Release Notes: MITRE ATT&CK Matrix with Samples, Upgraded Automated Interactivity, Expanded Threat Coverage, and More

Welcome to ANY.RUN’s monthly updates, where we give you all the details on our latest features and enhancements. 

November has been a month of innovation at ANY.RUN, with major upgrades. We’ve launched Smart Content Analysis as part of Automated Interactivity, updated the home screen of TI Lookup featuring an interactive MITRE ATT&CK matrix connected with real-world samples, and expanded our detection capabilities with new YARA rules, signatures, and Suricata rules for even more comprehensive threat coverage. 

Here’s everything you need to know about our November updates! 

Product Updates 

Automated Interactivity: Stage 2 

Enabling Automated Interactivity inside ANY.RUN sandbox

Last year, we introduced Automated Interactivity, a feature that simulates user behavior inside the ANY.RUN sandbox to automatically trigger cyberattacks. It was a game-changer, helping analysts streamline tasks like clicking buttons or solving CAPTCHA challenges. 

Now, we’re thrilled to unveil Stage 2 of this feature: Smart Content Analysis, a major upgrade that offers better detection and execution of complex threats. 

This update makes your security workflow more efficient by enhancing detection capabilities, automating time-consuming tasks, and simplifying complex analyses. It saves analysts valuable time, provides deeper insights, and helps teams respond to threats faster and more effectively. 

What is Smart Content Analysis? 

Smart Content Analysis enhances Automated Interactivity by analyzing and detonating malware and phishing attacks at every step of the kill chain. Here’s how it works: 

  • Identifying content: It scans for URLs, email attachments, or hidden malicious components. 
  • Extracting key data: This includes extracting URLs from QR codes or bypassing rewritten links from security filters. 
  • Simulating actions: It interacts with extracted content, such as opening links, solving CAPTCHA challenges, or launching payloads. 
ANY.RUN sandbox automatically solving CAPTCHA problems

Automated Interactivity is available to Hunter and Enterprise-plan users and can be manually enabled in any sandbox session.  

Black Friday 2024: Get up to 3 sandbox licenses for free 



See details


MITRE ATT&CK Techniques with Real-World Samples inside TI Lookup 

We’re thrilled to announce a major update to TI Lookup, now featuring a redesigned home screen integrated with the MITRE ATT&CK matrix. This upgrade turns the matrix into an interactive tool, bridging the gap between theoretical frameworks and practical, real-world threat analysis. 

What’s new? 

Updated home screen of TI Lookup featuring MITRE ATT&CK matrix
  • Interactive MITRE ATT&CK matrix: All techniques and tactics are now neatly organized in a functional, actionable layout. 
Filtering options for MITRE ATT&CK techniques
  • Filtering options: Prioritize techniques by risk level—red for high risk, yellow for moderate, and blue for less urgent. 
Tactics, techniques and procedures of phishing (T1566)
  • Real-world sample connections: Click on any technique to see related malware samples and how they behave in real attacks. 

Best of all, this feature is completely free and available to everyone right now. Dive into the MITRE ATT&CK matrix on TI Lookup and start exploring it today! 

Black Friday 2024:
Double your search requests in TI Lookup for free 



See details


Threat Coverage Update 

Enhanced Network Threat Detection 

In November, we expanded our Suricata rule collection with an additional 7,206 rules, significantly enhancing network threat detection.  

The new rules were added using domains derived directly from Public submissions, supplemented by data from TI Lookup and advanced processing logic.  

Key highlights: 

  • Focus on threat group activity: We continue to monitor the operations of major threat groups and phishing kits, leveraging this information to enhance detection capabilities. 
  • Community engagement: Regular updates and insights into phishing threats are shared through our dedicated weekly post on X, helping you stay informed about the latest developments in the phishing and malware attacks. 

Recent Updates in Suricata Rules 

Our latest Suricata updates have focused on enhancing detection accuracy for phishing campaigns and domain-related threats. Here are some examples of the recent additions: 

MassBass phishing campaign detection– A massive phishing attack that we named MassBass, has been identified and tagged in our Suricata rules: 

TI Lookup: Search MassBass-related rules and insights here 

CrossDomain rules detection– These Suricata rules for domains were created using data from public submissions and include “CrossDomain” in their rule names. 

TI Lookup: You can explore CrossDomain-related activity and insights using our TI Lookup tool: 
Search CrossDomain 

New Signatures 

This month, we’ve added a total of 56 new signatures to enhance our detection capabilities, covering a wide range of malicious behaviors and threats. 

  • Office/archive exploit: Detection of deliberately damaged files exploiting the self-repair mechanism. 
  • Kms tool: Identification of unauthorized kms activation tools. 
  • Torvil mutex: Discovery of torvil-related mutex activity. 
  • Cve-2024-43451: a critical vulnerability (example session). 
  • Untrusted certificate execution: alerting on files executed with untrusted certificates. 
  • Silentkill: a sophisticated malware strain identified. 
  • Rhysida: a ransomware strain (example session). 
  • Secretsdump: detection of credential-stealing activity. 
  • Gumen: a unique malware variant (example session). 
  • Badrabbit: identification of the infamous ransomware. 
  • Ateraagent: detection of unauthorized agent installations (example session). 
  • Lunam and Luna: discovery of related malware strains (example session). 
  • Behavioral detection of attempts to establish rdp connections using configuration files extracted from outlook emails. 
  • Identification of conti-based ransomware, formbook, and xworm
  • Detection of expresszip malware (example session). 

Browser extension module

A new signature module for browser extensions was introduced, enabling in-depth content analysis of web pages. Besides, the following signatures were added: 

  • Obfuscated JavaScript. 
  • Fake Microsoft authentication pages. 
  • Email addresses embedded in URLs. 
  • Phishing kits such as Tycoon2fa and Mamba2fa

New YARA Rules  

This month, 9 new YARA rules were implemented, further enhancing our detection capabilities. Notable additions include: 

APT Detection Update 

This month, we’ve enhanced our detection capabilities against APT groups, specifically focusing on Lazarus and Rhysida. To address these threats, we’ve added 2 YARA rules and approximately 20 tailored signatures, ensuring more precise tracking and analysis of their activity. 

Get Your Black Friday Deals from ANY.RUN! 

Black Friday 2024 is here, and ANY.RUN has prepared exclusive time-limited offers to help you save big while enhancing your security workflow: 

  • Hunter Plan: Get two annual subscriptions for the price of one—perfect for individual researchers who want to collaborate. 
  • Enterprise Plan: Buy 5 licenses and get 2 free, or 10 licenses with 3 free plus a complimentary Threat Intelligence Lookup plan. Special renewal bonuses available! 
  • TI Lookup: Double your search requests with every subscription purchase. 

