Home Blog Page 230

APT Group Targets Middle East Organizations with “Milum” Trojan

Android Trojan, Trojan, ReverseRat, Numando Banking Trojan

A threat intelligence group from Kaspersky discovered a hacking campaign, distributing a malicious Trojan tracked as Milum, which is targeting industrial organizations in the Middle East. The research team described the hacking activity as APT (advanced persistent threat), which is operating under the name “WildPressure.” According to Kaspersky, signs of past infections from Milum Trojan were found in May and August 2019.

Once infected, the Milum Trojan gains remote control of the victim’s devices and performs various malicious activities like:

  • Download and execute commands from its operator
  • Collect various information from the attacked machine and send it over to the command and control server
  • Upgrade itself to a newer version

In APT attacks, the attacker gains access to the victim’s device to steal information or disrupt its operations. Generally, APT attacks are deployed by hackers who have access to huge financial and professional resources.

Denis Legezo, Kaspersky’s Senior Security Researcher, said, “Analysts must pay attention because the consequences of an attack against an industrial target can be devastating. So far, we haven’t seen any clues that would support the idea that the attackers behind WildPressure have intentions beyond gathering information from the targeted networks. However, this campaign is still actively developing, and we’ve already discovered new malicious samples apart from the three originally discovered. At this point, we don’t know what will happen as WildPressure develops, but we will be continuing to monitor its progression.”

Recurring Cyberthreats in Middle East

This is not the first time that an APT group has targeted Middle East organizations. Cybersecurity experts stated that the Middle East countries will see an increase in APT attacks compared to other criminal activities in 2020. According to Simone Vernacchia, Head of Digital and Cybersecurity Resilience at PwC Middle East, the geopolitical tensions resulted in the rise of potential cyberthreats targeting critical national infrastructures.

A recent research stated that from May 2019, a Russian state-sponsored notorious cyber espionage threat group called Pawn Storm (also known as Fancy Bear or APT28) has been scanning servers for reusing previously compromised emails. The compromised email addresses are used to carry out phishing campaigns, targeted mainly at defense firms from the Middle East with an intent of cyber espionage.

Hackers Launch Phishing Attack on World Health Organization

Phishing, phishing attacks

A hacker group targeted the World Health Organization (WHO) via a sophisticated phishing attack, which involved an email hosted on a phishing domain that tried to trick the employees into entering their credentials, Reuters reported.

It’s said that the WHO observed the hacking attempt in mid-March and is suspected to have come  from DarkHotel, a threat group from Southeast Asia that has been active since 2004. The group targets high-net-worth travelers across the world by tracking their hotel bookings via compromised hotel websites and applications. WHO is responsible for international public health and is playing a crucial role in monitoring and mitigating the COVID-19 pandemic.

According to Flavio Aggio, CISO at WHO, the hackers were unidentified. Aggio confirmed that the hackers group activated a malicious site mimicking WHO’s internal email system to steal passwords from the employees. The issue came to light after Alexander Urbelis, a cybersecurity professional and attorney with the New York-based Blackstone Law Group—which tracks suspicious internet domain registration activity—discovered the activity on March 13, 2020 and flagged the threat activity to Reuters.

Several industry experts stated that they aren’t surprised that hackers are targeting health organizations, as criminal activities on medical agencies have soared in recent times. Recently, WHO even published a notification warning individuals that hackers are posing as the agency to steal money and sensitive information from the public. The agency urged users to verify the authenticity of the source before responding.

Medical Devices Vulnerable to Cyberthreats

Due to the severity of the Coronavirus threat, the healthcare sector leaves many connected medical devices vulnerable to potential cyberthreats. According to a similar research from Atlas VPN, 83% of healthcare providers in the U.S. are running on outdated software. Based on cybersecurity firm Palo Alto Networks’ survey of 1.2 million IoT devices used in thousands of healthcare organizations across the U.S., 56% of devices were still running on the Windows 7 operating system, for which Microsoft discontinued support in January 2020. The research also revealed that 27% of medical devices are still running Windows XP or old versions of Linux OS, while nearly 16% of imaging systems are at 51% risk of getting hacked.

Ginp Banking Trojan Lures Android Users Amidst COVID-19 Outbreak

Threat Alert! Attackers Use Malicious Email Accounts to Launch BEC Attacks

The outbreak of the novel Coronavirus (COVID-19) is giving rise to threats related to cybersecurity and data privacy. One such threat, according to Kaspersky researchers, is the Ginp Banking Trojan, which takes advantage of Android users. The infamous Trojan is known to steal the credit card credentials of potential victims.

By Pooja Tikekar, Feature Writer at CISO MAG

The Ginp Clickbait

  • Once the Ginp Banking Trojan is downloaded on the victims’ phone, the attacker sends a special command to the Trojan to open a web page titled “Coronavirus Finder.”
  • The Coronavirus Finder web page displays the number of people infected with the virus near the victim’s location.
  • It then asks them to pay 0.75 Euros to see the location of the virus-infected persons.
  • If the victims agree to pay, the Trojan redirects them to a payment page, where the payment details need to be entered.
  • Once the details are entered, the victims are neither charged, nor do they receive any information about the location of the infected persons. Instead, the credit card details of the victims are accessed.

