Home Blog Page 125

Indian Government Asks WhatsApp to Withdraw its “Discriminatory” Policy

Whatsapp

In the latest saga of WhatsApp’s changes in its data sharing policy, the Indian Government has written a letter to WhatsApp CEO, Will Cathcart, asking him to withdraw the “discriminatory” policy changes that are challenging the “right to privacy” of Indian users bestowed upon them by the country’s constitution itself. Owing to the extensive criticism and the amount of misinformation spread related to the updated privacy policies, WhatsApp has decided to delay the changes by three months until everything is sorted.

What were the WhatsApp Privacy Policy Changes?

WhatsApp’s updated Privacy Policy mandated users to share their data with its parent company Facebook. It included sharing the metadata of users’ chat with business accounts of other Facebook companies. Moreover, WhatsApp did not allow users to opt-out of such a drastic change in the privacy policy.

Related News:

WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?

Why is the Indian Government Opposing?

According to a report from a national news channel NDTV, experts in the government familiar with the matter cited concerns over WhatsApp’s data collection and sharing with the other parent and sister companies. They said, “It would create a honeypot of information about users with a Facebook group, which can invariably create security risks and vulnerabilities for all users.”

Secondly, the Ministry of Electronics and Information Technology (MeitY) is baffled by the double standards of WhatsApp. In the European Union (EU), WhatsApp has given an opt-out option to its users; however, the Indian user base, which the company states are the biggest in the world, does not get one. MeitY strongly condemned this “discriminatory treatment” and termed it “disrespectful” towards Indian citizens. In a stern voice, MeitY reminded WhatsApp that it has a sovereign right to protect the interests of Indian citizens and it shall not compromise on that at any cost.

After a brief study of the updated policy, the Indian government is now seeking clarity and conformance on privacy and data security concerns. It has sent a list of 14 questions asking about the disclosure of the exact categories of data that WhatsApp collects from its users in India, the permissions and user consent sought by the app, and how each of these sets of data will be used by the company post collection.

Petition in Delhi High Court Against WhatsApp’s Policy

Meanwhile, a lawyer has filed a petition against WhatsApp’s new privacy policy, which was heard in the Delhi High Court on Monday, January 18. The petitioner argued that the updated privacy policy violates users’ right to privacy under the Indian Constitution and must not come into effect. However, Kapil Sibal and Mukul Rohatgi, senior advocates and defendants of WhatsApp and Facebook,  found this argument baseless. They told the High Court that none of the private or group chats were being accessed or stored by WhatsApp, and very much remained encrypted. They further argued that it was only the business chats on WhatsApp that were getting affected.

In response to the petition, Justice Sanjeev Sachdeva said, It is a private app. Don’t join it. It is a voluntary thing, don’t accept it. Use some other app. Pointing at other apps like Google Maps, Justice Sachdeva stated that even others do it and you would be surprised as to what all you are consenting to. However, the High Court wanted more time to analyze the amount of data being shared and the data that was being leaked as per the petitioner. Thus, the matter will be listed on January 25 for further address.

Related News:

After Juspay, ClickIndia, ChqBook and WedMeGood Allegedly Suffer Data Breaches

FireEye Releases ‘Azure AD Investigator’ to Know SolarWinds Hacking Techniques

FireEye’s Red Team tools breach

The SolarWinds supply chain cyberattack took the digital world by storm, affecting government agencies and IT giants. To detail the techniques used by the SolarWinds threat actors, also known as UNC2452 actors, cybersecurity firm FireEye released a free tool, dubbed Azure AD Investigator, on GitHub.

FireEye claimed that Azure AD Investigator helps identify Indicators of Compromise (IoC) that require further verification and analysis. The tool will alert security administrators to artifacts that may require further review to determine their legitimacy.

