Home Blog Page 107

Leading Post-COVID-19: Securing Applications in a Borderless World

Convergence of IoT Applications

The COVID-19 pandemic — the single most disruptive event in human history — has caused seismic shifts in how we engage with each other and the world. One of its most significant and, most likely, permanent impacts has been the acceleration of digitization in every industry, with technology becoming critical to everything we do, build and consume. The last few months have given us a glimpse into the future. Technology has enabled borderless enterprises, allowing decentralization of employment and equal opportunity for gig workers, especially women. These changes have increased democratic digital access to health care, banking, education, other essential citizen services, effective infrastructure management, and public safety, offering wider reach, and efficient implementation of benefit programs.

By Vishak Raman, Director of Security Business, Cisco India & SAARC

However, with the low-touch/no-touch economy fast becoming a reality, millions of devices and people are connected virtually. The preference for applications across the web and mobile for the delivery of all kinds of individual, corporate, and citizen services is rising. As a result, Application Security has emerged as the most urgent challenge in ensuring individuals’ and organizations’ safety and security in a new remote world, given that the threat landscape has not only widened but become far more complex.

Application Security: A Core to the New, Distributed Enterprise

and software gets deployed across new fronts such as cloud, mobile, and IoT, hackers will also have more avenues to target organizations. Therefore, putting the organization’s applications first will become a strategic move to safeguard the business’s most valued assets. There will be increased awareness and commitment to ensuring security early within the application development cycle.

DevOps has thus far been preoccupied with creating synergy between app developers and operational teams, who are often responsible for the smooth running of the business. This essentially means that security teams have little or no clarity of the app development process and come in once test cycles are already rolled out to build security layers on top of existing infrastructure. The focus on integrating security into the development and operations processes from the outset is deepening, thus shaping the DevSecOps model. Going forward, as application security programs mature, security testing during the development stage will be mandated to weed out bugs and glitches as early as possible.

As DevSecOps makes security a core aspect of building software in the development phase, there will be an organizational transformation where development and security teams understand each other’s roles better and begin to work together. Developers will be expected to have basic training in application security — basic understanding in input validation, error handling, and secure data handling when they write code.

The trend of “serverless” architectures, wherein a third-party provides the backend services as the application, which exists as programming code in the cloud, will see sustained growth. While these services are easy to use, it may be a point of concern for large organizations because their security and IT teams may not know how they operate (like unapproved storing of company data). Yet, the adaptability offered by these concepts does help to reduce the complexity of backend infrastructure for developers to a great extent.

Significant alterations are taking place in how organizations deploy and access applications, due to which we will see a subsequent change and expansion in how application security is conceptualized. Greater importance will be laid on application-level security monitoring as the application base grows, making it tougher to detect vulnerabilities in real-time. Further, visibility, segmentation, and access control will continue to gain traction. Concepts that typically come into play at the network level will be applied to applications directly.

securing applications

Emerging Challenges in Application Security

So far, the focus has been on on-premise and perimeter security. The traditional approach to security, which assumed a static application environment is no longer adequate in distributed, remote environments with users accessing corporate applications from multiple devices, public and private networks, from dispersed locations. As more and more organizations switch to cloud models to enhance the agility and resilience of their core processes and workflows, next-generation applications will be in a state of constant flux, as new functions are added, and existing ones are transformed.

This is introducing complexities in the current application security infrastructure. A Cisco study shows that 39% of surveyed organizations find that they are struggling to secure applications. The most troublesome aspect is data stored in the cloud, with 52% finding it extremely challenging to secure. According to a McKinsey survey, over 70% of security leaders believe that their budgets for FY21 will shrink.

To address these challenges, security leaders are assuming a much larger and more strategic role in identifying security priorities that align with overall business goals and allow for conscious spending, while ensuring end-to-end security of corporate applications. The shift is already taking place — while security budgets are expected to reduce overall, Gartner predicts that spending in application security will witness a growth of 6.2% in 2020, making it the third-highest segment after cloud security and data security.

