyber security at Contrast Security, told The Register .

"Cybercrime cartels and rogue nation intelligence services appreciate that the future is island hopping, which lies in colonizing the cloud," he said. "This also means that defense capabilities in cloud networks need to improve."

It's befuddling that we aren't doing any better, security-wise, in the cloud than we did before the cloud

According to Check Point, that means taking such steps as using zero-trust cloud network security controls, incorporating security and compliance earlier in the development lifecycle, avoid misconfigurations, and using tools such as an intrusion detection and prevention systems and next-generation web application firewalls.

Roger Grimes, an evangelist at KnowBe4, told The Register no one should be surprised that miscreants are increasing their attacks on cloud networks, adding that "organizations are using more cloud resources than ever before. Hackers have always gone to what's popular. That's never not been the case."

What is surprising is that while there are attacks specific to cloud resources, most are the same as those perpetrated against on-premises systems, Grimes said. They include everything from social engineering and credential theft to unpatched software, overly permissive permissions, and misconfigurations.

"Defenders don't have to learn something new," he said. "The cloud is a new paradigm, but the way cloud resources are successfully attacked the most isn't. In that light, it's even more befuddling that we aren't doing any better, security-wise, in the cloud than we did before the cloud. You think we would have taken the lessons learned and then moved them to the cloud." ®

Get our [14]Tech Resources



[1] https://blog.checkpoint.com/2023/01/17/check-point-research-flags-a-48-growth-in-cloud-based-networks-attacks-in-2022-compared-to-2021/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8p0UvSAx2agOegUjX-X7gAAAM4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://rainbowtabl.es/2020/05/25/thai-database-leaks-internet-records/?=may-23-2020

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8p0UvSAx2agOegUjX-X7gAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8p0UvSAx2agOegUjX-X7gAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/11/16/iranian_cyberspies_log4j/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8p0UvSAx2agOegUjX-X7gAAAM4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2022/05/12/intel_amd_security/

[9] https://www.theregister.com/2022/10/12/microsoft_ignite_security/

[10] https://www.theregister.com/2022/10/11/google_mandiant_brain/

[11] https://www.theregister.com/2022/12/14/aws_simple_storage_service_simplified/

[12] https://www.theregister.com/2022/04/07/vmware_security_vmworld_explore/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8p0UvSAx2agOegUjX-X7gAAAM4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://whitepapers.theregister.com/



Potemkine!

"You think we would have taken the lessons learned and then moved them to the cloud". Yes, of course! Beancounters are always happy to throw money in cybersecurity, aren't they? It isn't as they asked to move everything in the cloud because they thought it would be less expensive. I also love the sentence that one should 'avoid misconfigurations', because IT has always the competent resources in sufficient number and all the time required to do things right. I would have another advice: bad people shouldn't do bad things, because it's bad you know.

DJO

I have that exact same sentence in my clipboard but you beat me to it. I was just astonished by the naivety - how can someone so insulated from the realities of life survive in what passes for "the real world"?

Well duh

Pascal Monett

" As enterprises around the world continue to move to the cloud, cybercriminals are following right behind them "

Pro tip : they want to get to the data. You put the data into The Cloud TM , they attack The Cloud TM .

Not rocket science and eminently foreseeable.

It is a very humbling experience to make a multimillion-dollar mistake, but
it is also very memorable. I vividly recall the night we decided how to
organize the actual writing of external specifications for OS/360. The
manager of architecture, the manager of control program implementation, and
I were threshing out the plan, schedule, and division of responsibilities.
The architecture manager had 10 good men. He asserted that they
could write the specifications and do it right. It would take ten months,
three more than the schedule allowed.
The control program manager had 150 men. He asserted that they
could prepare the specifications, with the architecture team coordinating;
it would be well-done and practical, and he could do it on schedule.
Furthermore, if the architecture team did it, his 150 men would sit twiddling
their thumbs for ten months.
To this the architecture manager responded that if I gave the control
program team the responsibility, the result would not in fact be on time,
but would also be three months late, and of much lower quality. I did, and
it was. He was right on both counts. Moreover, the lack of conceptual
integrity made the system far more costly to build and change, and I would
estimate that it added a year to debugging time.
-- Frederick Brooks Jr., "The Mythical Man Month"