The company also issued a report detailing the attack techniques used by SolarWinds threat actor groups in their recent cyber operations.  The report discussed how companies can boost their security landscape and remediate cybersecurity loopholes. FireEye, along with Microsoft and CrowdStrike, recently led several investigations into the SolarWinds cyberattacks.   FireEye has observed UNC2452 attackers’ tactics, techniques, and procedures (TTPs) moving laterally to the Microsoft 365 cloud using a combination of four primary techniques. These include:

  • Steal the Active Directory Federation Services (AD FS) token-signing certificate and use it to forge tokens for arbitrary users (sometimes described as Golden SAML). This would allow the attacker to authenticate into a federated resource provider (such as Microsoft 365) as any user, without the need for that user’s password or their corresponding multi-factor authentication (MFA) mechanism.
  • Modify or add trusted domains in Azure AD to add a new federated Identity Provider (IdP) that the attacker controls. This would allow the attacker to forge tokens for arbitrary users and has been described as an Azure AD backdoor.
  • Compromise the credentials of on-premises user accounts that are synchronized to Microsoft 365 that have high privileged directory roles, such as Global Administrator or Application Administrator.
  • Backdoor an existing Microsoft 365 application by adding a new application or service principal credential to use the legitimate permissions assigned to the application, such as the ability to read email, send email as an arbitrary user, access user calendars, etc.

Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Popular American health insurer Excellus Health Plan has agreed to pay a penalty of $5.1 million to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) to settle a data breach that occurred in 2015. Excellus has been penalized for potentially violating the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules.

Though Excellus discovered the data breach in 2015, it began before December 2013. Attackers illicitly gained access to Excellus computer systems and compromised more than 9.3 million individuals’ Protected Health Information (PHI). The data breach, which lasted over 17 months, exposed consumer details like names, addresses, social security numbers, health plan claims, bank account information, and other sensitive information.

Excellus Violated HIPAA

As per the OCR investigation, Excellus violated the HIPAA Act by failing to perform an enterprise-wide risk analysis, implement risk management service, and protect customers’ sensitive information.

“The settlement agreement contains no finding of HIPAA or other violations, nor does the company make any admissions or concessions. The civil rights office started its investigation in 2016, and there are no new factual findings regarding the attack as a result of the OCR inquiry,” said Excellus spokesman Jim Redmond.

“We know that the most dangerous hackers are sophisticated, patient, and persistent. Health care entities need to step up their game to protect the privacy of people’s health information from this growing threat,” said OCR Director Roger Severino.

Biggest HIPAA Fine So Far

In one of the biggest HIPAA fines imposed by OCR in 2019, Jackson Health Systems, Florida, was charged $2.15 million on account of multiple HIPAA violation instancesWith the intent of identity theft, an employee of Jackson Health Systems leaked and sold around 2,000 PHI patient records. Read more

MAS Tightens Rules for Financial Firms in Singapore Post SolarWinds Cyberattack

Singapore cybersecurity

The SolarWinds cyberattack has affected almost all the sectors around the globe. Taking into account the outreach and aftermath of the attack, the Monetary Authority of Singapore (MAS) has issued a new set of rules for effective tech risk management that came into effect on January 18, 2021. According to the MAS directives, all financial services and e-payment service providers must adhere to the new set of central banking rules.

What was the Need?

The MAS has strict control over all the financial firms providing services in Singapore. However, the SolarWinds attack was an eyeopener to the agency. During the SolarWinds cyberattack, cybercriminals compromised a third-party firm and gained access into the target’s mainframe. Government networks like the U.S. Department of Treasury, the U.S. Department of Commerce, and the National Nuclear Security Administration (NNSA), and even tech giants like Microsoft and FireEye were not spared. Thus, the third-party service provider was a free pass gateway, which was a threat in the first place. MAS wants to mitigate this flaw and has made effective modifications to the rules.

Related News:

SolarWinds Hack Affected Yet Another Tech Giant – Microsoft

MAS’s New Rules for Tech Risk Management

Previously, MAS did not mandate the assessment of third-party service providers and vendors. However, now MAS requires all financial firms, including e-payment providers, brokerage, and insurance providers, to assess the suppliers and third-party products and software of their technology partner/vendors. Suppliers may need to prove their software is rigorously tested and that they do not fall short on exercising best practices in their programming. Additionally, the new rules also provide a right to ask the suppliers to reveal their security measures and the frequency of their cyber risk monitoring.