This is primarily because security leaders are reimagining their blueprints for off-premise application security in preparation of operations post-COVID-19, for which building these capabilities is critical:

1. Simplifying Security Through Integrated Cloud Platforms

Application updates and evolution are crucial to success in a digital-first world. Still, they are capable of taking down the business if not prevented from malicious entities. To keep pace with expanding workplace boundaries, firms need simplified application security that offers visibility on a single integrated, cloud-native platform. This platform should be able to detect hard-to-find threats and policy violations through security analytics to drive more informed actions and automate security functions, including threat investigation and remediation, for more efficient operations.

2. Assuming Zero Trust Always, Everywhere

Most importantly, the platform should be anchored in a zero-trust framework, which can support the maintenance of software-defined access control over connections within applications and across a multi-cloud ecosystem based on users, devices, and applications, not on location.

Zero Trust assumes that all environments are hostile and breached. Therefore it proactively identifies and prevents attacks, protecting data at all endpoints through multi-factor authentication, DNS-based security, EDR (Endpoint Detection and Response), data leak prevention, and enhanced SecOps. For applications, this means workload and application protection through group-level and micro-segmentation, along with the implementation of behavioral analytics for detection and response to anomalies.

3. Securing User Identity with Comprehensive User Authentication Policies

Businesses need to have the ability to first verify trustworthiness before granting access to corporate applications so that they can prevent unauthorized access, contain breaches, and reduce the risk of lateral movement through the network. For this, identifying and deploying the appropriate user authentication policies is essential. These policies help ensure that only the intended audience is accessing certain assets in an organization. The person requesting sensitive information and data is the right person to access that information. This can be achieved by implementing VPNcontrolled access to certain apps, multi-factor authentication, single sign-on, and other tools.

4. Managing Dispersed Devices and Distributed Workloads

A certain level of access control must be applied to devices as well. Until now, most organizations had employees working on devices owned and managed by the company, permitting a greater level of control. With devices owned and operated by the user coming into play, access policies must be adapted to contain access to essential applications while limiting access to the more information-sensitive ones.

Additionally, protecting cloud-based and on-premise workloads require comprehensive security policies for applications that render them invisible, effectively reducing the attack surface. These policies can also help companies gain insight into their security posture across work settings and bring in an extra level of threat intelligence by identifying and addressing vulnerabilities before an incident occurs.

5. Protecting Cloud Assets and Private Networks

As more and more company assets migrate to the cloud, increasingly accessed through private networks, security leaders are turning their attention to cloud-delivered, SaaS (software-as-a-service) security to protect their applications. This will not only help them with the incident response across the distributed network, detect threats in real-time and reduce complexities and costs, but can also provide actionable security insights and intelligence to their security teams. Furthermore, it will automatically and preemptively detect early signs of a breach, including malware, multi-staged attacks, wrongly configured cloud assets, policy violations, and misuse, and send alerts in real-time.

Leadership in Enabling Our Secure Future

Security leaders are quickly rebalancing their budgets to prioritize application security, implementing measures that will aid in saving costs and improving efficiencies in managing remote environments. In the new world post-COVID-19, as application security and privacy become indispensable necessities for organizations, security leaders will serve as the bridge between business leaders, functional leaders, and their own operations teams. They will be instrumental in accelerating their organization’s recovery and shaping its new phase of growth, with security at the center of and foundational to all business imperatives.


About the Author

Vishak RamanVishak Raman is the Director of Security Business, Cisco India & SAARC. He has over 20 years of experience in the Information Security Services space with stints in product management, sales, marketing, and business development.

Prior to joining Cisco, Raman was the Sr. Regional Director – India & SAARC at FireEye. He was also the Global Head of Content Delivery Network (CDN) & Managed Security Services (MSS) business at Tata Communications, for three years.

Raman was the Sr. Regional Director for Fortinet (India/SAARC region) and is credited with having built Fortinet’s Unified Threat Management success story in India/SAARC. He was also instrumental in setting up the first-of-its-kind Global Technical Assistance Center at Bangalore for providing support to Fortinet’s customers worldwide. He has worked at WatchGuard, Sify, and HCL Technologies too.

