Contrast Security Raises $150 Million at ‘Unicorn’ Valuation

Code security company Contrast Security this week announced that it has closed $150 million Series E funding round at a billion-dollar valuation, making the company the latest cybersecurity unicorn.

The company offers a platform that helps developers create more secure applications by discovering vulnerabilities in code, detecting what libraries are being used, and goes as far as providing embedded runtime exploit prevention that analyzes application runtime to prevents and confirm exploitability of bugs.

Contrast says the investment will help it meet demand for its platform and that it will use the funds to accelerate global expansion plans, to further gain market share. The new infusion of cash will also help the company “execute on strategic opportunities and acquisitions.”

According to Contrast, its solutions secure code for numerous large organizations worldwide, including American Red Cross, AXA, BMW, DocuSign, SOMPO Japan, and Zurich, along with other global Fortune 500 enterprises.

Founded in 2014 and headquartered in Los Altos, California, Contrast provides customers with an Application Security Platform designed to help secure code faster through identifying vulnerabilities and providing context-specific guidance on how to address them.

 

The funding round was led by Liberty Strategic Capital, with existing investors Acero Capital, AXA Venture Partners, Battery Ventures, General Catalyst, Microsoft’s M-12 Fund, and Warburg Pincus, contributing as well.

Related: Socure Raises $450 Million at $4.5 Billion Valuation

Related: Logging and Security Analytics Firm Devo Raises $250 Million at $1.5B Valuation

Related: Dragos Becomes First Industrial Cybersecurity Unicorn After Raising $200 Million

Related: Compliance-as-a-Service Platform Laika Raises $35 Million

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/contrast-security-raises-150-million-unicorn-valuation




Remote Code Execution Flaw in Palo Alto GlobalProtect VPN

Palo Alto remote code execution flaw

Cybersecurity vendor Palo Alto Networks is calling urgent attention to a remote code execution vulnerability in its GlobalProtect portal and gateway interfaces, warning that it’s easy to launch network-based exploits with root privileges.

The Santa Clara, Calif.-based Palo Alto Networks said the security defect can be exploited to allow an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges.

The company slapped a critical-severity rating on the CVE-2021-3064 vulnerability and noted that an attacker must have network access to the GlobalProtect interface to exploit this issue.

Palo Alto said the issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.17.  High-priority patches have been issued for enterprise customers running PAN-OS 8.1.17 and all later PAN-OS versions.

The company said it was not aware of any malicious exploitation of this issue but confirmed that attack surface management firm Randori had fitted successful exploits into its red-teaming software product.

[ READ: Zero-Days Under Attack: Microsoft Plugs Exchange Server, Excel Holes ]

According to a vulnerability report from the Randori Attack Team, the vulnerability affects PAN firewalls using the GlobalProtect Portal VPN and allows for unauthenticated remote code execution on vulnerable installations of the product. 

“Our team was able to gain a shell on the affected target, access sensitive configuration data, extract credentials, and more. Once an attacker has control over the firewall, they will have visibility into the internal network and can proceed to move laterally,” Randori said.

The company is withholding technical details on the vulnerability for 30 days to allow Palo Alto Networks customers to apply available fixes.

Related: VMware Calls Attention to High-Severity vCenter Server Flaw

Related: US Cyber Command: Foreign APTs Will Exploit Palo Alto Bug

Related: Google Triples Bounty for Linux Kernel Exploitation

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

https://www.securityweek.com/remote-code-execution-flaw-palo-alto-globalprotect-vpn




VMware Working on Patches for Serious vCenter Server Vulnerability

VMware announced on Wednesday that it’s working on patches for a potentially serious privilege escalation vulnerability affecting vCenter Server.

The vulnerability is tracked as CVE-2021-22048 and it has been assigned an “important” severity rating, which is equivalent to “high severity” based on its CVSS score of 7.1.

“The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authentication mechanism,” VMware said in its advisory. “A malicious actor with non-administrative access to vCenter Server may exploit this issue to elevate privileges to a higher privileged group.”

The vulnerability impacts vCenter Server 6.7 and 7.0, as well as Cloud Foundation 3.x and 4.x. Until patches become available, VMware has published a document with workaround instructions.

“Workaround for CVE-2021-22048 is to switch to AD over LDAPS authentication/Identity Provider Federation for AD FS (vSphere 7.0 only) from Integrated Windows Authentication (IWA),” the virtualization giant explained.

Yaron Zinar and Sagi Sheinfeld of CrowdStrike have been credited for reporting the issue to VMware.