Risks from third-parties keep increasing by the day as newer technologies and the need to integrate them arises. For example, the usage of APIs for daily banking and payment services is now very important. Without APIs, online customers will not be able to make any payments on e-commerce websites or apps. However, payment gateways can act as a threat vector as well. MAS now wants to stop the compromise by strictly asking the vendors to secure the development of their APIs and encrypt sensitive data transmitted to prevent leaks or hackers injecting malicious codes into their APIs.

Other Inclusions in the Risk Management Rules

MAS has recorded a tremendous growth in mobile application usage and BYOD devices. Owing to this, it has also issued guidelines for the testing and mitigation of mobile device or application management. This mainly includes:

  • Static Application Security Testing
  • Dynamic Application Security Testing
  • Interactive Application Security Testing
  • Fuzzing or Fuzz Testing
  • Mobile Device or Application Management
  • Virtualization

Related News:

More than Half of Singapore Businesses Admit that Cybersecurity is on the Back Burner

FBI Warns Enterprises About Rising Vishing Attacks

The FBI is warning about threat actors targeting remote employees by exploiting network misconfigurations and remote workforce access privileges. The agency has issued a Private Industry Notification (PIN) to notify about various cyberattacks targeting global corporate networks to illicitly obtain employees’ credentials. It noted that cybercriminals are leveraging vishing techniques and chatrooms to perform social engineering attacks on employees. In a vishing attack,  a victim is phished over the phone to obtain sensitive data like login details.

Shift in Attack Tactics

FBI claimed that attackers have changed their hacking techniques to compromise users’ accounts and credentials. Several cybercriminal groups collaborated to target employees of popular enterprises worldwide using (Voice over Internet Protocol) VoIP platforms. VoIP is a technology that converts voice into a digital signal and allows to make calls directly from a computer, a VoIP phone, or other data-driven devices.

“During the phone calls, employees were tricked into logging into a phishing webpage to capture the employee’s username and password. After gaining access to the network, many cybercriminals found they had greater network access, including the ability to escalate privileges of the compromised employees’ accounts, thus allowing them to gain further access into the network often causing significant financial damage,” the FBI said.

Threat actors also phished employees via official chatrooms and convinced them to login onto fake VPN pages. The operators then used the compromised credentials to log into the company’s VPN and performed reconnaissance to locate someone with higher access privileges.

Mitigation Measures

The FBI also recommended certain security protocols to mitigate the risks from all kinds of phishing attacks. These include:

  • Implement multi-factor authentication (MFA) for accessing employees’ accounts to minimize the chances of an initial compromise.
  • When new employees are hired, network access should be granted on a least privilege scale. Periodic review of this network access for all employees can significantly reduce the risk of compromise of vulnerable and/or weak spots within the network.
  • Actively scanning and monitoring for unauthorized access or modifications can help detect a possible compromise to prevent or minimize the loss of data.
  • Network segmentation should be implemented to break up one large network into multiple smaller networks which allow administrators to control the flow of network traffic.
  • Administrators should be issued two accounts: one account with admin privileges to make system changes and the other account used for email, deploying updates, and generating reports.

Related Story: Five Baits that Get You Phished

Why Apple Dropped macOS Big Sur Feature ‘ContentFilterExclusionList’

Apple App Store, Apple vulnerabilities

Apple has dropped a controversial feature from its macOS Big Sur 11.2 beta 2 that allowed 53 of its applications to evade security scans, third-party firewalls, and VPNs. The feature, dubbed ContentFilterExclusionList, allowed popular apps like App Store, iCloud, FaceTime, Music app, and Maps to bypass the security protocols, which could be exploited by cybercriminals.

The Controversial Feature

In the latest versions of macOS, Apple deprecated third-party Kernel Extensions, including the Network Kernel Extensions (NKEs), which are used to comprehensively monitor and filter the network traffic. Apple launched the user-mode Network Extension Framework to support such products on modern versions of macOS (10.15+). However, it exempted more than 50 of its applications from being routed through the Network Extension Framework.