Offers will expire on December 8th, 11:59 PM PST. Don’t miss out: secure your deal today

About ANY.RUN  

ANY.RUN helps more than 500,000 cybersecurity professionals worldwide. Our interactive sandbox simplifies malware analysis of threats that target both Windows and Linux systems. Our threat intelligence products, TI Lookup, YARA Search and Feeds, help you find IOCs or files to learn more about the threats and respond to incidents faster.  

With ANY.RUN you can: 

  • Detect malware in seconds
  • Interact with samples in real time
  • Save time and money on sandbox setup and maintenance
  • Record and study all aspects of malware behavior
  • Collaborate with your team 
  • Scale as you need

Explore all Black Friday 2024 offers →

The post Release Notes: MITRE ATT&CK Matrix with Samples, Upgraded Automated Interactivity, Expanded Threat Coverage, and More appeared first on ANY.RUN’s Cybersecurity Blog.

ANY.RUN’s Cybersecurity Blog – ​Read More

Attackers target sellers on message boards | Kaspersky official blog

Large online marketplaces do what they can to combat fraud, but cybercriminals remain one step ahead when it comes to scamming both buyers and sellers. This year has seen the rise of an online video-call scam where fake buyers ask for a video-demo of a product, during which they swipe one-time codes. Here’s all about this scheme — in four acts.

Act one. Suspicion

A seller of a high-end product (say, a fancy TV) is approached by someone posing as a buyer who wants to pay and collect as quickly as possible. But there’s a catch: that someone requests a video-demo first. Most message boards don’t let you do this, and even if they do — the “buyer” will mysteriously have some issue at their end: “Strange, it’s not working, how about we use WhatsApp instead?” And so the conversation moves seamlessly to a messenger or other chat platform. The request to switch to WhatsApp, Telegram or whatever is a BIG red flag. On their own home turf, scammers have an easier job of luring you to a phishing site, because many message boards don’t allow sharing links in chats.

Act two. Certainty

The “buyer” asks the seller lots of questions about the product: where did they buy it, does it work ok, and, if so — why are they selling it? With each passing minute, this dialogue between strangers becomes all the more like a conversation between long-time buddies. The “buyer” seems keen and ready to fork out — the seller just needs to provide a card number for the transfer of funds and the deal is done: “What a pleasure doing business with this guy. He sure is trustworthy.” But here’s when the trap springs…

Act three. Discovery

Without even naming the screen-sharing feature, the “buyer” asks the seller to turn on screen-sharing in WhatsApp. If the seller complies, their banking app screen becomes visible to the scammers, who attempt to log in to the seller’s online bank account. At this point, the victim’s smartphone receives an unexpected text message with a one-time code. On most devices, the code is displayed in a pop-up message that the cybercriminals also get to see. And if the victim, still in screen-sharing mode, checks to see what message just arrived, the scammers don’t even need the pop-up — they get the code anyway!

Act four. Loss

Depending on what information the “buyer” had beforehand, and what access they gained to the victim’s bank account, they can either siphon off funds immediately, or, if the amount in the account is too large to transfer, switch to another scam involving a call from an “investigator” who promises to investigate the incident of fraudulent bank access and persuades the victim to transfer the money to “a safe account”. One way or another, the money disappears.

How to guard against message board scams

Bear in mind that message boards are often teeming with fake sellers and buyers. Sure, such accounts eventually get exposed and blocked after user complaints, but the perpetrators simply create or buy new ones. So we’ve made a list of tips to help you stay safe when buying or selling on any message board:

  • Chat with other buyers or sellers only within the platform. Never switch to a messenger app — even (or especially) if the other party really wants to. Outside the marketplace itself, scammers can slip you a phishing link to steal your account — or worse.
  • Use reliable protection on both your smartphone and computer, for example Kaspersky Premium.
  • Decline offers to use alternative delivery or money transfer services — opt for the platform’s native tools or accept payments in cash only.
  • Do not give anyone your phone number (and hide it in your marketplace profile) or card number.
  • Get yourself a virtual card with a limit on online payments.
  • Never give out one-time codes, because then even two-factor authentication won’t save your account.
  • Disable pop-up notifications and on-screen text messages.
  • Check the domain registration date before entering payment details on the site (see here for details of how to do this).

Kaspersky official blog – ​Read More

CISA Releases New List of Known Exploited Vulnerabilities, Urges Immediate Actions 

Vulnerabilities

Overview 

The Cybersecurity and Infrastructure Security Agency (CISA) has once again emphasized the critical importance of addressing IT vulnerabilities. This week, Cyble has reported multiple vulnerabilities across IT devices based on the findings published in the Known Exploited Vulnerabilities (KEVs) catalog.  

Among the most concerning vulnerabilities in the list are CVE-2024-11680, CVE-2024-23113, and CVE-2024-47575, as well as others like CVE-2024-10924, CVE-2023-50094, and CVE-2024-38077. The vulnerabilities included in this updated list, classified as Known Exploited Vulnerabilities (KEVs), pose online threats to both government and private sector organizations.  

These flaws are not just theoretical or potential risks; they have been actively exploited by threat actors, making it essential for organizations to take immediate action to patch or mitigate these weaknesses in their systems. The CISA’s KEV catalog highlights which vulnerabilities need to be addressed immediately to prevent cybercriminals from taking advantage of them. 

Major IT Vulnerabilities Listed in the Known Exploited Vulnerabilities Catalog 

Among the most urgent vulnerabilities is CVE-2024-11680, which affects the popular network management software used by many large organizations. This vulnerability, if left unaddressed, can allow attackers to remotely execute arbitrary code, enabling them to gain unauthorized access to sensitive data or disrupt business operations.  

  • CVE-2024-23113 is another severe IT vulnerability listed by CISA. This flaw is tied to a specific version of a widely deployed application, leaving it susceptible to exploitation through specially crafted requests that could allow an attacker to gain control over an affected system. The widespread use of this application in various industries—from finance to healthcare—means that the ramifications of an exploit could be catastrophic if left unpatched. 

  • CVE-2024-47575, a vulnerability in yet another popular software package, has been flagged as critical by both CISA and security experts. Attackers can exploit this flaw to escalate their privileges, potentially taking control of a system and bypassing normal security mechanisms. Such an escalation could result in the compromise of sensitive data or the deployment of ransomware, making this a particularly malicious vulnerability. 

Other Vulnerabilities on the Radar 

In addition to the three high-priority vulnerabilities, CISA’s latest KEV catalog also includes other notable IT vulnerabilities, such as CVE-2024-10924, CVE-2023-50094, and CVE-2024-38077. While these flaws may not be as widely exploited as the previous ones, they still pose serious risks and require immediate attention. 

  • CVE-2024-10924, for example, is a vulnerability in a widely used version of open-source software that could allow remote code execution. If exploited, attackers could bypass security controls and access systems that are critical to both business and governmental functions. 