There is no mention of the vulnerability being exploited for malicious purposes, but the lack of patches and the fact that the security hole was reported by CrowdStrike could suggest that it has been exploited.

SecurityWeek has reached out to CrowdStrike, but the cybersecurity firm has declined to share any additional information.

Threat actors exploiting vCenter Server vulnerabilities is not unheard of so it’s important that organizations deploy patches or workarounds as soon as possible. There are several thousand instances of vCenter Server that are exposed to the internet.

Related: VMware vCenter Servers in Hacker Crosshairs After Disclosure of New Flaw

Related: Hackers Can Compromise VMware vCenter Server Via Newly Patched Flaw

Related: Critical VMware vCenter Server Flaw Can Expose Organizations to Remote Attacks

Related: VMware Calls Attention to High-Severity vCenter Server Flaw

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/vmware-working-patches-serious-vcenter-server-vulnerability




Critical Flaw in WordPress Plugin Leads to Database Wipe

A major security vulnerability in the WP Reset PRO WordPress plugin could be exploited by an authenticated user to wipe the entire database of a website, according to a warning from researchers at Packstack (formerly WebARX).

The issue can be exploited by any authenticated user, regardless of their authorization, to wipe all tables in a WordPress installation’s database.

This would trigger the restart of the WordPress installation process. An attacker could abuse this to create an administrator account onto the WordPress website (an admin account must be created to complete the installation process), according to a Patchstack advisory.

An attacker could further exploit the newly created account to upload malicious plugins to the website, or even install trojan backdoors.

[ READ: WordPress 5.8.1 Patches Several Vulnerabilities ]

WP Reset PRO aims to help site administrators to easily reset a website’s database to the default installation while leaving files intact, to restore damaged sites, and remove customizations or parts of the site.

WP Reset PRO registers a few actions in the admin_action_* scope, including table deletion operation, but no check is performed to learn whether the user is indeed authorized to perform such an action, and because a nonce token to prevent CSRF attacks isn’t validated or checked.

Because of this vulnerability, “someone could simply visit the homepage of the site to start the WordPress installation process,” Patchstack warned.

WebFactory Ltd, which develops both the WP Reset and its PRO version, addressed the issue in version 5.99 of the plugin, by adding an authentication and authorization check, along with a check for a valid nonce token.

“It’s quite a destructive vulnerability, quite a problem for e-commerce and other sites that have open registration,” Patchstack CEO Oliver Sild told SecurityWeek.

Related: WordPress 5.8.1 Patches Several Vulnerabilities

Related: Over 580 WordPress Vulnerabilities Disclosed in 2020: Report

Related: Hacker Exploiting Vulnerabilities in Thrive Theme WordPress Plugins

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/critical-flaw-wordpress-plugin-leads-database-wipe




South Korean Users Targeted with Android Spyware ‘PhoneSpy’

More than 1,000 mobile phone users in South Korea have been targeted with a powerful piece of Android spyware as part of an ongoing campaign, according to a new report from Zimperium zLabs.

Dubbed PhoneSpy, the malware was designed with extensive spyware capabilities inside, such including data theft, audio and video capture, and location monitoring.

The malware was not found in any Android application stores, a suggestion that the attackers are employing different distribution methods, such as social engineering and web redirects. A total of 23 applications used in this campaign were identified to date, according to a report from Zimperium.

The threat masquerades as various lifestyle applications that allow users to watch TV or videos, or browse photos, but in reality it steals as much data from the infected devices as possible, including calls, messages, photos, and other types of data.

[ READ: Sophisticated APT Group Burned 11 Zero-Days in Mass Spying Operation ]

It also allows an attacker to remotely control the compromised devices, providing them with access to the camera and microphone to take pictures and record audio and video, as well as to the GPS, to get the device’s precise location.

In addition to grabbing calls, contact information, and messages from the infected devices, PhoneSpy can send SMS messages with attacker-controlled content. It can also display a fake login page for the Kakao Talk messaging app to steal users’ credentials.

“While the victims have been limited to South Korea, PhoneSpy is an example of how malicious applications can disguise their true intent. When installed on victims’ devices, they leave personal and corporate data at risk,” Zimperium said.