What Researchers Say…

The issue came to light in October 2020, after several security experts and app developers reported that their security tools failed to monitor/filter the traffic of the apps listed under ContentFilterExclusionList.

According to security researcher Patrick Wardle, cybercriminals can create malicious codes to exploit the legitimate Apple apps present in the list and then bypass the security tools and firewalls. He said, “Due to the ContentFilterExclusionList list, any traffic generated from these ‘excluded items’ could not be filtered or blocked by a socket filter firewall (such as LuLu).”

Users of macOS are also concerned about exposing their actual IP address and locations while using these apps.

Wardle Tweets…

“The ContentFilterExclusionList list has been removed (in macOS 11.2 beta 2). This means socket filter firewalls (such as LuLu) can now comprehensively monitor & block all network traffic). In Big Sur, Apple decided to exempt many of its apps from being routed thru the frameworks they now require third-party firewalls to use (LuLu, Little Snitch, etc.),” Wardle added.

AjnaLens – Making Augmented Reality a Reality

AjnaLens

In the last three decades, we have seen how innovation in computer technology has transformed human life at a rate which no other invention has done before. This was possible because computers augmented human intelligence and enhanced their capabilities. Over the years, computers have transformed from huge machines–that consume the space of an entire room–to handheld tablets. The evolution is still underway, as we now move towards wearable devices that are just smaller versions of computers.

Wearables have become the talk of the town in recent years owing to their wide range of consumer-focused and industry-based offerings. These devices are broadly classified into four types:

  • Smart glasses and head gear
  • Smart watches
  • Wearable medical devices
  • Fitness trackers

Of these, the one that really interests and fascinates people the most is the head-mounted wearable display. These devices have the broadest scope of usage as they visually transmit data and information to the eyes via the headgear. Considering the tech industry’s inclination towards, and the demand for wearable gadgets and artificial intelligence (AI), a bunch of tech enthusiasts came together to co-found AjnaLens.

The company, registered under the name Dimension NXG Pvt. Ltd., is co-founded by Pankaj Raut (CEO), Abhishek Tomar (CTO) and Abhijit Patil (COO). Before AjnaLens, all the co-founders worked in different fields. Raut, who comes from a business background, had developed a tech product in 3D scanning, Tomar headed the VFX team at Red Chillies Entertainment and Patil was working with Godrej on process planning and optimization for the manufacturing of Brahmos Missile. However, expertise from various domains is exactly what worked in their favor. They covered all bases required to form a startup – technology, business and operations.

Using the brand name, the company designed AjnaLens – a pair of AI-powered mixed reality (MR) glasses that augments human intelligence. In layman’s terms, this pair of glasses enables the user to use AI and helps in better, concise and real-time decision making in fields ranging from education to enterprise to defense.

The Struggle

The path to success like other tech startups was not flower-laden. Finding the right investors and visionaries who believed in their vision and the future of such a technology was an uphill task. They were in a literal sense talking sci-fi; talking to investors was like talking to people with a James Bond movie script in hand. The industry was unexplored, untouched, and unheard off. Raut, Tomar, and Patil needed brave and visionary people by their side. They were fortunate enough to have met people like Vijay Shekhar Sharma, Founder and CEO of Paytm, and Nailesh Khimji, Director and Board Member – Khimji Ramdas Group (Oman), among other angel investors. After acquiring the required seed funding, it was time to get to the drawing table and this is where the second part of the challenge began.

Network Security and Bandwidth

Uninterrupted streaming of Augmented Reality (AR) based on cloud-hosted content and services requires huge bandwidth and coverage in areas where these wearable AR glasses are deployed. Ensuring reliable Wi-Fi and other modes of network availability in remote locations, where even mobile/cellular network coverage is not present, was a daunting challenge.