Raman holds an engineering degree in Computer Science and a Post Graduate Diploma in Business Management (PGDBM) from IIM Ahmedabad.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


securing applications
This story first appeared in the October issue of CISO MAG.
Get your preview here.
 Subscribe now!

 

EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Register now!

McAfee to Sell Enterprise Business to Symphony Technology Group

Cybersecurity firm McAfee Corp. has entered into a definitive agreement to sell its enterprise business unit to a software firm Symphony Technology Group (STG) in an all-cash deal of $4 billion. The acquisition deal, which is subject to customary regulatory approvals, is expected to close by the end of 2021. McAfee’s enterprise business is one of the recognized device-to-cloud cybersecurity companies in the security industry for more than 30 years.

Key highlights of the deal

  • Divestiture of McAfee enterprise business for $4 billion in cash before tax
  • McAfee to become a pure-play consumer cybersecurity company
  • McAfee expects to issue an estimated $4.50 special dividend per Class A common share upon transaction close
  • McAfee expects to reduce debt by approximately $1 billion, which is expected to result in a neutral impact on to net leverage ratio

Until the closure of the deal, McAfee will continue to operate the enterprise business. After the transaction, McAfee will focus on delivering personal security solutions to consumers.

McAfee President and Chief Executive Officer, Peter Leav, said, “STG is the right partner to continue strengthening our Enterprise business, and this outcome is a testament to the business’ industry-leading solutions and most notably to the outstanding contributions of our employees. This transaction will allow McAfee to singularly focus on our consumer business and accelerate our strategy to be a leader in personal security for consumers.”

McAfee has made a place within the tech industry for its device-to-cloud cybersecurity software solutions. For more than 30 years, it has held a reputation of enterprise security, creating both consumer and business value.

iOS Call Recording App Allowed Snooping-in on Users Conversations

iOs

Researchers found a security vulnerability in the iOS call recording app “Automatic call recorder” that gave access to the conversations of thousands of app users. According to Anand Prakash, security researcher and founder of PingSafe AI, who discovered the flaw, the vulnerable app used open-source intelligence and exposed hostnames and other sensitive data from its cloud storage.

With more than a million downloads from the App Store, the Automatic call recorder app is a popular mobile application used by iPhone users to record their calls. The app developer fixed the vulnerability and released a new version after the researcher notified the issue.

Prakash stated that he discovered the vulnerability while performing open-source intelligence across mobile applications in various categories. The flaw has been leaking the cloud storage URL of the victim’s data to an unauthenticated API endpoint.  It allowed attackers to listen to any user’s call recording from the cloud storage bucket used by the application.

Reproducing the Vulnerability

  • Install the “Automatic Call Recorder” application on your phone.
  • Intercept application’s traffic in Burp Suite/Zap Proxy.
  • You will observe a POST API request to 88.123.157:80/fetch-sinch-recordings.phpchange UserID to victim’s phone number with country code.
  • The response will have an s3 URL for the recording and other sensitive details.

“Security issues like this are catastrophic in nature. Along with impacting customer’s privacy, this also dents the company’s image and provides added advantage to the competitors. PingSafe AI uses the state-of-the-art intelligent risk evaluation engine to monitors the security health of a company comprehensively by assessing all domains, IPs, mobile applications, source codes, and leaked credentials,” Prakash said.

Another Accellion Hack! Flagstar Bank’s Customer Data Breached

BlackMatter Group, Volvo Cars ransomware attack

Flagstar Bank suffered a data breach after cybercriminals compromised Accellion file transfer software, which the bank uses for sharing sensitive information. In an official release, the U.S.-based bank and mortgage lender revealed that threat actors belonging to the Clop ransomware group exploited the vulnerabilities in Accellion FTA servers. Based in California, Accellion is a private cloud solutions company that provides software for third-party secure file transfers.

The Breach Impact

Flagstar stated that the threat actors obtained access to some of its information on the Accellion platform. However, it clarified that its IT infrastructure outside of the Accellion platform was not impacted and all its functions are fully operational. However, Flagstar discontinued using Accellion’s file sharing platform and notified the users about the breach.