  • CVE-2023-50094 is related to a flaw in a popular content management system, which could allow attackers to execute arbitrary code remotely. As businesses and organizations increasingly rely on digital platforms to manage content, vulnerabilities like this one could open the door to a range of cyberattacks, from data breaches to full system takeovers. 

  • CVE-2024-38077 impacts a specific configuration of a widely used database management system. Though not as severe as some of the other vulnerabilities, it can still lead to data corruption or unauthorized access if exploited. 

Mitigations and Recommendations 

Organizations can protect themselves from these vulnerabilities by implementing a range of security measures. Some of these measures include:  

  • Regularly update software and hardware with the latest patches from official vendors and apply critical patches immediately. 
  • Develop a patch management strategy, including inventory management, testing, deployment, and automation for efficiency. 
  • Segment the network to isolate critical assets, using firewalls, VLANs, and access controls to reduce exposure. 
  • Create and maintain an incident response plan, regularly testing and updating it to address current threats. 
  • Implement monitoring and logging systems, such as SIEM, for real-time threat detection and analysis. 
  • Subscribe to security alerts from official sources and conduct regular VAPT exercises to identify and fix vulnerabilities. 

Conclusion 

The publication of new Known Exploited Vulnerabilities (KEVs) by CISA serves as a vital resource in the fight against cybercrime. The vulnerabilities highlighted in the latest list, including CVE-2024-11680, CVE-2024-23113, and CVE-2024-47575, require immediate attention. The inclusion of these flaws highlights the importance of being proactive in identifying and addressing IT vulnerabilities before they can be exploited by attackers. 

The post CISA Releases New List of Known Exploited Vulnerabilities, Urges Immediate Actions  appeared first on Cyble.

Blog – Cyble – ​Read More

Malaysia’s Fight Against Cybercrime: Two New Bills Tabled in Parliament 

Vulnerabilities

Overview 

The Madani Government has taken a significant step toward ensuring online safety by tabling two crucial bills in the Dewan Rakyat on Monday. This development marks a pivotal moment in Malaysia’s efforts to combat cybercrime and modernize outdated cyber laws that were enacted nearly three decades ago. 

Communications Minister Fahmi Fadzil tabled the Communications and Multimedia (Amendment) Bill 2024 and the Malaysian Communications and Multimedia Commission (Amendment) Bill 2024 for their first reading in Parliament.  

These legislative changes highlight the government’s determination to strengthen Malaysia’s legal framework against cybercrime while promoting a safer digital environment for its citizens. 

Why these new Bills are necessary 

The internet has evolved dramatically over the past 26 years, bringing both incredible opportunities and risks. As cyber threats become more advanced, outdated laws struggle to provide adequate protection for users, businesses, and institutions.  

From online scams and fraudulent activities to harassment and the misuse of personal data, the need for strong cyber laws has never been more pressing. The tabling of these two bills comes in response to rising online threats and the necessity to adapt Malaysia’s legal framework to the realities of today’s digital age.  

Minister Fahmi emphasized that these amendments aim to close gaps in existing legislation, ensuring that Malaysia stays ahead in its fight against cybercrime. 

Key Provisions in the Communications and Multimedia (Amendment) Bill 2024 

The Communications and Multimedia (Amendment) Bill 2024 focuses on updating Act 588 to address new challenges in the digital realm. Below are the significant proposed changes: 

  1. Expanded Definition of Harassment and Fraud 

  • Subsection 233(1) will now include the phrase “harass or commit an offense involving fraud or dishonesty against any person”, broadening the scope of punishable offenses under the act. 
  • This change ensures that fraudulent online activities, in addition to harassment, are explicitly covered under the law. 

  1. Prohibition of Unsolicited Commercial Messages 

  • Clause 92 introduces a new Section 233a, which prohibits the sending of unsolicited commercial electronic messages. 
  • This measure aims to combat spam and phishing schemes, which often serve as gateways for more serious cybercrimes. 

  1. Disclosure of Communications Data 

  • Clause 112 introduces Section 252b, empowering police or authorized officers to compel the disclosure of communications data from individuals in control of a communications system. 
  • This change seeks to enhance law enforcement’s ability to investigate and respond to cybercrimes swiftly. 

Key Provisions in the Malaysian Communications and Multimedia Commission (Amendment) Bill 2024 

The Malaysian Communications and Multimedia Commission (MCMC) (Amendment) Bill 2024, meanwhile, focuses on strengthening the capabilities and functions of the MCMC under Act 589. Notable amendments include: 

  1. Expansion of MCMC’s Functions 

  • Clause 5 proposes an amendment to Section 16, enabling the MCMC to review and audit information provided by licensees. 
  • This includes auditing the activities of licensees or service providers as determined by the commission, ensuring better oversight and accountability. 

  1. New Definitions 

  • Clause 2 amends Section 3 to introduce new definitions for “chief executive officer” and “communications system” while also refining the definition of “chairman.” 
  • These updates provide clearer guidelines for roles and responsibilities within the MCMC. 

  1. Increased Contract Value Limit 

  • Clause 13 proposes an amendment to Section 45, raising the contract value limit the commission can enter without ministerial or financial concurrence from RM5 million to RM10 million. 
  • This change is expected to streamline administrative processes and enhance the MCMC’s operational efficiency. 

Implications of these Bills 

The amendments to these two critical acts represent a comprehensive approach to tackling cybercrime. Key implications include: 

  • Enhanced Legal Protections: The laws provide stronger safeguards for individuals and businesses by explicitly addressing harassment, fraud, and spam. 
  • Modernized Oversight: Changes to the MCMC’s functions and financial thresholds will enable the commission to better regulate and oversee the telecommunications and multimedia sectors. 

However, some of these changes, particularly the expanded search powers, may raise concerns about privacy and potential misuse of authority. Balancing security and personal freedoms will be crucial as the bills are debated. 

A Critical Moment for Cybersecurity in Malaysia 

Minister Fahmi Fadzil expressed optimism that these amendments will be passed during the current parliamentary session, which concludes on December 12.  

While the journey toward a safer online environment is far from over, these bills lay a strong foundation for future advancements in Malaysia’s cybersecurity landscape. As debates ensue in Parliament, the hope is that these laws will strike a balance between strong enforcement and the protection of individual rights, paving the way for a secure and prosperous digital future. 

Source:

https://mcmc.gov.my/skmmgovmy/media/General/pdf2/NEAP-Amendment-Notice-No-1-of-2024.pdf 
https://theedgemalaysia.com/node/736203
https://theedgemalaysia.com/node/736160

The post Malaysia’s Fight Against Cybercrime: Two New Bills Tabled in Parliament  appeared first on Cyble.

Blog – Cyble – ​Read More

New Report Highlights Critical Cybersecurity Challenges Facing the U.S.

U.S

The U.S. has never faced a more challenging time for cybersecurity, with critical infrastructure under siege, nation-state threat actors emboldened, and a new Presidential Administration that could usher in policy changes and a possible government restructuring.

