{"id":51527,"date":"2022-09-22T12:35:14","date_gmt":"2022-09-22T04:35:14","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=51527"},"modified":"2022-09-22T12:35:16","modified_gmt":"2022-09-22T04:35:16","slug":"kaspersky-reveals-external-cybersecurity-loopholes-in-sea","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2022\/09\/22\/kaspersky-reveals-external-cybersecurity-loopholes-in-sea\/","title":{"rendered":"Kaspersky reveals external cybersecurity loopholes in SEA"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Cyberattacks can be prevented before an attacker is inside the internal network. Threat monitoring allows organizations to take action and properly neutralize a threat before it can exploit any existing vulnerabilities and affect the target institutions.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Kaspersky unveiled the results of its <a rel=\"noreferrer noopener\" href=\"https:\/\/securelist.com\/external-attack-surface-and-ongoing-cybercriminal-activity-in-apac-region\/107430\/\" target=\"_blank\">Digital Footprint Intelligence<\/a> (DFI) report covering the external threats for a selection of countries from the Asia Pacific (APAC) region in 2021, including the six key countries in Southeast Asia (SEA).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The report\u2019s sole purpose is to create awareness about security threats and demonstrate effective approaches to risk mitigation for widespread attacks with high business impact.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Cybercriminals\u2019 exploitation capabilities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The rapidly growing share of adversaries\u2019 initial access approach is the exploitation of 1-day vulnerabilities. Complicated business processes are forced to leave services on the perimeter, which in turn increases the external attack surface.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With the help of public sources and specialized search engines, Kaspersky collected information on 390,497 services available from public networks and analyzed them for key security issues and vulnerabilities.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Analysis revealed that in 2021, almost every fifth of the vulnerable services contained more than one vulnerability, thereby increasing the chances of an attacker performing a successful attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">All industry sectors, analyzed in the report, in all countries have issues with application of security updates for publicly available services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Government institutions (major personally identifiable information (PII) processors and providers of critical services for citizens) are potential incident-generators by a huge margin.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Singapore has a low number of vulnerabilities and an outstanding low ratio between the number of services and the sum of vulnerabilities in them, while Vietnam, Indonesia, Thailand and Malaysia have the highest ratio among SEA countries<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh4.googleusercontent.com%2FhpNhOrGAvAhEgZDpSz_QhpCmr8iN2ZWNa2nKMvWRfd0tj-4D3vX_IFQaYRJ1kkP2pi2JyZBhTIyskpLtU8rRiUc9KWWNBvO_sJJlr5fS9cTD4xGyv-KEqoJo-3JwWyqZgY8SmpmySTGKhDHxF010Jwm9YzVUVFB0bkTTyCEyhscE9zzfqYlI1lTZPw&amp;t=1663821234&amp;ymreqid=27f3344f-c727-c29c-1c7a-f0000601db00&amp;sig=uEtXiDrYviZu.fjieI4feA--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Figure 1. Distribution of vulnerable services<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In terms of the share of vulnerabilities with publicly available exploits, 3 countries out of TOP-5 are located in Southeast Asia (SEA) \u2013 these are Malaysia, Vietnam, and Philippines.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/ecp.yusercontent.com\/mail?url=https%3A%2F%2Flh3.googleusercontent.com%2FYJUlQ8BCJL_pgEUDgZ34lOJecniMSrHXdoHLE4Qjvt-hY_kPpJx7P-8BV8rLu0ZHaYOZ9Er2QgefUHNOnETX8HntAYO-bqiVmyV9zvYTMz7FICsNQwCXQltuJ8V44EioCNaOMGwVkka4ZNZkwx-Ti63Ldf19MMEU0WFSi_r8sYIzesFbFAGwPtbpEA&amp;t=1663821234&amp;ymreqid=27f3344f-c727-c29c-1c7a-f0000601db00&amp;sig=HnPTQIV.vSK6.vVApdSdvQ--~D\" alt=\"\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Figure 2. Distribution of vulnerable services with publicly available exploits<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From Kaspersky\u2019s practice in incident response handled by Global Emergency Response Team (GERT) and CISA advisory adversaries use a well-known list of vulnerabilities to exploit organization defenses.&nbsp; While researching the security problems of companies from the APAC region, Kaspersky experts observed a number of commonly used vulnerabilities dubbed ProxyShell and ProxyLogon. Exploits for these vulnerabilities are easily available on the Internet, therefore, they can be easily exploited by even a low-skilled attacker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While ProxyShell is quite common in China and in Vietnam, the countries most affected by ProxyLogon are:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>In Government bodies \u2013 Thailand<\/li><li>In Financial \u2013 China<\/li><li>In Healthcare \u2013 Philippines<\/li><li>In Industrial \u2013 Indonesia<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">ProxyShell is a group of vulnerabilities for Microsoft Exchange servers &#8211; <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-31206\">CVE-2021-31206<\/a>, <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-31207\">CVE-2021-31207 <\/a>, <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34473\">CVE-2021-34473<\/a>, and <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-34523\">CVE-2021-34523<\/a>. ProxyLogon group includes <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26855\">CVE-2021-26855<\/a>, <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26857\">CVE-2021-26857<\/a>, <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-26858\">CVE-2021-26858<\/a>, and <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2021-27065\">CVE-2021-27065<\/a>. The vulnerabilities from the both groups enable an actor to bypass authentication and execute code as a privileged user.