“Upon discovery, we acted immediately to contain the threat and engaged a team of third-party forensic experts to investigate and determine the full scope of this incident. We are working expeditiously with our internal and external teams to determine what data may have been accessed and will notify any impacted customers directly after we complete a thorough, diligent review of the data,” Flagstar said.

Flagstar is also offering free credit monitoring, fraud consultation, and identity theft restoration services to the affected individuals.

The Ripples of Accellion’s Flaw

Till now, threat actors attacked several organizations globally by exploiting the Accellion vulnerability. Multiple critical organizations including the Office of the Washington State Auditor (SAO), the Australian Securities and Investment Commission (ASIC), and New Zealand’s Reserve Bank suffered security breaches.  Recently, Singapore telco giant Singtel issued a statement confirming that over 129,000 of its customers’ data has been breached after attackers exploited a bug in Accellion’s software used by the company.

RedEcho Attacked 10 Indian Power Sector Companies and 2 Seaports: Recorded Future

Cyber-Security-Threat-to-National-Power-Grids, Recorded Future

Chinese state-actor hacker groups launched attacks on ten Indian power sector companies and two seaports since early last year. The latest attack occurred on February 28, which is attributed to the Chinese state-backed hacker group RedEcho. This was revealed in a webinar on March 9, by the U.S.-based cybersecurity organization Recorded Future. In its report “China-linked Group RedEcho Targets the Indian Power Sector Amid Heightened Border Tensions,” Recorded Future cites geopolitical reasons and heightened border clashes between the two Asian neighbors – India and China – since last May, as the reasons for these attacks. The report does not include any activities post-February 7. For the news story, which CISO MAG published on RedEcho, click here.

— Brian Pereira, Editor-in-Chief, CISO MAG

Recorded Future recently launched a network traffic analysis source which helps it trace the attacks from the targets/victims back to the attackers. It collects threat intelligence from various sources and transforms the information into actionable intelligence, through its platform and security intelligence graph. And it offers six solutions: brand intelligence, SecOps intelligence, threat intelligence, vulnerability intelligence, third-party intelligence, and geopolitical intelligence. Recorded Future disseminates threat intelligence through its portal, mobile application, browser extension, and API for integrations. It also advises governments and institutions alike, on mitigation strategies.

Since early 2020, Recorded Future’s Insikt Group observed a large increase in suspected targeted intrusion activity against Indian organizations from Chinese state-sponsored groups. From mid-2020 onwards, Recorded Future’s midpoint collection revealed a steep rise in the use of infrastructure tracked as AXIOMATICASYMPTOTE, which encompasses ShadowPad command and control (C2) servers, to target a large swathe of India’s power sector. Ten distinct Indian power sector organizations, including four of the five Regional Load Despatch Centres (RLDC) responsible for the operation of the power grid through balancing electricity supply and demand, have been identified as targets in a concerted campaign against India’s critical infrastructure. Other targets identified included two Indian seaports.

RedEcho attacks on Indian power sector
Suspected Indian power sector victims of RedEcho targeted intrusions Source: Recorded Future (Map Data: Google – 2021)

“We have been tracking the malicious activities of the RedEcho group since October 2020. And we have observed significant, sustained, high-volume traffic from Indian power sector assets to RedEcho infrastructure. RedEcho has overlapping MO with several Chinese groups, but we chose to name them because at this time, we do not have information to make a definitive connection to a specific existing group. The RedEcho infrastructure is still active, with the last observation on February 28, with comms to NTPC infrastructure,” said Charity Wright, Cyber Threat Intelligence Analyst with Recorded Future’s Insikt Group.

It was observed that RedEcho attacked National Thermal Power Corporation (NTPC) infrastructure. Recorded Future first observed RedEcho’s activity in October 2020. It also informed the Indian Government about the intrusion on October 10, which was two days before the major power outage experienced in the city of Mumbai and its satellite towns and cities.

However, Recorded Future cannot ascertain if the Mumbai power outage on October 12 was due to the RedEcho attacks.

According to a report in India Today, the Maharashtra state load despatch centre was targeted in October 2020.