A new Cyble report highlights the cyber threats and challenges facing the U.S., offering critical insights into the biggest threats that organizations must grapple with. The report examines the top threats, threat actors, and attack targets; hacktivism trends; more than 50 actively exploited IT and ICS vulnerabilities; Dark Web and cybercrime trends; and recommendations for security teams.

Major U.S. Cyber Challenges

The challenges that will help define the U.S. cybersecurity direction in the coming months include:

Disinformation: Efforts to influence the U.S. election escalated significantly in the final weeks of the campaign. The main foreign actors involved in influence campaigns—notably Russia, China, and Iran—will likely continue to try to influence U.S. policy and discourse.

The Future of CISA: The Republican “Project 2025” agenda includes proposals to reorganize the top U.S. cybersecurity agency and its responsibilities at a time when critical infrastructure is facing significant challenges.

Nation-State Threats: Concern about foreign adversaries escalated when China-linked threat actors successfully infiltrated U.S. telecom systems to access wiretap data and the phone data of top U.S. officials. As China is believed to have significantly infiltrated critical infrastructure in the U.S. and elsewhere, national cyber agencies must do more to detect and remove these threats.

AI in Social Engineering: The proliferation of AI technology is enhancing the effectiveness of social engineering attacks, enabling more personalized and convincing tactics that have scammed average citizens as well as multi-national corporations. To help combat this rising threat, Cyble has added AI deepfake detection and takedown services to its threat intelligence suite.

Dark Web and Cybercrime: Dark Web activity remains a major threat, as exploits are under discussion on cybercrime forums within hours after vulnerabilities are publicly revealed, and zero-day vulnerabilities can frequently be found for sale on these forums.

Healthcare and OT/ICS environments: Threat actors continue to heavily target healthcare and critical infrastructure, with Manufacturing, Energy, Oil and Gas, and Building Automation being the leading attack targets detected by Cyble.

Ransomware: The U.S. is by far the biggest ransomware target, and data exfiltration is increasingly a goal of ransomware groups.

Infostealers continue to grow in frequency and sophistication, threatening the accounts and credentials of both enterprises and consumers.

Most Active Threat Groups and Ransomware Targets

Cyble detected four of the most active threat groups in October: ransomware groups. RansomHub was the top threat actor, followed by DragonForce, Lockbit, and Storm-0501. An APT group, UNC5812, rounded out the top five.

According to Cyble data, the U.S. remains the biggest ransomware target, with October attack volumes 10 times higher than in any other country (chart below).

Healthcare is being increasingly targeted by ransomware groups, and the effects on patient care are predictably dire. Texas Tech Health Sciences Center, Aspen Healthcare Services, and Boston Children’s Health Physicians were among the bigger ransomware targets in October.

The full report examines more than 30 threat groups, more than 50 IT and ICS vulnerabilities, and 52 malware families. The top malware families observed by Cyble in October were:

  • Hydra
  • Lynx
  • Nitro
  • RansomHub
  • Rhysida
  • Hellcat Ransomware
  • Cactus
  • Everest
  • Medusa
  • Interlock

Hacktivism Trends

Hacktivism remained significantly active heading into the election, both in the U.S. and elsewhere. Israel and Palestinian concerns were by far the most dominant – and played a surprisingly pivotal role in the U.S. election in some states, most notably in Michigan and Wisconsin.

Some of the most active hacktivist groups in October included:

  • XYZ/Alpha Wolf
  • Key Group
  • NoName
  • Cyber Operation Alliance
  • Anon Black Flag

Dark Web and Cybercrime Activity

The dark web has become a democratizing force in cybercrime, giving less experienced threat actors and hacktivists access to more sophisticated exploits, leaked files, credentials, stolen credit cards, compromised endpoints, and more.

Cyble dark web researchers typically see ten or more vulnerability exploits discussed each week on cybercrime forums, many of which have available Proof of Concept (PoC) exploits that can be easily deployed.

Cyble’s AI-powered threat intelligence tool detected 1.5 million data exposures, 48,000 compromised endpoints, and 178,000 leaked credentials in October, all readily available for a price.

The report also looked at 34 IT and 20 ICS vulnerabilities targeted by attackers, many of which were discussed on dark web forums. Network devices are frequently a starting point for cyberattacks, but the list touches a wide range of systems that hackers use to move laterally, elevate privileges, and establish persistence.

Cyble Recommendations

The threat landscape may appear overwhelming at times, but good cybersecurity practices performed regularly can do much to reduce your attack surface. Patching, network segmentation, air-gapped backups, monitoring and logging, vulnerability assessments, and a strong incident response plan are all essential practices that take time but don’t necessarily carry a high price tag. Cyble can help with cost-effective vulnerability intelligence and scanning services targeted to individual environments.

The post New Report Highlights Critical Cybersecurity Challenges Facing the U.S. appeared first on Cyble.

Blog – Cyble – ​Read More

Combatting Counterfeit Goods in E-Commerce with Cyble Brand Protection Strategies

Counterfeit

Overview

The rapid growth of e-commerce has revolutionized the way consumers shop, with global e-commerce revenues expected to exceed $6 trillion in 2024. However, this surge in online transactions has also created fertile ground for counterfeit goods, with fraudulent sellers exploiting online platforms to deceive shoppers and tarnish brand reputations.

The problem intensifies during peak shopping periods like Black Friday and Cyber Monday, where high online traffic increases opportunities for counterfeiters to take advantage of consumer demand for discounted products. Cyble’s latest report examines the current state of counterfeit threats in e-commerce, the challenges brands face in detecting and responding to these threats, and the best practices companies can adopt to protect themselves.

Counterfeit goods pose a threat to both consumers and brands, causing financial and reputational damage. According to estimates, counterfeit goods accounted for $500 billion in global trade in 2023, equating to 3.3% of world trade. In addition to harming consumer trust, counterfeit goods cost companies an average of $3.8 billion annually. Small businesses, which often lack the resources to monitor and fight counterfeiting effectively, are especially vulnerable.

The generality of counterfeit goods has become a critical concern in the e-commerce industry. This issue has grown more complex with the rise of online marketplaces such as Amazon, eBay, and Alibaba, where sellers can set up accounts with minimal verification. During high-volume shopping events, counterfeiters intensify their activities, taking advantage of the surge in consumer interest and the pressure on platforms to process transactions quickly.

Key Drivers of the Counterfeit Goods Market

Several factors contribute to the rapid proliferation of counterfeit goods in the digital marketplace. One of the primary reasons is the ease of entry for sellers on e-commerce platforms. Many online marketplaces have minimal barriers to setting up seller accounts, which allows counterfeiters to quickly create profiles and list fake products.

These counterfeit listings can often go unnoticed for extended periods, giving fraudsters ample time to profit before their activities are discovered. The lack of stringent vetting and seller monitoring also allows counterfeiters to operate with relative impunity, further encouraging their presence in the marketplace.

