Showing posts with label intelligence. Show all posts
Showing posts with label intelligence. Show all posts

Monday, June 19, 2017

U.S. Corporate Concerns with China’s New Cybersecurity Law

On 1 June 2017, the Chinese government put an extensive new Cybersecurity law into effect. This law applies to all network operations in China, by Chinese citizens and foreign business operations alike. Many U.S. corporations operating in China have expressed concerns about how this law will impact their ability to operate under the more intrusive Chinese government control. The provisions with the potential for the greatest negative impact on foreign firms include:
  • Definition of network operators. The scope of the Cybersecurity Law provides control over not just telecom operators and internet firms but also banking institutions, insurance companies, securities companies, providers of cybersecurity products and services, and essentially any enterprise with a website in China or that provides network services. The American Chamber of Commerce in China has said the Law “will impact almost every company that operates in China.”
  • Requirements for “critical information infrastructure” operators. The Law defines these to include “public communications and information services, energy, finance, transportation, water conservation, public services, e-governance,” and other enterprises that could harm national security or the economy if damaged. Foreign corporations included in this category now face restrictions on equipment and services they can use, and they are vulnerable to inspection and intrusion by the Chinese government.
  • Restrictions on sending data outside China. The Law states that “personal information and other important data from operations within the PRC shall be stored within mainland China.” Business information and data on Chinese citizens cannot be transferred abroad without permission, and that would be contingent on intrusive “security assessments” by the Chinese government. Some U.S. analysis suggests that this could also prohibit the export of economic, technological, or scientific data considered to “pose a threat to national security or the public interest.”
The situation for foreign firms is uncertain at present because details on the scope of the Law and how it will be enforced are still unavailable. The initial impression among U.S. businesses is that the potential for intrusion and interruption is certainly considerable.

Wapack Labs has cataloged and reported extensively on China's cybersecurity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Wednesday, January 11, 2017

Foreign Influence of the 2016 Presidential Election


The 2016 U.S. Presidential Election was unprecedented on a number of levels. One’s personal politics aside, it is clear that there was a concerted foreign effort undertaken to influence the decision-making calculus of the American electorate. Was the perpetrator of that effort Russia, as conventional wisdom holds?

The analysts, linguists, and cultural experts at Wapack Labs looked at what data has been made publicly available from the government and other sources, as well as our own private data sources. We undertook this project to demonstrate that a serious analytic effort to attribute malicious activity is more than just connecting the dots: it is holistic, relying on diverse data sets, and subject to formal analytic methodologies.

Democracy Compromised is available to all Red Sky Alliance members in the portal.

We hope this work will both elevate the discussion around these issues, and enable decision-makers in the public and private sector who are concerned about these issues to focus their limited time on actual intelligence, rather than fear, hyperbole, and circular reporting.

Wapack labs is a cyber threat analysis and intelligence organization supporting the Red Sky Alliance, the FS-ISAC, and other organizations with targeted intelligence analysis that helps reduce risk and counter cybersecurity threats. Security teams, C-suites, and board rooms of public and private organizations around the world rely on our assessments and reports to keep them informed of threats to their enterprise. To learn more about us and the value of belonging to the Red Sky Alliance, contact sales@wapacklabs.com or call (603) 661-0366.

Saturday, October 1, 2016

Cyberwatch update

To all who've been using Cyberwatch(R) and provided feedback, thank you!  It's very much appreciated. As a result of some of these feedback,  Cyberwatch API version 1.1 was released last night, and its packed with improvements that you've requested:
  1. 25-35% faster with database clustering improvements
  2. For our automated alerting mechanism, we've built in dynamic notification API keys, which don’t require authenticating! Click through, see everything we know from that 
  3. API key removal from the url on the front end wrapper
  4. Security Updates & bug improvements 
To all who've not yet heard of Cyberwatch, last week we went public with a new application program interface (API), that allows users to run queries against our backend raw intelligence collections.  We knew two things... 

First, many (all?) companies need intelligence --not just information received when they buy that million dollar security tool, but a real understanding of what's going on outside of their border router that will likely affect them. 

Second, many of those companies would prefer to slog through the myriad of google groups, open source lists, and take on the dark web themselves and waste an enormous amount of time chasing things that just don't mean much to the questions they should be asking themselves. 

For example... a RISK focused security pro will always want to know if there's a RISK of something breaching. And if they do, what's the likelihood of loss?

An INTELLIGENCE focused security pro will want to look over the horizon for risks that'll might mean something soon, or they'll want to know that tactical information --what IP blocks should we be monitoring now? Blocking now? Remediating?

At the same time,  our customer base is largely 100,000 computers or bigger... which while good for us, represents a small number of companies who need help... and who may be partnered with or in the supply chain to these larger companies. 