Related: Amnesty Links Indian Cybersecurity Firm to Spyware Attack on African Activist

Related: Google: Sophisticated APT Group Burned 11 Zero-Days in Mass Spying Operation

Related: Apple Points to Android Malware Infections in Argument Against Sideloading on iOS

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/south-korean-users-targeted-android-spyware-phonespy




RPC Firewall Dubbed ‘Ransomware Kill Switch’ Released to Open Source

Today at Black Hat London, Zero Networks announced the release of its RPC firewall – also dubbed the ‘ransomware kill switch’ – into open source. The tool provides granular control over RPC, capable of blocking the use of lateral movement hacker tools and stopping almost all ransomware in its tracks.

Microsoft’s Remote Procedure Call (MS-RPCE) lies at the heart of Windows. It effectively manages the relationship between clients and servers – if a client requests from a server, it goes through RPC; This happens both locally and between remote devices.

RPC was introduced into Windows back in the days of Windows 2000 and has been ever-present since then. This has two effects. Firstly, RPC was built with little or no security. While there is a documented Event for a remote RPC call, it hasn’t been implemented. Further, the Event Tracing for Windows (ETW) option will likely result in millions of RPC client/server events every hour, but doesn’t tell you where the call came from, nor which user was concerned.

Secondly, RPC use has spread over time into every aspect of Windows computing. “There is almost nothing you can do without RPC — whether to get information or change information. Everything is done via RPC,” explains Benny Lakunishok, co-founder and CEO at Zero Networks, and another product of Israel’s IDF conveyor belt.

Normal attempts to block RPC ports could rapidly cause the network to fail. For example, the most sensitive servers such as Domain Controllers must have RPC services open to any asset in the network for the domain to function properly. “If you try to shut down RPC, you will be shutting down the functionality of Windows itself,” added Lakunishok.

It is there, it is used by the bad guys, and there is nothing you can do about it. Any Windows host which is accessible over the network, offers an attacker hundreds, if not thousands, of RPC functions to choose from for exploitation – either by using stolen credentials or a vulnerability.

Over the last year, a relatively small number of ransomware gangs have been responsible for the majority of big game hunting ransom attacks: Maze, Conti, REvil, Netwalker, DoppelPaymer, DarkSide and Avaddon. In every case–with the exception of Avaddon– RPC has been used for reconnaissance and lateral movement. 

The common hacker tools used for lateral movement – such as BloodHound, mimikatz, CobaltStrike, PS-Empire, PsExec and WMIC – all use RPC. But you cannot simply block the use of RPC. And even if you are able to detect something, detection is often too late.

To solve this problem and provide auditing, visibility and control over RPC calls, Zero Networks developed an agent that scans the machine and finds the RPC processes. “The agent hooks into those it finds in a legitimate manner (nothing malicious) so that it sees everything.,” Lakunishok told SecurityWeek. 

“We provide full auditing and visibility so we can see, these are calling these RPC functions. Finally, we can map who is calling which RPC function. We can also create a whitelist. Even though RPC supports thousands of functions, only a few are really needed. We allow those and block everything else. We provide granular control over what RPC is doing. We can block the rest. Down the drain goes most of the attack tactics, and tools.”

The RPC Firewall will not stop all attacks. APT attackers will be able to find and use routes other than RPC – something tackled by Zero Networks’ commercial products. But the common lateral movement tools can be blocked, and network takeover stopped for all but the more advanced attackers.

More importantly in today’s threat landscape, something like 86% of ransomware will be stopped in its tracks. “Ransomware is a bit simpler in the way it operates,” continued Lakunishok. “If you block just one of the things it uses, it simply doesn’t move anymore.”

Zero Networks has now open sourced this tool. It can be found on GitHub.

Related: NTLM Relay Attack Abuses Windows RPC Protocol Vulnerability

Related: Google Details How It Protects Data Within Its Infrastructure

Related: CrowdStrike Discloses Details of Recently Patched Windows NTLM Vulnerability

Related: Turla Cyber-Spies Target European Government With Multiple Backdoors

view counter

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Previous Columns by Kevin Townsend:
Tags:

https://www.securityweek.com/rpc-firewall-dubbed-ransomware-kill-switch-released-open-source




Citrix Patches Critical Vulnerability in ADC, Gateway

Citrix this week released patches for a couple of vulnerabilities affecting Citrix ADC, Gateway, and SD-WAN, including a critical bug leading to denial of service (DoS).

The most severe of the two bugs is CVE-2021-22955, a critical security hole that could lead to a DoS condition on appliances that have been configured as a VPN (Gateway) or AAA virtual server.

The security flaw was identified in Citrix Application Delivery Controller (ADC, formerly NetScaler ADC), and Gateway (formerly NetScaler Gateway).