Another key factor enabling the growth of counterfeit goods is anonymity. Counterfeiters often exploit weak identity verification processes and poorly regulated seller protocols on e-commerce platforms, making it difficult to trace their operations. These sellers can easily mask their identities and operate under false information, preventing authorities and brands from taking action.

The growing demand for branded goods, particularly during sales events like Black Friday, also fuels the counterfeit market. Consumers are increasingly drawn to deals on high-demand items, and the temptation of discounted prices can cloud judgment, making them more susceptible to purchasing counterfeit goods unknowingly. Counterfeiters capitalize on this demand by offering fake products that closely resemble legitimate branded items, often priced much lower than the original, which makes it difficult for buyers to spot the difference.

As counterfeit products become more sophisticated, distinguishing them from legitimate goods becomes even more difficult. Counterfeiters commonly use high-quality replicas, fraudulent packaging, and deceptive marketing tactics. These items often appear to be of the same quality as their authentic counterparts, making it even harder for consumers to recognize they’ve been deceived until it’s too late.

The combination of these factors—easy access, anonymity, heightened demand, and increasing product sophistication—creates a perfect storm that allows counterfeit goods to flourish, particularly during peak shopping periods like Black Friday when online traffic and consumer activity surge.

The Financial and Reputational Toll on Brands

Counterfeit goods have economic consequences. The OECD estimates that counterfeit imports into the UK were worth $8.95 billion in 2021. This leads to a direct revenue loss, as counterfeit goods account for 3% of total sales in some sectors, such as luxury goods and electronics. Small businesses, in particular, face the brunt of these losses, as they lack the resources to monitor and combat counterfeiting effectively.

In addition to the financial toll, counterfeit products severely damage brand reputation. Consumers who unknowingly purchase fake goods may associate the substandard experience with the original brand, undermining trust. Furthermore, counterfeit goods can lead to consumer health risks, especially in sectors like pharmaceuticals and health products. The presence of counterfeit goods in fast-moving consumer goods (FMCG), including food and cosmetics, further exacerbates the problem, raising concerns about safety.

E-Commerce Platforms: Key Players in the Fight Against Counterfeiting

Major online marketplaces have recognized the growing threat of counterfeit goods and are increasingly investing in advanced technologies to prevent their proliferation. For example, Amazon has reported blocking over 8 million suspected counterfeit listings in 2024 alone. Cyble’s artificial intelligence-based solutions are invaluable in assisting e-commerce platforms to detect and prevent counterfeit activity during peak shopping events like Black Friday, where fraudulent listings are more likely to surface.

Additionally, platforms like Amazon and eBay have launched brand protection programs such as Amazon’s “Brand Registry” and eBay’s “Verified Rights Owner (VeRO) Program.” These tools allow brands to report and remove counterfeit listings more efficiently. However, detection alone is not enough. Brands must take proactive steps to protect their intellectual property and protect their consumers.

The Role of Technology in Counterfeit Detection and Prevention

Cutting-edge technologies enabling brands to track, authenticate, and remove fake products from online marketplaces are strengthening the fight against counterfeit goods in e-commerce.

  1. Digital Watermarking and Serialization: Brands use unique codes or invisible markers embedded in product packaging to allow consumers and platforms to verify the authenticity of the products. Even if counterfeiters replicate the packaging, these markers can help detect fake goods.
  2. Artificial Intelligence (AI) and Machine Learning: AI algorithms can analyze seller profiles, product descriptions, and reviews to identify suspicious activity. Cyble leverages AI-based solutions to track and authenticate items in real-time, making it easier for brands to monitor listings during busy shopping periods like Black Friday.
  3. Blockchain: This technology offers a tamper-proof system to track product authenticity across the supply chain. By recording every transaction, blockchain creates an immutable trail that verifies the product’s origin, providing greater transparency for brands and consumers.
  4. Image Recognition Tools: These tools scan e-commerce platforms for duplicate images or unauthorized use of brand logos. During peak sales events like Black Friday, counterfeiters often reuse product images to mislead buyers, making image recognition a critical tool for detecting fake listings.
  5. Consumer Empowerment Apps: Brands can deploy apps that allow consumers to verify product authenticity using QR codes or barcodes. Empowering shoppers with tools to check for counterfeit products is an effective way to combat the issue during high-traffic shopping events.

Legal and Policy Measures to Combat Counterfeiting

Alongside technological advancements, legal frameworks are evolving to address the counterfeit threat. For example, the SHOP SAFE Act, reintroduced to Congress in September 2023, aims to hold e-commerce platforms accountable for the sale of counterfeit goods.

The act incentivizes platforms to vet sellers more thoroughly and implement stricter measures to prevent counterfeit products from reaching consumers. In addition, the INFORM Consumers Act passed in June 2023, increases transparency for third-party sellers on e-commerce platforms.

This legislation aims to reduce the prevalence of counterfeit goods and stolen products by enforcing stricter seller identification processes.

Cyble’s Role in Brand Protection

To tackle the growing problem of counterfeit goods, Cyble’s Brand Intelligence services offer a comprehensive suite of tools designed to help businesses monitor and protect their brands from online threats. Cybersecurity solutions like Cyble Vision and Cyble Hawk are particularly effective in identifying and mitigating counterfeit activity during high-risk periods.

Cyble’s Brand Intelligence services include:

  • Social Media Monitoring: Detect unauthorized use of your brand and counterfeit product listings on platforms like Facebook, Instagram, and Twitter, with real-time alerts to help brands respond quickly.
  • Mobile Application Monitoring: Identify counterfeit or malicious apps impersonating your brand on major app stores, protecting your reputation and maintaining customer trust.
  • Phishing Domains: Protect your customers and brand identity by detecting and mitigating phishing domains that mimic your official website.
  • Watchlisted and Suspicious Domains: Continuously track domains linked to counterfeit activities, ensuring constant monitoring of potential threats to your brand.
  • Website Monitoring: Monitor your official website to prevent unauthorized changes, malicious activities, or cloning attempts that could damage your brand’s credibility.
  • Website Watermarking: Enhance security by adding unique watermarks to your website content, preventing unauthorized copying or cloning.
  • Takedown Tracker: This tool simplifies the process of reporting and removing counterfeit listings or domains. It provides real-time updates on takedown request statuses for greater transparency and efficiency.

Cyble’s brand monitoring capabilities provide real-time alerts and data-driven insights that help brands respond effectively to counterfeit threats. By leveraging Cyble’s comprehensive monitoring services, brands can protect their reputation, prevent revenue loss, and ensure that consumers are not deceived by counterfeit products.

The post Combatting Counterfeit Goods in E-Commerce with Cyble Brand Protection Strategies appeared first on Cyble.

