Okta Executive Director of Cybersecurity Marc Rogers, like many of us, has lost all concept of time during the COVID-19 pandemic. There’s pre-COVID life and work, and then there’s the Groundhog’s Day existence that has become our collective reality. “I measure things in 2020 units now,” he said, during a virtual interview at Black Hat. “Some of it’s turned into a daily grind.”
But for Rogers, a founding member of the CTI League, the daily grind means preventing cyberattacks on hospitals and checking cyberthreat feeds for potential public health and safety dangers.
Rogers, along with cyberthreat intelligence (CTI) researchers and security incident responders at Microsoft, ClearSky Cyber Security, and other companies formed the league in March in response to COVID-19. The all-volunteer group works to protect medical organizations, public health care facilities, and emergency organizations from cyberthreats. As such, they cooperate closely with law enforcement agencies that are also hunting criminals who are trying to take down life-saving medical systems and spread pandemic-related scams.
Rogers can’t talk about the attacks that the CTI League prevented because they remain active criminal investigations. “It’s a little bit frustrating sometimes, because we’ve stopped some pretty big attacks,” he admitted. “And yet, we can’t shout about it from the rooftops. But it’s worth it in the long run. Knowing that we’ve been able to help some of these big institutions is one of the most optimistic points of this sort of bleak year. While there have been some major compromises of medical institutions, they are not falling to the extent that some other parts of industry are. And I’d like to think that’s because this group, plus other related groups, are all working to combat some of this stuff.”
‘The Vuln Storm’A massive number of serious infrastructure vulnerabilities dropped around the middle of July. Rogers puts the number at around 1,000. “To put context on it, that’s 10 times what I would expect to see around this time of the year,” he said, adding that the CTI League calls this “the vuln storm.”
And these weren’t minor security flaws. One, a major Microsoft Windows DNS server vulnerability that Microsoft patched, is a 17-year-old bug, dubbed SIGred and tracked as CVE-2020-1350. It received a CVSS severity score of 10 out of 10. Microsoft called it “wormable,” meaning that it can spread via malware between vulnerable computers without user interaction.
Another critical vulnerability, this one in F5’s Big-IP advanced delivery controller, allowed unauthenticated attackers to remotely run commands or code. Hackers continued to actively exploit this bug weeks after F5 patched it.
“And then there have been other issues with vendors pretty much across the board,” Rogers said. “So we’ve spent a lot of time triaging these things, and one of the things that we’ve been focused on is producing tools and detection code that people can use to determine just how many exposures to the service structure are vulnerable to these things.”
This likely prevented attacks against hospitals and health organizations, and “is a testament to the fact that the league is maturing and becoming pretty solid,” Rogers said. The group has about 1,600 members right now after peaking at just over 2,000 earlier in the summer. In July it hosted a hackathon to drum up additional interest and further engage with the cyberthreat investigator community.
COVID-19 Campaigns: From Malware to Disinformation“We started selecting a little bit more, focusing on folks who were able to contribute to the platform, and also to sort of weed out folks who weren’t necessarily the right fit for what we were doing,” Roger said. “I think it’s worked well because we’ve got this solid engagement from people with so many channels now on the platform.”
These channels tackle various threats, and they move at different speeds. “Some of them are running at 100 miles an hour, and some of them are at walking speed,” Rogers said. “For example, some of the work we’ve been doing with malware is moving at walking speed because there’s not a lot of new stuff coming out of that space. But, on the other hand, disinformation has exploded. We have six or seven different work streams dedicated to different aspects of disinformation.”
While most of these are COVID-19 related, hackers are casting wider disinformation nets and focusing on other events like Black Lives Matter protests and riots, he added. “And we’re even starting to see some that are focusing on the November election.”
And this illustrates the one given during this time of uncertainty. Cyberthreats, like COVID-19 itself, will continue to mutate and find a way to attack weaknesses. Meanwhile, first responders of all stripes continue fighting back.
Comments