Tracked as CVE-2021-22956, the second flaw could lead to the temporary disruption of the Management GUI, Nitro API, and RPC communication.

Considered low severity, the bug affects ADC and Gateway, as well as SD-WAN WANOP edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO, Citrix explains in an advisory.

Citrix addressed both vulnerabilities in ADC and Gateway 13.1-4.43 and later releases of 13.1, 13.0-83.27 and later releases of 13.0, 12.1-63.22 and later releases of 12.1, and 11.1-65.23 and later releases of 11.1, and in ADC 12.1-FIPS 12.1-55.257 and later releases of 12.1-FIPS.

CVE-2021-22956, Citrix says, was addressed in SD-WAN WANOP Edition 11.4.2 and later releases of 11.4, and 10.2.9c and later releases of 10.2.

“Please note that the WANOP feature of SD-WAN Premium Edition is not impacted,” Citrix notes.

Affected Citrix customers are encouraged to install the available patches as soon as possible.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged users and administrators to review Citrix’s advisory and apply the necessary updates.

Related: Citrix Patches Hypervisor Vulnerabilities Allowing Host Compromise

Related: Citrix Patches DoS Vulnerabilities in Hypervisor

Related: Citrix Releases Updates to Prevent DDoS Attacks Abusing Its Appliances

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/citrix-patches-critical-vulnerability-adc-gateway




ICS, OT Cybersecurity Incidents Cost Some U.S. Firms Over $100 Million: Survey

A report published on Wednesday by the Ponemon Institute and industrial cybersecurity firm Dragos shows that the average cost of a security incident impacting industrial control systems (ICS) or other operational technology (OT) systems is roughly $3 million, and some companies reported costs of over $100 million.

The report is based on data from a survey of 600 IT, IT security, and OT security practitioners conducted by the Ponemon Institute in the United States.

Twenty-nine percent of respondents admitted that their organization was hit by ransomware in the past two years, and more than half of them said they had paid an average ransom of more than $500,000. Some organizations reported paying more than $2 million.

ICS, OT ransomware payments

Nearly two-thirds of respondents said they experienced an ICS/OT cybersecurity incident in the past two years. The most common causes were negligent insiders, a maintenance-related issue, or IT security incidents “overflowing” to the OT network due to poor segmentation between IT and OT.

On average, it took organizations 170 days to detect an incident, 66 days to investigate it, and 80 days to remediate the incident. A calculation based on the total number of hours it would take a team of six people to detect, investigate, and remediate an incident showed a total labor cost of nearly $1 million. Adding roughly $2 million for downtime, legal costs, regulatory fines, and equipment replacement results in an average total cost of approximately $3 million.

Of the companies that confirmed suffering an incident, 1% said the total cost of the ICS/OT incident exceeded $100 million, and 2% reported costs between $10 million and $100 million. Overall, 13% of respondents said the incident had cost them more than $1 million.

Learn more about OT security at SecurityWeek’s ICS Cyber Security Conference and SecurityWeek’s Security Summits virtual event series

The report published by Dragos and Ponemon focuses on the “cultural divide” between IT and OT teams and its impact on their ability to secure both IT and OT environments.

Half of respondents cited cultural differences between security, IT and engineers as the main challenge when it comes to collaboration between IT and OT teams. Technical differences and clear ownership of industrial cyber risk were also cited by over 40% of respondents.

Several other issues were identified by the survey:

  • C-level executives and the board are not regularly informed about the efficiency, effectiveness, and security of their ICS/OT cybersecurity program;
  • Many senior managers lack awareness of the risks and threats to OT environments, which results in inadequate resource allocation;
  • Reporting relationships and accountability for OT security are not properly structured and become deterrents to investing in OT and ICS cybersecurity;
  • The level of cybersecurity maturity for ICS/OT is inadequate in many organizations.

Related: Water Sector Security Report Released Just as Another Water Plant Hack Comes to Light

Related: Over 90% of OT Organizations Experienced Cyber Incidents in Past Year: Report

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/ics-ot-cybersecurity-incidents-cost-some-us-firms-over-100-million-survey




Socure Raises $450 Million at $4.5 Billion Valuation

Digital identity verification provider Socure on Tuesday announced that it has closed a $450 million Series E funding round, at a $4.5 billion valuation. To date, the company has raised nearly $650 million.

The new funding round was announced roughly half a year after Socure closed a $100 million Series D round, at a $1.3 billion valuation.