Both devices and networks require the highest security standards in sensitive environments to ensure critical, personal and organizational information is not compromised. These devices carry massive amounts of user data ranging from user demographics to personally identifiable information (PII). The team at AjnaLens was very much aware of the cybersecurity aspect of their wearable glasses, especially being in the defense sector. Thus, they implemented multi-layered 256-bit encryption to secure the data and communication of these devices. An in-depth discussion with the team related to the core cybersecurity technology used in the wearable was not possible as they are still awaiting a few security certificates and clearances from the defense authorities. However, after two years of intensive R&D, the team was confident about the data safety of this device and finally launched AjnaLite and AjnaLite Plus at DIDAC in September 2019.

The Beginning of the Rise

The trio was very clear about their first target industry – the Education industry. They found a way to integrate AR/VR technology and AI in one headset, that would help education and training in remote areas. This was the beginning of the rise. The startup was immediately taken note of by the local and international media, and won many accolades including Technology Innovation Leadership Award in Augmented Reality Headset – Frost & Sullivan (2018), Awarded #1 Innovation across India by CII, AICTE & DST, Early Growth IOT Startup of the year – The AEONIAN 2018 and many more.

The Future of Warfare

Meanwhile, the team at AjnaLens saw a huge potential of their technology in the future of warfare. Thus, was born one of the world’s most advanced MR glasses for defense and law enforcement forces – AjnaBolt. This pair of MR glasses was launched at the recently held Defence Expo 2020, in the presence of India’s Prime Minister Narendra Modi, and Defence Minister Rajnath Singh. AjnaLens also signed an MoU with the government to set up a manufacturing unit in the state of Uttar Pradesh, India.

What’s Next

AjnaLens is soon launching an enterprise version of its AR glasses, in 2020, called AjnaOne. To support the manufacturing of the enterprise version and further enhance their AR/VR capabilities, AjnaLens raised a Pre-Series A funding of US$1.5 million which was led by Maharashtra Defence and Aerospace Venture Fund.

With nearly 15+ Patents in AR/MR and allied fields under their name, and after receiving the backing from the Government of India-led institutions like DRDO, Army, Navy and Air Force the co-founders humbly said, “The journey is still challenging. But people are slowly realizing the possibilities and opportunities. They are now coming forward to join hands for a larger vision.”

S N A P S H O T
Company Dimension NXG Pvt. Ltd. (Brand Name – AjnaLens)
CEO Pankaj Raut, Co-founder and CEO
Website https://www.ajnalens.com
Consulting Partner Optiv
Tech Partners CISCO, AWS, RSA
Social Media Handles
Location(s) Mumbai and Bangalore (India)
Employees 20
Total Funding US$ 2.2 Million (till Feb 2020)
Funding
  • Seed Round/Angel Round
    • Total investment: US$411,000
    • List of investors
      • Vijay Shekhar Sharma, Founder and CEO – Paytm
      • Japan Vyas, Founder – Root Ventures
      • Nailesh Khimji, Director and Board Member – Khimji Ramdas Group (Oman)
      • Chetan Kajaria, Joint MD – Kajaria Ceramics
      • Manish Bhatia, Chairman – Bhatia Brothers
      • Jay Jesrani, Mountain Lion Partners
      • Multiple other Angels
    • Grant
      • Total amount – US$215,000
      • Received grant of ₹ 1.5 Crore (approx. US$215,000) from the Ministry of Defence under iDEX initiative to develop and give military tanks as see through capability in 360 degrees (X-Ray Vision).

 

  • Pre-Series A
    • Total investment in US$ 1.5 Million
    • List of investors
      • Nailesh Khimji, Director and Board Member – Khimji Ramdas Group (Oman)
      • Mohsin Hani Al Bahrani, Director – Mohsin Haider Darwish Group
      • Michael Marks, Founder – Innoventure Partner
      • Multiple other HNI
    • Lead investor – Maharashtra Defence and Aerospace Venture Fund
Industry-wise Services
  • Aerospace, Defense & Law enforcement
  • Education
  • Enterprise (Launching in 2020)
    • Architecture, Construction and Interior designing
    • Manufacturing
    • Oil & Gas
    • Automobile
    • Retail
    • Logistics
    • Media & Entertainment

 

PRODUCTS OFFERINGS
Offerings
  • AjnaBolt for Defence: AjnaBolt is a pair of mixed reality glasses that enhances situational awareness, decreases response time, and helps the defense and law enforcement personnel make better tactical decisions instantly. It receives, compiles, and processes the raw data from various sources using AI and shows critical information in the most intuitive way possible.
  • AjnaLite for Education: AjnaLite is an affordable standalone AR/VR headset that enables the students to enhance their imagination and ignite their curiosity as well as increase focus and memory retention. It helps the educators take their teaching experience to the next level by getting immersed in the students’ learning process and guide them better using performance insights.
  • AjnaOne for Enterprise: Launching soon.

