Published on: August 17, 2023
The Cyber Safety Review Board (CSRB) has released a comprehensive analysis highlighting the dangers posed by the Lapsus$ threat group, urging businesses and government agencies to bolster their identity and access management systems. This report comes in the wake of a series of cyberattacks orchestrated by Lapsus$ between 2021 and 2022.
Lapsus$, described as a loosely organized group, has gained notoriety for its extortion-focused cyberattacks. The group’s modus operandi often involves exploiting vulnerabilities in identity and access management systems, stealing source codes, demanding ransoms, and infiltrating corporate networks. Notably, some of its members are believed to be teenagers, which poses challenges for law enforcement due to lighter penalties for juvenile threat actors, under certain jurisdictions.
A significant concern raised by the CSRB is the inadequacy of the current multi-factor authentication (MFA) systems.
“The Board found that the multi-factor authentication (MFA) implementations used broadly in the digital ecosystem today are not sufficient for most organizations or consumers,” the report read. “In particular, the Board saw a collective failure to sufficiently account for and mitigate the risks associated with using Short Message Service (SMS) and voice calls for MFA.”
The CSRB’s recommendations are multifaceted. They advocate for a shift from voice and SMS-based MFA to Fast IDentity Online (FIDO)2-compliant, hardware-backed solutions. The board also urged telecommunication providers to enhance their defenses against SIM swapping and called for increased oversight from the Federal Communications Commission (FCC) and Federal Trade Commission (FTC).
Furthermore, the CSRB emphasized the importance of strengthening identity and access management, addressing vulnerabilities in telecommunications, and building resilience in multi-party systems. They also highlighted the need for lawmakers to “advance ‘whole-of-society’ programs and mechanisms for juvenile cybercrime prevention and intervention.”
As cyber threats continue to evolve, the CSRB’s insights and recommendations serve as a crucial guide for organizations aiming to fortify their defenses in this digital age.
“Our ability to protect Americans from cyber vulnerabilities has never been stronger thanks to the community we are building through the Cyber Safety Review Board,” said Secretary of Homeland Security Alejandro N. Mayorkas. “As our threat environment evolves, so too must our detection and prevention capabilities. We must also evolve our ability to deploy those capabilities. The CSRB’s findings are not only timely, they are actionable and written with the guidance of real-world practitioners in the private sector.”
- SEO Powered Content & PR Distribution. Get Amplified Today.
- PlatoData.Network Vertical Generative Ai. Empower Yourself. Access Here.
- PlatoAiStream. Web3 Intelligence. Knowledge Amplified. Access Here.
- PlatoESG. Automotive / EVs, Carbon, CleanTech, Energy, Environment, Solar, Waste Management. Access Here.
- PlatoHealth. Biotech and Clinical Trials Intelligence. Access Here.
- ChartPrime. Elevate your Trading Game with ChartPrime. Access Here.
- BlockOffsets. Modernizing Environmental Offset Ownership. Access Here.
- Source: https://www.safetydetectives.com/news/csrb-lapsus-threat-group-poses-cybersecurity-risks/
- :has
- :is
- :not
- 17
- 200
- 2021
- 2022
- 300
- 40
- a
- ability
- access
- access management
- Account
- actors
- addressing
- advocate
- Affiliate
- against
- age
- agencies
- Aiming
- also
- Americans
- analysis
- and
- ARE
- AS
- associated
- Authentication
- avatar
- BE
- been
- believed
- between
- board
- bolster
- broadly
- Building
- businesses
- by
- called
- Calls
- capabilities
- certain
- challenges
- codes
- Collective
- commission
- Communications
- community
- comprehensive
- Concern
- Consumers
- continue
- Corporate
- crucial
- CSRB
- Current
- cyber
- cyberattacks
- cybercrime
- Cybersecurity
- dangers
- data
- demanding
- deploy
- described
- Detection
- DHS
- digital
- digital age
- digital ecosystem
- due
- ecosystem
- emphasized
- enforcement
- enhance
- Environment
- evolve
- evolves
- Failure
- FAST
- FCC
- Federal
- Federal Communications Commission
- Federal Trade Commission
- findings
- For
- found
- from
- FTC
- gained
- Government
- government agencies
- Group
- Group’s
- guidance
- guide
- Highlighted
- highlighting
- homeland
- Homeland Security
- HTTPS
- Identity
- identity and access management
- importance
- in
- increased
- insights
- intervention
- ITS
- jurisdictions
- Law
- law enforcement
- lawmakers
- lighter
- LINK
- management
- mechanisms
- Members
- message
- MFA
- Mitigate
- Modus
- most
- multi-factor authentication
- multi-party
- multifaceted
- must
- Need
- networks
- never
- notably
- of
- often
- on
- online
- only
- or
- orchestrated
- organizations
- Organized
- our
- Oversight
- particular
- plato
- Plato Data Intelligence
- PlatoData
- poses
- Prevention
- private
- private sector
- Programs
- protect
- providers
- raised
- Read
- real world
- recommendations
- released
- report
- resilience
- review
- risks
- Safety
- Said
- saw
- secretary
- sector
- security
- Series
- serve
- service
- shift
- Short
- significant
- SIM
- SIM Swapping
- SMS
- So
- Solutions
- some
- Source
- strengthening
- stronger
- sufficient
- swapping
- Systems
- teenagers
- telecommunication
- telecommunications
- thanks
- that
- The
- their
- they
- this
- those
- threat
- threat actors
- threats
- Through
- to
- today
- too
- trade
- under
- urging
- used
- using
- Voice
- Vulnerabilities
- Wake
- we
- webp
- which
- with
- written
- zephyrnet