“We cannot link that particular incident to RedEcho at this time,” said Wright.

Recorded Future again notified the Indian Government about the attacks on infrastructure on February 10 this year, and on February 11, India and China signed an agreement for de-escalation along Pangong Lake near the LAC (line of actual control).

Power companies in other counties have been targeted as well.

“A year ago, Recorded Future revealed an intrusion into a European energy organization (ENTSO-E), by a non-Chinese group. We used a similar methodology based on combining adversary infrastructure detection with network traffic analysis. We discovered a PuppyRAT malware campaign in late 2019. We published those findings on January 23, 2020 and the victim announced the intrusion on March 9, 2020,” added Wright.

Related Story:

Chinese Hacking Group “RedEcho” Targets Indian Power Sector

Key Judgments from Recorded Future

  • The targeting of Indian critical infrastructure offers limited economic espionage opportunities; however, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives.
  • Pre-positioning on energy assets may support several potential outcomes, including geostrategic signaling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation.
  • RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least five distinct Chinese groups.
  • The high concentration of IPs resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicates a targeted campaign, with little evidence of wider targeting in Recorded Future’s network telemetry.

To view the complete list of IoCs related to the RedEcho threat group, click here.

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStanley Mierzwa, Director, Center for Cybersecurity at Kean University, U.S., said, “Those organizations recently attacked should consider studying, or if unavailable, employing proper Information Governance strategies to help with the protection of data, as an invaluable asset. This effort will entail going back to the drawing table to study the legal and sector-related regulations, so that they are met, but more importantly so that they are exceeded! This focal action will include a process to employ tasks to help categorize the most critical and important information and data. Ensure to engage appropriate Information Governance policies that will help to enforce security-related information technologies, such as encryption, strict access controls, information rights management, digital shredding capabilities, auditing, and logging.”

Mierzwa lectures at Kean University on Cybersecurity Risk Management, Cyber Policy, Digital Crime and Terrorism, and Foundations in Cybersecurity. He is a regular contributor to CISO MAG. Be sure to read Mierzwa’s article in the April 2021 issue of CISO MAG.

About the Author

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years.

“Cybersecurity scholarships for women are needed”

It has been an age-old myth that women prioritize family over work. Women are under-represented in tech and leadership. According to an (ISC)² Cybersecurity Workforce Report, women working in cybersecurity account for about one quarter (24%) of the overall workforce. Though there’s a continuing inequity, things have begun to look brighter. Workforces – especially post-COVID-19 pandemic and lockdown – have been offering flexibility in timings, empowering women to lead, and showing support through digital mediums. Change happens with time, but it requires consistency. There is a need to go beyond the 24%.

Let’s hear what Julie Beck, Information Security Analyst, Homestar Financial Corp., Georgia, has to say about Women in Cybersecurity:

Less representation of women: I don’t think this is a “one size fits all” answer. I believe there are numerous reasons for different people.

One would be the cost of investing in education. Had I not had my company paying for my education and the scholarships I received, I would not have been able to afford the tuition as a single mom. The same goes for the cost of certification classes and certifications.

When I grew up, I was still a part of the generation who was told that women were not good in Science and Math. I still think we have a generation who is being taught this, but it is improving with STEM classes in our schools.

Then I believe that there are women who are intimidated to work in a male dominant industry. I will say that I’ve met few “bad apples,” but for the most part, men counterparts have been very supportive and accepting women into conferences and this industry.

Lack of women role models: I feel the dearth of women role models has lessened over the years. I do feel like there is still a slight dearth. I think it is more about getting to know the women in the field. I think that the women in this industry need to be more outspoken and stand up to be seen and heard so other women know we are here. In the years I was developing an interest in this field, one of my instructors was a woman. She had a passion for the material and presented herself in a way I admired and wanted to be like her. Having this role model gave me someone to look up to and to know that it is possible for women to be successful in this industry.