Company Timeline

 2014 

  • Founded in Mumbai Maharashtra
  • Founders met at Google startup weekend held at IIT Bombay. Synergies between founders met and decided to start working together on technologies that could have a positive impact on human lives.
  • Officially registered on November 14, 2014

 2015 – 2017 

  • Raised first funding: Angel Round
  • Team Size of 5
  • Incubated at Zone Startup India.
  • Build an in-house R&D Optics Lab
  • Dedicated the 2 years for R&D in Optics, 3D World sensors and tech.
  • Got the first fully functional prototype ready.
  • Started generating revenue using allied skills in 3D Printing.
  • Applied for 6 patents in India.
  • Landing 20+ Letters of Interest.

 2018 

  • Team size expanded to 10
  • Created breakthrough in Multiple Optics for Augmented Reality
  • Applied for 6 patents.
  • Started multiple Industry paid pilots.

 2019 

  • Team exceeds 15 members
  • Launched AjnaLite and AjnaLite Plus at DIDAC in September 2019 for pre-orders
  • Signed 30+ LOI/MoU with private schools and colleges to setup AR/VR Lab
  • First batch manufacturing of AjnaLite and AjnaLite Plus started
  • Received grant of ₹ 1.5 Crore (Approx. US$215,000) from the Ministry of Defence (India) under iDEX initiative to give military tanks a see-through capability in 360 degrees (X-Ray Vision)
  • Accelerated at Forge accelerator
  • Key Customers: DRDO, PM Experts, Army, etc

 2020 

  • February, launched AjnaBolt at the Defence Expo 2020
  • Completed fundraise of US$1.5 million lead by Maharashtra Defence and Aerospace Venture Fund
About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

**Disclaimer**

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by AjnaLens. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article. The material in this article was curated from brochures and other sources as provided by AjnaLens.

Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

AI-based cybersecurity firm Cybereason recently announced a collaboration with Intel Hardware Shield to provide protection against ransomware attacks without disrupting the CPU resource consumption. “The joint solution represents the first instance where PC hardware plays a direct role in ransomware defenses to better protect enterprise endpoints from costly attacks, and underscores both companies’ commitment to empowering defenders by reversing the adversary advantage,” Cybereason said.

The solution leverages the CPU-based threat detection to find and prevent ransomware attacks. It also integrates Intel Threat Detection Technology (TDT) capabilities with the Cybereason Defense Platform to deliver ransomware intelligence for threat detection and helps enterprises enhance their security capabilities.

Key Features of the Intel and Cybereason Joint Solution

  • Enables enterprise customers to go beyond signature and file-based techniques by leveraging CPU-based behavioral prevention of ransomware.
  • Eliminates blind spots to expose ransomware as it avoids detection in memory or hides in virtual machines while differentiating legitimate data encryption processes for business purposes.
  • Enterprises can accelerate performance-intensive machine learning security algorithms by offloading to the Intel integrated graphics controller to boost capacity to analyze more data and do more security scans.
  • Enterprises can bolster the performance of their security agent processing for better user experiences.

“This collaboration with Intel to add CPU based threat detection bolsters our long history and industry-leading capabilities in detecting and eradicating ransomware. The combination of best-of-class hardware, software, and security know-how provides defenders with full-stack visibility critical to ending the era of double extortion that is currently costing organizations hundreds of millions each year,” said Lior Div, CEO and Co-Founder, Cybereason.