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The best defense against these vulnerabilities is to keep public-faced systems updated with the latest <a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/msrc.microsoft.com\/update-guide\/en-us\/vulnerability\/CVE-2021-31207\">patches<\/a> and product versions. Companies should also avoid direct access to Exchange Server from the Internet. Kaspersky products protect against vulnerabilities from both groups \u2013 ProxyShell and Proxy-logon.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Credential brute force attacks&nbsp;<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">A great share of attackers\u2019 initial accesses leading to cybersecurity incidents are related to services with remote access or management features. One of the best-known examples is RDP (Remote Desktop Protocol). It is Microsoft\u2019s proprietary protocol that enables a user to connect to another computer through a network of computers running Windows.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RDP is widely used by both system administrators and less-technical users to control servers and other PCs remotely but this tool is also what intruders exploit to penetrate the target computer that usually houses important corporate resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Last year, Kaspersky monitored 16,003 remote access and management services available for exploit. Indonesia, India, Bangladesh, the Philippines, and Vietnam provide the maximum facilities for an attacker to gain remote access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Government institutions are serving more than 40% of the attack surface for brute force attacks and credential leaks reuse.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cClearly, cybercriminals are busy uncovering possible entry points in the region. From hunting for unpatched software, one-day vulnerabilities, and exploitable remote access and management services, malicious actors have a lot of options to infect lucrative industries. In short, a cyberattack is like a ticking bomb. While worrisome, reports such as our Digital Footprint Intelligence can be used as a tool to guide the cybersecurity capacity building of concerned organizations. If you know your weak areas, it\u2019s easier to prioritize,\u201d comments Chris Connell, Managing Director for Asia Pacific at Kaspersky.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To protect your businesses from such threats, Kaspersky experts also recommend that you:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Regulate every major change to the network perimeter hosts, including services or applications launching, exposing new APIs, software installation and updating, network devices configuration and so on. All changes should be reviewed from the perspective of security impact.<\/li><li>Develop and implement reliable procedures for identifying, installing, and verifying patches for products and systems.<\/li><li>Focus your defense strategy on detecting lateral movements and data exfiltration to the internet. Pay special attention to outgoing traffic to detect cybercriminal connections. Backup data regularly. Make sure you can quickly access it in an emergency.<\/li><li>Use solutions like<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/endpoint-detection-response-edr\">&nbsp;Kaspersky Endpoint Detection and Response<\/a>&nbsp;and the&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/enterprise-security\/managed-detection-and-response\">Kaspersky Managed Detection and Response<\/a>&nbsp;service, which help to identify and stop the attack in the early stages, before the attackers achieve their goals.<\/li><li>Use a reliable endpoint security solution, such as&nbsp;<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/small-to-medium-business-security\/endpoint-advanced\">Kaspersky Endpoint Security for Business<\/a>&nbsp;(KESB) that is powered by exploit prevention, behavior detection, and a remediation engine that is able to roll back malicious actions. KESB also has self-defense mechanisms that can prevent its removal by cybercriminals.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky unveiled the results of its Digital Footprint Intelligence (DFI) report covering the external threats for a selection of countries from the Asia Pacific (APAC) region in 2021, including the six key countries in Southeast Asia (SEA).<\/p>\n","protected":false},"author":6,"featured_media":48152,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,101,54,2103],"class_list":["post-51527","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-kaspersky","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51527","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=51527"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/51527\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/48152"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=51527"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=51527"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=51527"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}