I've talked with dozens of smaller companies. They simply can not, and like will never, spend the money on an intelligence shop.

So what if Wapack Labs could help them? What if we could allow users to query our backend data for say, 30 queries per day (for free), so that these smaller companies could see exactly what they're exposure looks like --and what if Wapack Labs could refer them to a security professional (under NDA of course) to help that smaller company get well? 

Well, that's exactly what we did.
  • Wapack Labs passively collects key logger 'dump' locations at about 1300 locations around the world; 
  • We collect on very specific sinkholes;
  • We collect some specific open source --but not all... we don't want circular reporting;
  • And we collect about a dozen other specific items that can help tell a company when they might have problems. 
And we make that all searchable to anyone who wants to search against it. 

As well, we started (this week) performing automated victim notifications. Our first batch, roughly 5000 of them, went out on Wednesday, with a no-cost, one time link to our databases to show the companies what we found, and why we think they may have been victimized. That email contains a link to our new Partner Exchange Program, and allows the victim to request a referral to one of our trusted, NDA'd,  partners who can assist in the cleanup if needed. 

The Cyberwatch API is available at api.wapacklabs.com.

Need more? We've built an ugly demo front end (we'll make it look nicer soon, I promise) on the API... cyberwatch.wapacklabs.com. Use it to monitor a portfolio of companies. If you're watching your supply chain, or a group of investment companies, you can set up five companies in our Cyberwatch front end, or you can use the API to bring the data into your own environment. Either way... you should be able to pull our data into a usable front end of your choosing or use ours.

So, to those who've provided feedback? We're listening.
To those who've not yet tried it? Try it! 

We're heading into Christmas shopping season. And although much of the work we'd done in the past is APT and Espionage related, we've taken on a second flavor in our analysis --money. So if you're a retailer, financial institution, or a supplier to one of these, as we head into the Christmas shopping season you should be watching our API at least daily, knocking down the threats we identify. 

Give it a try. There's absolutely no reason you shouldn't... it's free and we might know something about you that you don't already know.

Until next time,
Have a great weekend!
Jeff

(CyberWatch(R) is a registered Trademark of Wapack Labs Corporation.)


Monday, September 12, 2016

Wapack Labs Announces Cyberwatch® API for Proactive Cyber Threat Intelligence.

Orlando, FL, September 12, 2016:  Wapack Labs, a cyber threat intelligence company, announced their new Cyberwatch® Application Program Interface (API) today at the Information Security Certification Consortium (ISC2) Congress in Orlando, FL. Companies will now be able to search Wapack Labs’ cyber intelligence collections directly through this bold, new application. That means users can identify and address security threats faster—including before they’re realized.


Wapack Labs recovers information stolen by hackers from keylogger information, sinkholes, the dark web, malicious emails, and more. “With Cyberwatch® API, we’re opening our collections to those not normally privy to high-end cyber threat intelligence,” says Jeff Stutzman, CEO of Wapack Labs. Everything from usernames and passwords to financial transactions and credit card information can indicate previously unknown network breaches. Users can simply enter a company domain into Wapack Labs Cyberwatch® API (api.wapacklabs.com) and find out if it has been compromised. 



What makes Wapack Labs Cyberwatch® API of even greater value, however, is that it enables companies to be proactive. “Because of the sheer volume of our backend collections—which also includes data derived from malicious actors’ activities, and not just the information they steal—results from your search can help you identify if you’re being targeted.” Stutzman explains.  This is revolutionary for an industry where, today, offerings are almost always post-hoc; that is, they are built after a company has already been broken into. Antivirus, sharing intrusion prevention rules, and indicators of compromise all rely on expert analysis after someone has been hacked, and damage is already done. For another company to successfully capitalize on these types of security offerings, they must obtain and incorporate this information into their security tools before the threat evolves.



The Cyberwatch® API enables companies to connect their security tools directly to Wapack Labs’ intelligence backend, giving them direct access to clean, parsed data without requiring additional analysis, thereby prioritizing work for CISOs and their cyber security operations center (SOC) teams. 



These are not credential dumps or aggregated data,” says Stutzman. “This is information stolen by nefarious actors or malware from roughly 15,000 companies and organizations all over the world. If a company or individual finds themselves in a query of our data, if they haven’t been hacked yet, they may be soon, and can get a head-start on precautions.” 



Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC, and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber. Wapack Labs’ engineers, researchers, and analysts design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information, using deep analysis techniques and visualization. Information derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.



For questions or comments regarding this report, please contact the lab directly by at 603-606-1246, or Chuck Nettleship at cnettleship@wapacklabs.com.