The Series E investment round was led by Accel and funds and accounts advised by T. Rowe Price Associates. New investors Bain Capital Ventures and Tiger Global, along with existing investors Commerce Ventures, Sorenson Ventures, and Scale Venture Partners, also contributed.

Socure, which was founded in 2012 and is based in New York, will use the funding to accelerate investment in product innovation, and to enhance its fully-automated, predictive analytics ID+ platform to prevent third party and synthetic fraud, along with payment and first party fraud.

Socure ID+ is already used by some of the largest banks, credit card issuers, and Buy Now, Pay Later (BNPL) providers, as well as fintechs and crypto exchanges.

“With this additional capital, we will substantially increase our level of commercial velocity and intensity in solving complex customer and societal problems, while maintaining our Day 0 founder’s mentality and continuing to attract the market’s best product, data science, and engineering minds to join our already incredibly talented team,” Johnny Ayers, Socure founder and CEO, said.

Related: Compliance-as-a-Service Platform Laika Raises $35 Million

Related: Encryption-as-a-Service Provider Vaultree Emerges From Stealth

Related: Quantum Cybersecurity Provider QuintessenceLabs Raises $18 Million

Related: Neosec Emerges From Stealth With $20.7 Million in Funding

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/socure-raises-450-million-45-billion-valuation




The Rising Threat Stemming From Identity Sprawl

Identity sprawl in the age of remote working and business transformation is a threat to cybersecurity

The identity sprawl generated by remote working and business digitization is out of control. This is the clear message from a global survey of more than 1,000 IT professionals.

The survey was undertaken by Dimensional Research for One Identity, a provider of unified identity security, and returned similar results across all industry verticals. 

Larry Chinski, One Identity’s VP of global IAM strategy, described the three primary results of the survey (PDF). These are the rapidly expanding and almost unchecked growth in the number of identities in use (sprawl); the large number of different tools used to manage the identities, leading to poor overall visibility; and the need to find a unified approach to identities as a solution. 

“We found that organizations have experienced an enormous amount of identity sprawl, especially over the last two years,” he told SecurityWeek. Eighty-four percent of the respondents said the number of identities they manage has more than doubled. Twenty-five percent said the number of identities they manage has increased by a factor of 10 or more. And 95% of the respondents are struggling to manage them.

“To get more control over their identities,” continued Chinski, “companies are investing in more and different types of identity-based tools. But the more tools you drop on the problem, the more siloed and fragmented it becomes.” The result is poor visibility into the overall problem.

Fifty-one percent of the respondents struggle with this lack of visibility; 55% complain that it complicates provisioning and deprovisioning; and 85% have employees with more privileged access than is needed for their work.

“So, although the tools are good and perform well,” Chinski told SecurityWeek, “the problem is that each one of those tools doesn’t necessarily understand the identities it is managing are the same identities that other tools are managing. When you create that fragmented state, you don’t have a single way to manage identities from a central location.”

This leads to the third conclusion from the survey: users need and are beginning to demand a unified solution to the identity problem. “We found that the ability to unify those tools is something that 62% of respondents would like to achieve,” he said, “and 45% believe they would benefit from end-to-end unification of all the identities and accounts.”

One of the problems with many surveys is that they are designed as marketing tools to justify the vendor’s own product. “I wish that were true here,” said Chinski. “I wish we could turn round and say ’we have the solution’. But we don’t – at least, not yet.”

The problem is getting worse. Two years ago, it was relatively easy to get good identity protection because everybody came into a central office protected by firewalls and other perimeter defenses. “But when people are out in the remote, you have to manage on top of the identity – and that’s where it gets more difficult,” he said. “That’s why a unified approach is the best way to manage the identity sprawl and to resolve that fragmented approach to identities.”

There is no one product that solves this problem. “The survey,” concludes Chinski, “describes a paradigm shift and philosophy around cyber security that needs to be employed. The different fragmented existing tools need to be unified. We haven’t got the one tool to do that yet. So, the key finding of the survey will hopefully get individuals and customers to understand that this is a process. Now you can start that process anywhere with different types of technology solutions, but the survey indicates that a new philosophy and methodology needs to be applied.”

Related: Are Overlapping Security Tools Adversely Impacting Your Security Posture?

Related: CISA Expands ‘Bad Practices’ List with Single-Factor Authentication

Related: Pass the Hash Remains a Poorly Defended Threat Vector

view counter

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Previous Columns by Kevin Townsend:
Tags:

https://www.securityweek.com/rising-threat-stemming-identity-sprawl