Cybersecurity scholarships for women: Yes! I absolutely feel that scholarships for women are important! For me, as a single mom, I prioritized spending money for my family and felt guilty for spending money to invest in myself. Programs like IBM’s, which paid for admittance to Hacker Halted, are needed. Scholarships for women are needed to help them get in and get interested. Once I landed a job in cyber, I was fortunate enough that my work would reimburse these costs. I still had to have the money or the credit to invest upfront many times though. Many women who have yet to enter the field do not have this luxury of getting reimbursed. We must alleviate the burden and financial strain to enter the industry.

What can men do? In my experience, I have had men mentor me and encourage me along my path. I feel it is important to not only have women role models but men who are accepting and encouraging. My mentor saw potential in me and invested in me. He encouraged me to take training and took the time to speak words of encouragement to me. Having someone from the opposite sex tell you in a professional manner that you have what it takes helped me from getting discouraged and prevented me from quitting numerous times.


Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview here. Subscribe now!

Delete These 9 Malicious Apps from Your Mobile Phones…Now

Mobile Apps Security, mobile apps

Cybersecurity experts from Check Point found threat actors dropping new malware via nine malicious Android apps on the Google Play store. Dubbed as Clast82, the new malware allows an attacker to illicitly obtain victims’ financial information by taking full control of their mobile devices. The search engine giant has removed the apps from the Play store after being notified by Check Point researchers.

 Clast82 Malware Dropper

The researchers stated that Clast82 malware can avoid Google Play Protect detection and change the payload dropped from a non-malicious payload to the AlienBot Banker and MRAT. Upon taking control of a device, the attacker can perform certain functions like installing a new application on the device or even control it with TeamViewer.

“The AlienBot malware family is a Malware-as-a-Service (MaaS) for Android devices that allows a remote attacker to inject malicious code into legitimate financial applications,” Check Point said.

The Nine Malicious Apps

“The malware’s ability to remain undetected demonstrates the importance of why a mobile security solution is needed. It is not enough to just scan the app during the evaluation period, as a malicious actor can, and will, change the application’s behavior using 3rd party tools. As the payload dropped by Clast82 does not originate from Google Play, the scanning of applications before submission to review would not prevent the installation of the malicious payload. A solution that monitors the device itself, constantly scanning network connections and behaviors by application would be able to detect such behavior,” Check Point added.

Is Google reCAPTCHA Really Secure?

recaptcha

Several cybersecurity experts have reported an increase in phishing attacks using Google’s reCAPTCHA feature to hide malware and escape security detections. A research team from Zscaler recently discovered a series of Microsoft-themed phishing attacks targeted at high-ranked employees in multiple organizations globally. Zscaler stated that it prevented over 2,500 such phishing attempts over the last three months.

“The attack is notable for its targeted aim at senior business leaders with titles such as Vice President and Managing Director who are likely to have a higher degree of access to sensitive company data. These campaigns aim to steal these victims’ login credentials to allow threat actors access to valuable company assets,” Zscaler said.

Scammers have been spreading their phishing campaigns across multiple industries, especially in the banking and IT sectors. While it is still unknown who is are behind these attacks, Zscaler stated that the phishing campaigns have been active since December 2020.

Purpose of reCAPTCHA

reCAPTCHA walls are typically used to verify and differentiate between human users and bots. Once the human intervention is verified, only then access to web content is allowed. It is also commonly used as one of the multi-factor authentication (MFA) techniques, which helps legitimate companies restrict bots from scraping and hijacking their content.

Exploiting Google reCAPTCHA

  • The campaign begins with cybercriminals sending phishing emails that appear as automated emails from their unified communications tools indicating that they have a voicemail attachment.
  • The phishing pages are hosted by using .xyz, .club, and .online generic Top Level Domains (TLDs).
  • When a user opens/clicks the attachment, it redirects the victims to a fake Google reCAPTCHA screen.
  • After verifying the reCAPTCHA, the page takes the user to a fake Microsoft login screen, allowing threat actors to steal victims’ login credentials.
  • After entering the login credentials, the campaign prompts a fake message saying, “Validation successful” and then shows a recording of a voicemail message to play, adding legitimacy to the phishing campaign.