Blog – Cyble – ​Read More

German CERT Warns Zyxel Firewalls Exploited for Helldown Ransomware Deployment

CERT

Overview

Zyxel firewalls have come under scrutiny following a wave of attacks leveraging vulnerabilities to deploy Helldown ransomware. A critical directory traversal vulnerability, tracked as CVE-2024-11667, in the Zyxel ZLD firmware (versions 5.00–5.38) has been linked to these breaches.

Attackers exploit this flaw to steal credentials and execute malicious activities, including creating unauthorized VPN connections and modifying security policies.

CERT Germany (CERT-Bund) and Zyxel have issued urgent advisories detailing these threats and recommending immediate action to mitigate risks.

Understanding the Vulnerability: CVE-2024-11667

CVE-2024-11667 is a directory traversal vulnerability in Zyxel’s firewall firmware. It allows attackers to upload or download files via specially crafted URLs, potentially leading to credential theft and unauthorized access.

This vulnerability impacts:

  • ATP and USG FLEX series firewalls in on-premise mode.
  • Devices running ZLD firmware versions from 4.32 to 5.38 with remote management or SSL VPN enabled.

Devices using Nebula cloud management mode are not affected.

Helldown Ransomware Evolution
Initially observed in August 2024, Helldown has escalated in sophistication, leveraging the CVE-2024-11667 vulnerability in Zyxel USG Flex and ATP firewall series. The vulnerability, though unidentified, appears to allow unauthorized access even on patched systems if account credentials remain unchanged.

Helldown, derived from the infamous LockBit ransomware builder, targets organizations with advanced tactics, including lateral movement within networks. Its leak site has named 32 victims globally, with five German entities suspected as targets, CERT-Bund (BSI) said.

Key Attack Observations

  • Attack Vectors: Exploitation of firewall vulnerabilities for initial access.
  • Post-Exploitation Tactics: Creation of unauthorized accounts (e.g., “SUPPORT87”), lateral movement, and persistent backdoors.
  • Impact: Data exfiltration, encryption of critical assets, and operational disruptions.

Identifying Signs of Compromise

Indicators of a compromised Zyxel firewall include:

  1. Unauthorized SSL VPN Connections:
    • VPN accounts such as “SUPPORT87,” “SUPPOR817,” or “VPN” appear in connection logs.
    • Login attempts from non-recognized IP addresses, often routed through VPN services.

  2. Modified Security Policies:
    • Policies granting unrestricted access (e.g., “ANY to ANY”) between WAN, LAN, and SSL VPN zones.
    • Changes to NAT rules allowing WAN-to-LAN access.

  3. Suspicious Admin Activity:
    • Creation of unauthorized admin accounts.
    • Login attempts from unrecognized IPs.
    • Activity logs in SecuReporter showing unusual administrative actions.

  4. AD Server Targeting:
    • Attackers use stolen administrator credentials to access Active Directory (AD) servers via SSL VPN connections, potentially encrypting files.

Steps to Detect and Remediate a Compromised Firewall

Detection

  • Check for unknown VPN connections or user accounts in logs.
  • Review SecuReporter activity logs for unauthorized admin actions.
  • Inspect firewall rules for unusual access permissions.

Remediation

Upgrade Firmware:
Update to ZLD 5.39 or later to patch CVE-2024-11667 and implement security enhancements.

Change Credentials:

  • Update passwords for all admin and user accounts (local and Active Directory).
  • Change VPN pre-shared keys and external authentication server credentials.

Remove Unauthorized Accounts:

  • Delete unrecognized admin and user accounts.
  • Force logout for all untrusted sessions.

Review Security Policies:

  • Remove rules that allow unrestricted access.
  • Ensure policies restrict WAN, LAN, and SSL VPN traffic as needed.

Monitor Logs:
Continuously analyze logs for suspicious activity and unauthorized access attempts.

Best Practices for Securing Zyxel Firewalls

To prevent future compromises, Zyxel recommends the following measures:

Restrict Access:

  • Disable remote management if not required.
  • Implement IP restrictions for accessing the management interface.

Change Default Ports:

  • Modify default HTTPS and SSL VPN ports to reduce exposure.

Enable Two-Factor Authentication (2FA):

  • Require 2FA for admin and user logins to strengthen access control.

Geo-Restriction Rules:

  • Use Geo-IP filtering to block traffic from untrusted regions.

Encrypt Configuration Files:

  • Add private encryption keys to secure configuration files.

Regular Backups and Monitoring:

  • Maintain updated backups of firewall configurations.
  • Continuously monitor for vulnerabilities using threat intelligence feeds.

Conclusion

The exploitation of Zyxel firewall vulnerabilities underscores the importance of proactive cybersecurity measures. Organizations using affected devices must prioritize firmware updates, strengthen access controls, and actively monitor for suspicious activity.

The Helldown ransomware campaign highlights the dangers of leaving systems exposed to known vulnerabilities. By adopting a layered security approach, including 2FA, IP filtering, and robust monitoring, organizations can effectively safeguard their networks against similar threats.

References:

https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-290907-1032.pdf?__blob=publicationFile&v=3

https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-protecting-against-recent-firewall-threats-11-27-2024

https://support.zyxel.eu/hc/en-us/articles/21878875707410-Zyxel-USG-FLEX-and-ATP-series-Upgrading-your-device-and-ALL-credentials-to-avoid-hackers-attacks#h_01J9RQPFVV0YYZY0CG3PJT7MAD

https://community.zyxel.com/en/discussion/26764/ransomware-helldown

The post German CERT Warns Zyxel Firewalls Exploited for Helldown Ransomware Deployment appeared first on Cyble.

Blog – Cyble – ​Read More

Top ICS Vulnerabilities This Week: Schneider Electric, mySCADA, and Automated Logic

ICS

This week’s Cyble ICS vulnerability report includes critical vulnerabilities like CVE-2024-10575 in Schneider Electric’s EcoStruxure IT Gateway, CVE-2024-47407 in mySCADA myPRO Manager/Runtime, and CVE-2024-8525 in Automated Logic that need urgent patching.

Overview

Cyble Research and Intelligence Labs (CRIL) analyzed the latest ICS vulnerabilities disclosed by the Cybersecurity and Infrastructure Security Agency (CISA) between November 19–25, 2024. These vulnerabilities highlight pressing security concerns across critical sectors, including manufacturing, energy, and communications.

Key insights include:

  1. CISA issued seven security advisories addressing 15 vulnerabilities in ICS products from Schneider Electric, Automated Logic, CODESYS GmbH, and mySCADA.
  2. A critical “Missing Authorization” flaw (CVE-2024-10575) affecting Schneider Electric’s EcoStruxure IT Gateway could allow attackers unauthorized access to critical systems.
  3. mySCADA and Automated Logic WebCTRL exposures show the growing attack surface, stressing the importance of proactive security measures.

Below, we delve into the most significant vulnerabilities and their implications for security teams.

