Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

8/8/2011
01:19 PM
Rob Enderle
Rob Enderle
Commentary
50%
50%

McAfee Finds A Shady RAT -- But I Smell Something Worse

A serious problem in adequate disclosure could represent a bigger exposure than the massive ongoing attacks in the report

McAfee released a report last week detailing its penetration of a remote-access tool, and its analysis revealed two types of public and private organizations: those that knew they were penetrated and those that hadn’t figured it out.

But there are some pretty strict disclosure rules regarding compromised political and financial data, and this report would indicate that disclosures that should have been made were likely avoided. This might make the real dirty rat in this story the public and private organizations that aren’t in compliance with disclosure rules.

The big problem with disclosure is that it is both embarrassing and could actually result in the very problems that disclosure is supposed to avoid -- problems like getting fired, being fined, having to pay penalties, and facing ongoing invasive scrutiny. In other words, while concealing a problem is risky, and certainly if that concealment is discovered, likely career-ending, but the career-ending part might happen even if the disclosure is done properly as the company looks for someone below the CEO to scapegoat. The discovery of breaches tends to happen down in the bowels of a company, not at the executive level, placing decision-making power with folks who don’t have the full perspective of what can happen to the company if a cover-up is disclosed. This tends to put the people who are mostly likely to be penalized (CEO, CFO, CIO) outside of the decision loop, and given they are the ones often taking the primary risk even if they aren’t aware of it, this decoupling of risk and decision contributes strongly to this problem. This suggests more effort than is generally being taken needs to go into mitigating the risk, starting with a reminder that executive management must be in the loop for any decision surrounding a penetration because criminal charges could result. And training for employees to better identify the kind of attack, spearfishing, that apparently is in most common use is also crucial.

McAfee recommended additional security processes, from email scans to detect spearfishing messages, to networking scans to detect unpatched hardware or unusual traffic patterns. But the message is clear: This is not an exposure you can ignore.

The report implies that many companies are covering up breaches. That is a serious problem because the world economy is at a breaking point, and a major disclosure of a covered-up national or international breach could be the spark that ignites a collapse.

As people looked for scapegoats, those who cover up an attack will be the low-hanging fruit; this suggests the financial and personal risks of the alleged problem could outweigh significantly the problem itself.

The recommendation is to quickly determine which kind of company you are, mitigate the attack, and disclose before the lack of disclosure is discovered and you are implicated by it. This is War Room-level stuff, however, and if the penetrations are as deep as McAfee alleges, even your board should likely be involved.

The worst rat I smell is the decision to cover up problems like this, and the real risk that this tendency could cause another economic collapse or worsen the one we are now in.

Rob Enderle is president and founder of The Enderle Group. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
I 'Hacked' My Accounts Using My Mobile Number: Here's What I Learned
Nicole Sette, Director in the Cyber Risk practice of Kroll, a division of Duff & Phelps,  11/19/2019
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5087
PUBLISHED: 2019-11-21
An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An integer overflow can occur while calculating the row's allocation size, that could be exploited to corrupt memory and eventually execute arbitrary code....
CVE-2019-5509
PUBLISHED: 2019-11-21
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.
CVE-2019-6693
PUBLISHED: 2019-11-21
Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the admini...
CVE-2019-17272
PUBLISHED: 2019-11-21
All versions of ONTAP Select Deploy administration utility are susceptible to a vulnerability which when successfully exploited could allow an administrative user to escalate their privileges.
CVE-2019-17650
PUBLISHED: 2019-11-21
An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security check.