“Ransomware was a top security threat in 2020, software alone is not enough to protect against ongoing threats. Our new 11th Gen Core vPro mobile platform provides the industry’s first silicon enabled threat detection capability, delivering the much-needed hardware-based protection against these types of attacks. Together with Cybereason’s multi-layered protection, businesses will have full-stack visibility from CPU telemetry to help prevent ransomware from evading traditional signature-based defenses,” said Stephanie Hallford, Client Computing Group Vice President and General Manager of Business Client Platforms at Intel.

$220 Million Riding on the Last Two Chances of Guessing a Password

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

A German programmer is sitting on a treasure chest that he knows is there and yet cannot open and savor it. Why? Because he has lost its key! It may sound funny, but a computer programmer named Stefan Thomas is having his worst nightmare come true. Amid the bitcoin boom, he had invested and bought 7,002 bitcoins which are saved and safely stored in his wallet. However, Thomas has forgotten the password of his IronKey hard drive which holds the private key to his wallet. Stefan now has only two attempts left to correctly guess the password else his treasure will remain beyond his grasp for eternity.

Why Bitcoins are Being Cashed

The Bitcoin price which was at $20,000 per coin has soared to a record high of $36,000 in a months’ time. This skyrocketing is not new because if the price has soared by 92% in the last one month, overall, it has boomed by 340% in a year. This all-time high has pepped the bitcoin owners to sell their bitcoins and savor their riches. However, a New York Times report shows that 20% of the cryptocurrency owners have either lost their passwords or have their wallets stranded. This means they now own a fortune but still cannot enjoy the riches.

Related News:

PII of Thousands of Users Exposed in Multi-Stage Bitcoin Scam

The Last Two Chances to Guess the Password

According to the NYT report, Thomas has stored the private key to his wallet in a small IronKey hard drive. This piece of hardware is protected by a password which allows the user to make only 10 possible attempts at getting the password right. However, if the user fails to enter the correct password on the 10th attempt then it seizes and encrypts the contents in the drive forever. Thomas has already used eight of his 10 attempts formulating his most utilized passwords, but with zero success.

A dejected Thomas says,

I would just lay in bed and think about it. Then I would go to the computer with some new strategy, and it wouldn’t work, and I would be desperate again.

The rise in the number of cases though has prompted a new booming business solution altogether, that of Bitcoin Wallet Recovery Services. But will they really be able to duplicate the key to these treasure chests? Only time will tell.

Related News:

How to Safeguard Your Cryptocurrency Wallet from Digital Exploits

The Largest Darknet Forum “Joker’s Stash” is Shutting Down

Patchwork BADNEWS, APT31 threat group

Joker’s Stash, an infamous dark web marketplace for trading stolen card data, has surprisingly announced that it is shutting down its operations by February 15, 2021. The site’s operators announced the closure via messages and advertisements posted on various hacking forums where the attackers usually advertised.

Pressure from Authorities

While the operators of Joker’s Stash did not disclose the exact reason behind the closure of the site, it’s suspected that the administrators of the platform have feared the intrusions by federal authorities. Recently, a coordinated police operation from the FBI and Interpol seized multiple servers that belonged to Joker’s Stash and temporarily disrupted the site’s operations. The agencies also seized four Joker’s Stash domains, which include:

  • jstash.bazar
  • jstash.lib
  • jstash.emc
  • jstash.coin

Joker’s Stash Says…

Image Courtesy: Cybersecuitynews.com

Joker’s Stash – A Hacker’s Paradise

Active since 2014, the Joker’s Stash carding platform is behind numerous data breaches and traded/exposed millions of users’ financial data on the dark web. The operators have illegally obtained hundreds of millions of dollars with the stolen information.

There were multiple security incidents where cybercriminals traded stolen cards’ data on Joker’s Stash. Recently, threat intelligence firm Gemini Advisory revealed that hackers kept payment card details of Wawa’s customers on Joker’s Stash. Wawa confirmed that hackers tried to sell customers’ card information that was breached in the security incident that occurred on December 10, 2019. The data belonged to 30 million Americans and over one million foreigners from more than 100 different countries.