The Week’s Top ICS Vulnerabilities

Key vulnerabilities identified in this report include:

CVE-2024-10575 (Schneider Electric):

  • Product: EcoStruxure IT Gateway
  • Severity: Critical
  • Issue: Missing Authorization
  • Impact: Unauthorized access to critical systems, risking data breaches and operational disruptions.
  • Patch Link

CVE-2024-47407 (mySCADA):

  • Product: myPRO Manager/Runtime
  • Severity: Critical
  • Issue: OS Command Injection
  • Impact: Remote execution of arbitrary commands compromising SCADA and HMI systems.
  • Patch Link

CVE-2024-8525 (Automated Logic):

  • Product: WebCTRL Server (v7.0)
  • Severity: Critical
  • Issue: Unrestricted File Upload
  • Impact: Uploading malicious files to building automation systems.
  • Patch Link

CVE-2024-8933 (Schneider Electric):

  • Product: Modicon M340, MC80, Momentum
  • Severity: High
  • Issue: Message Integrity Bypass
  • Impact: Potential manipulation of system communications.
  • Patch Link

CVE-2024-50054 (mySCADA):

  • Product: myPRO Manager/Runtime
  • Severity: High
  • Issue: Path Traversal
  • Impact: Unauthorized file access and data compromise.
  • Patch Link

For the complete list of vulnerabilities and their respective mitigations subscribe to Cyble’s AI-powered threat intelligence product suite!

Vendor Spotlight

Schneider Electric reported 50% of vulnerabilities, spanning industrial automation and energy management systems.

mySCADA followed with 33%, reflecting issues in SCADA and HMI platforms.

Automated Logic and CODESYS GmbH accounted for 17%, impacting building automation and PLC software.

Figure 1. Vendors who reported and released patches for ICS vulnerabilities, this week. (Source: Cyble)

Impacted Critical Infrastructure Sectors

Critical Manufacturing dominated the impacted sectors with seven vulnerabilities (50%).

The interconnected sectors of manufacturing, energy, and communications accounted for six vulnerabilities (43%), showcasing the criticality of cross-sector dependencies.

Impacted critical Infrastructure Sectors

Figure 2. Impacted critical infrastructure sectors. (Source: Cyble)

Recommendations

To address these vulnerabilities and reduce exploitation risks, CRIL recommends:

  • Monitor Alerts: Regularly review security advisories from vendors and government agencies like CISA.
  • Implement Zero-Trust: Restrict access to critical systems using risk-based management approaches.
  • Network Segmentation: Isolate sensitive ICS components to prevent lateral movement during attacks.
  • Patch Management: Develop a strategy for inventory, assessment, testing, and deployment of patches.
  • Regular Assessments: Conduct vulnerability assessments, penetration tests, and audits to identify weaknesses.
  • Secure Access: Restrict access to ICS devices, ensuring strong authentication measures are in place.
  • Incident Response Plans: Establish and test procedures for detecting and responding to cyber incidents.
  • Employee Training: Train employees to recognize phishing attempts and adhere to security protocols.

Conclusion

This week’s ICS vulnerability report shows the persistent threats to critical infrastructure. The vulnerabilities in Schneider Electric, mySCADA, and Automated Logic products demonstrate the importance of prioritizing cybersecurity measures to safeguard essential systems.

Organizations must act swiftly to patch critical flaws, enhance monitoring, and strengthen overall cybersecurity posture. Proactive measures are crucial in mitigating risks and maintaining the integrity of critical operations.

The post Top ICS Vulnerabilities This Week: Schneider Electric, mySCADA, and Automated Logic appeared first on Cyble.

Blog – Cyble – ​Read More

Telegram Premium gift subscription scam | Kaspersky official blog

We at Kaspersky recently conducted a study and found that the average person spends $938 a year on 12 subscriptions. This just confirms that in today’s world, being subscribed to numerous services is just as much a part of everyday life as having your smartphone with you at all times.

There are subscriptions for everything: music, movies, fitness, security solutions, and even messaging apps. In this article, we’ll focus on one of the latter — Telegram Premium, a subscription that doubles almost all the messenger’s free-version’s limits. And the coolest thing about it is that you can give it to your friends as a present. If you have a large contact list, Telegram frequently reminds you of this possibility. Of course, scammers are exploiting this feature, sending out fake Telegram Premium gift subscriptions left and right.

So what’s behind these gift subscriptions from cybercriminals — and how can you protect your Telegram account?

How the Telegram gift-subscription scam works

It all starts with an innocent-looking Telegram message from someone in your contact list (actually — an impostor): “You’ve been sent a gift — a Telegram Premium subscription”. Beneath it is a link that, at first glance, seems legitimate. And indeed, it leads to an official-looking Telegram Premium channel. But there’s a catch…

Admit it, receiving a message like this feels great, and in a moment of excitement, it's easy not to cotton on to the trap

Admit it, receiving a message like this feels great, and in a moment of excitement, it’s easy not to cotton on to the trap

The text you see — https://t.me/premium — actually hides a link to a completely different phishing page. It’s a simple trick. Consider this example: here’s a link to the Kaspersky Daily blog homepage — https://kaspersky.com/blog, but it actually redirects to the homepage of our other blog, Securelist. Scammers use the same principle: they mask their phishing links with seemingly legitimate addresses.

Let’s return to the Telegram gift-subscriptions scam. The phishing page looks like a regular Telegram login page in a browser. However, the scam is betrayed by the dodgy URL: the address starts with the familiar https://t.me, but then has something extra, which wouldn’t be there if were a legitimate page:

Nice try, scammers — it looks almost identical to the real site

Nice try, scammers — it looks almost identical to the real site

If you enter your account details here, consider them stolen. Your user name, password, and possibly your two-factor authentication code will end up in bad guys’ hands. Once you’ve handed over your credentials, the scammers display a congratulatory message and start a 24-hour timer, claiming it’s the activation period for Telegram Premium. This delay is a classic cybercriminal tactic. They’re counting on the user either forgetting about the subscription or believing it’s genuinely on its way. Most likely, the only thing that will happen during these 24 hours is that you’ll permanently lose access to your account.

After 24 hours, the timer ends, but the subscription never materializes

After 24 hours, the timer ends, but the subscription never materializes

How else do scammers exploit gift Telegram subscriptions?

Since Telegram Premium launched several years ago, various scam scenarios have emerged. Unsurprisingly, these scams bear similarities to other primitive forms of fraud we frequently discuss on the Kaspersky Daily blog.

For example, cybercriminals might claim to host a free raffle for a three-month Telegram Premium subscription. However, there’s no real drawing of the winning “tickets” — everyone’s a winner; however, the prize isn’t a genuine gift subscription. Victims are directed to click a link and log in to Telegram on a phishing site. And that’s where their accounts get compromised.

Cybercriminals play to your ego with false claims like: "You've been selected as one of seven participants in our exclusive prize draw!"

Cybercriminals play to your ego with false claims like: “You’ve been selected as one of seven participants in our exclusive prize draw!”