“Similar phishing campaigns utilizing fake Google reCAPTCHAs have been observed for several years, but this specific campaign targeting executives across specific industry verticals started in December 2020,” Zscaler added.

WhatsApp Trialing Encrypted Chat Backups?

FMWhatsapp

WhatsApp has been feeling the heat of governments and its users for quite some time now. Be it for the “discriminatory policy” labeled by the Indian Government or the vulnerability that made WhatsApp account takeover possible, it has been in the news for all the wrong reasons. However, it has now decided to work towards a much-needed and highly appreciated offering – password-protected, encrypted chat backups for Google Drive and iCloud.

What is Encrypted WhatsApp Chat Backup

At the moment, this unique feature is still under development and there is no official feature release date made available by WhatsApp, said WABetaInfo who first broke the news on Twitter.

WhatsApp provides its users two options of performing chat backup and chat history, first is on the device itself and the second is on cloud storage like Google Drive for Android devices and iCloud for iPhone and Apple devices. WhatsApp already has End-to-End (E2E) encryption for their chat feature. However, the chat backups stored on cloud storage were not encrypted. Considering how privacy and security have now become the center of all discussions – especially post their new privacy policies issuance, which had been deferred by three months citing rumors and misinformation issues – WhatsApp seems keen on covering this base at the earliest to avoid more flak.

According to the screenshots shared by WABetaInfo on Twitter, it seems like the user will be required to enter their phone number to confirm password protection for their backups. However, there is a catch in this, because if any user forgets the password, WhatsApp does not give any “Forgot Password” link. This means it will simply not allow any user to access or restore the backup data if they do not remember the password.

So, memorize this password thoroughly, else there will be no backup to your WhatsApp chats available. We also recommend a password vault app like Norton Lifelock.

Related News:

WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?

Indian Government Asks WhatsApp to Withdraw its “Discriminatory” Policy

This Vulnerability made WhatsApp and Telegram Account Takeover Possible: Check Point

Episode #9: Protecting 5G Networks from Sophisticated Cyberattacks

Protecting 5G networks, Positive Technologies

The U.K. is one of the most developed markets in Europe in terms of 5G deployments, as people and critical national infrastructure become more dependent on these next-generation networks.  Apart from mobile network operators (MNOs) even utility providers, banks, manufacturers, and others are accelerating their deployments of private 5G. As these next-generation networks roll out this year, we can expect to see new and sophisticated attacks on 5G networks and attacks aimed at compromising the IoT devices on these networks.

And all this will cause substantial national security, cybersecurity, and privacy risks.

In November 2019, the U.K. government introduced the Telecommunications Security Bill which imposes harsher fines for operators who fail to protect their networks and subscribers. The European Union also released the EU Toolkit, which was supported by a document from ENISA, the European Union’s cybersecurity agency.

In this episode, we have Dmitry Kurbatov, Chief Technology Officer at Positive Technologies. He tells us how telecom operators have been impacted by the Bill. In February 2021, Positive Technologies launched a 5G Security Program to support mobile operators in securing their next-generation networks against new and hidden threats. Kurbatov offers some details of this program, and how will it help Telecom operators in the U.K. comply with the Telecoms Security Bill.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

Dmitry worked as a network engineer for system integrators from 2006. He joined Positive Technologies in 2010. First, he was engaged in the development of an automated security analysis system. Then he switched over to telecom security research, where his work included finding vulnerabilities in network equipment, errors in data transfer network design, protection of signaling protocols (SS7, Diameter, GTP). And then he moved on to IoT security. Since 2014, he has been Director of Telecom Security at Positive Technologies.

He holds a degree in information security of telecommunications systems from Moscow Technological University (MIREA).

Positive Technologies is a global cybersecurity company. They offer a Telecom Cybersecurity Suite that enables network operators to drive business performance while protecting their subscribers and services.

By providing greater visibility into infrastructure vulnerabilities and securing customer services, Positive Technologies helps to strengthen loyalty, drive revenue with value-added security offerings, and protect emerging telecom technologies such as 5G and the IoT.

Listen to more podcasts episodes from CISO MAG here.


Brian PereiraAbout the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years.