Another common tactic involves distributing APK files for supposedly “hacked” Telegram apps bundled with Premium subscriptions. Needless to say, such modified apps are often nothing more than malware in disguise.

Always be skeptical of allegedly hacked or alternative versions of popular apps

Always be skeptical of allegedly hacked or alternative versions of popular apps

Now, you’ll have noticed that the screenshots above are in various languages. The fact is that these scammers operate all over the world, and if this scheme hasn’t reached your region yet, rest assured it surely soon will. Therefore, you should ensure the security of your devices and accounts with reliable protection.

How to protect your Telegram account

To start, we recommend setting up your Telegram security and privacy using our guide. If you’ve already done this, here are some additional tips to help you avoid becoming a victim of these and other scams:

  • Remember that there’s no such thing as a free lunch. Before celebrating a sudden gift, double-check if the sender really has good intentions. At the very least, contact them via a different communication channel — call them, use another messenger, or verify in person. As your personal account is at stake, you’d better err on the side of excessive caution.
  • Purchase subscriptions only through official channels. Telegram, for example, has a designated bot for buying subscriptions.
  • Enable two-factor authentication. This could be your last line of defense in case you fall for a scam. One way to store your 2FA tokens conveniently and securely is in Kaspersky Password Manager.
  • Learn more about other ways scammers can steal your Telegram account. There are countless fraudulent schemes — many of which are more sophisticated than they appear.
  • Slow down, even if you’re being rushed. Scammers love pressuring victims with timers. When it comes to your digital safety, ignore countdowns and take your time.
  • Be cautious about alternative versions of apps. We recommend only using official apps, because unofficial versions are almost always loaded with Trojans.

Kaspersky official blog – ​Read More

CISA Enhances Secure by Design Strategy with AI Red Teaming for Critical Infrastructure Protection

CISA

Overview

CISA has announced new additions to its Secure by Design initiative with the introduction of advanced fields in artificial intelligence (AI). This plan ensures the safety, security, and reliability of AI systems, especially as they are increasingly integrated into critical infrastructure and public safety applications. One of the most effective ways to evaluate and improve the resilience of AI systems is through the process of AI red teaming, which is an integral part of a broader strategy known as Testing, Evaluation, Validation, and Verification (TEVV).

This approach, backed by decades of experience in software security testing, emphasizes the importance of a Secure by Design methodology and aims to protect against both technical and ethical risks associated with AI deployment. The Cybersecurity and Infrastructure Security Agency (CISA), as the national coordinator for critical infrastructure security, has been at the forefront of promoting the Secure by Design approach in the development and testing of AI systems.

This initiative is designed to ensure that AI technologies are not only functional but also resistant to exploitation and capable of operating safely within complex environments. In a recent blog post by Jonathan Spring, Deputy Chief AI Officer, and Divjot Singh Bawa, Strategic Advisor, CISA emphasizes the importance of integrating AI red teaming into the established framework of software TEVV.

Red teaming, in the context of AI, refers to third-party safety and security evaluations of AI systems. It is part of a broader risk-based approach that includes thorough testing to uncover vulnerabilities and potential points of failure. According to the CISA blog, AI red teaming is essential for identifying weaknesses that could lead to critical failures, whether through physical attacks, cyberattacks, or unforeseen system malfunctions. The goal of AI testing is to predict how an AI system may fail and develop strategies to mitigate such risks.

AI Testing, Evaluation, Validation, and Verification (TEVV)

TEVV, a well-established methodology used for testing software systems, is not just relevant but essential for evaluating AI systems. Despite some misconceptions, AI TEVV should not be seen as entirely distinct from software TEVV. In fact, AI systems are fundamentally software systems, and the principles of TEVV are directly applicable to AI evaluations. This approach is particularly important as AI becomes increasingly integrated into safety-critical sectors like healthcare, transportation, and aerospace.

The TEVV framework is built upon three core components: system test and evaluation, software verification, and software validation. These processes ensure that software, including AI systems, functions as intended, meets safety standards, and performs reliably in diverse conditions. AI systems, like traditional software, must be rigorously tested for both validity (whether the system performs as expected) and reliability (how well the system performs under varying conditions).

One of the common misconceptions about AI systems is that their probabilistic nature — which allows them to adapt to changing inputs and conditions — makes them fundamentally different from traditional software. However, both AI and traditional software systems are inherently probabilistic, as demonstrated by issues like race conditions in software, where seemingly minor changes can lead to critical errors.

The Intersection of Software and AI TEVV

The notion that AI systems require entirely new testing frameworks separate from software TEVV is flawed. While AI systems may introduce new challenges, particularly around their decision-making processes and data-driven behaviors, many of the testing methodologies used in traditional software security remain relevant.

For instance, AI systems must undergo similar testing to ensure they are robust against unexpected inputs, exhibit reliability over time, and operate within secure boundaries. These concepts are not new but have been applied to traditional software for decades, particularly in industries where safety is paramount.

Take, for example, automated braking systems in modern vehicles. These systems rely on AI to interpret sensor data and make split-second decisions in critical situations, such as detecting pedestrians or obstacles. To ensure these systems are safe, engineers must test their robustness under a variety of scenarios, from unexpected road conditions to sensor malfunctions. Similarly, AI systems, regardless of their complexity, must undergo similar evaluations to guarantee their safety and reliability in real-world conditions.

CISA’s Role in Advancing AI Red Teaming and Security

CISA’s leadership in AI red teaming and security testing is crucial as AI becomes more prevalent in critical infrastructure. The agency is a founding member of the newly formed Testing Risks of AI for National Security (TRAINS) Taskforce, which aims to test advanced AI models used in national security and public safety contexts. The taskforce will focus on creating new AI evaluation methods and benchmarks to ensure that AI systems meet national security standards and can be securely deployed.

Moreover, CISA is actively involved in post-deployment AI security testing. This includes penetration testing, vulnerability scanning, and configuration testing for AI systems deployed across both federal and non-federal entities. As AI technologies, especially Large Language Models (LLMs), become more integrated into various sectors, CISA expects an increase in demand for these security testing services.

In addition to its technical efforts, CISA works closely with the National Institute of Standards and Technology (NIST) to develop and refine standards for AI security testing, providing expertise on how to make these standards actionable and effective.

Conclusion

As the field of AI testing continues to evolve, integrating AI red teaming into the existing software TEVV framework offers significant benefits. By adapting traditional software security testing methods to address the unique challenges posed by AI, the testing community can build upon proven strategies while incorporating new tools and methodologies specific to AI evaluation. This streamlined approach helps save time, resources, and effort by avoiding the creation of parallel testing processes that may ultimately yield similar results.

References

The post CISA Enhances Secure by Design Strategy with AI Red Teaming for Critical Infrastructure Protection appeared first on Cyble.

Blog – Cyble – ​Read More