Kaspersky’s Security Expert, Alexander Eremin, said, “Cybercriminals have, for months, attempted to take advantage of the coronavirus crisis by launching phishing attacks and creating coronavirus-themed malware. This is the first time, though, we’ve seen a banking Trojan attempting to capitalize on the pandemic. It’s alarming, particularly since Ginp is such an effective Trojan. We encourage Android users to be particularly vigilant at this time–pop-ups, unfamiliar web pages, and spontaneous messages about coronavirus should always be viewed skeptically.”

Mitigation Measures Against Ginp

Researchers at Kaspersky suggested precautionary measures to avoid exposure to the banking Trojan, which include:

  • Install or update Android apps only from Google Play.
  • Do not click on suspicious links and never give away sensitive information, such as logins, passwords or credit card information.
  • Do not give the Accessibility permission to apps that request it, other than anti-virus apps.

Not the First Time

The Ginp Trojan, which was first discovered in October 2019 by Kaspersky expert Tatyana Shishkova, had targeted Spanish banks as well as legitimate banking apps per bank. The Trojan exploited the Accessibility Service privilege to send messages and make calls, without the knowledge of the victims.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

 

Don’t Get Phished! [INFOGRAPHIC]

phishing campaign, Smishing attacks

Hackers have now set their sights on the global workforce working from home. Taking advantage of the COVID-19 pandemic, there has been an increase in Phishing scams using COVID-19-themed text messages. Here are some ways to identify a phishing email — so read this before you click on any links in an email.

EC-Council is now offering free phishing protection for home office workers and small businesses. More details here.

Phishing, Infographic

What’s Your Perimeter? Network, Identity, or Endpoint?

Perimeter security

The answer depends on which era did you ask this question. From the 90s to the noughties the answer was “Network” since every critical asset–servers, applications, users and devices–were safely ensconced within your perimeter defense. With the advent of mobility and BYOD in the past decade, endpoints started moving outside the perimeter, and therefore couldn’t avail of the traditional security umbrella offered by network security, thereby becoming the new perimeter by themselves.

By Pankit Desai, Co-founder and CEO, Sequretek

There are two trends in the 2020s that will throw up a new security challenge:

  • First is on account of the all too powerful movement to cloud spearheaded by the new AMIGOS aka Amazon, Microsoft, IBM, Google, Oracle, and SAP, resulting in an astounding CAGR of over 150% in cloud consumption. Whilst there are obvious benefits of moving to the cloud, the onus on security the last mile, in this case, an “Identity” is pretty much left outside the purview of the core services offered by cloud service providers.
  • The second is the diversity of technology privileges and commensurate access rights that end-users in enterprises have access to these days. Traditionally, enterprises used to worry about user privileges linked to applications since the majority of the users and the data that was generated by applications were governed through them. In the recent past, this has moved to include a diverse set of privileges to include shared services, endpoint related elements, and infrastructure and network-related privileges.

In the past, organizations would have looked at traditional identity and access management solutions to address these challenges, but they have mostly flattered to deceive. The complexity of the architecture primarily arising out of a centralized identity profile with tight integration to the target systems, primarily on-premise applications has meant inordinately long and expensive implementation cycles.

The impact of the trends mentioned above and the inability of the traditional approach to address identity-related challenges has exposed an underbelly that needs a complete rethink on this new perimeter–which is “Identity.”

The industry is abuzz with the next set of terms such as Zero trust, User Behavior Analytics, and multi-factor authentication systems, as a way to address the challenges of the “Identity” perimeter. While identifying and authenticating the right user to the right system is absolutely important, there is an area that goes relatively unaddressed, and that is linked to Access Governance. With the heterogeneity of access privileges as well as user types, and add to it the complexity brought together by constant churn in user roles, one really needs to get their arms around what these identities are supposed to do in the first place.

There are a few aspects related to Access Governance for the Identity that needs to be understood well enough to be defended.

  • Stale Access: First, at an organizational level a complete understanding of privileges granted to all user types: employees & contractors. Stale and inappropriate access rights contribute to a large chunk of insider related threats. Ensuring disabling of user access for users who are on extended leave (sabbatical/parental leave/vacation) is also a good practice to limit potential risks with access.
  • Beyond Application Access: Whilst application privileges are important to control there is an equally important underbelly of privileges that needs to be controlled. For example, endpoint control (access to removable devices/USB blocking/admin rights), network (Internet/Wi-Fi/VPN), shared services (folder/file/printers), and cloud services.
  • Privilege harvesting: Oftentimes, access rights end up being equated to the power one enjoys within the company, resulting in an uncontrolled access footprint at the highest echelons of the company. These are the same folks who are most likely targets for social engineering attacks. Understanding usage patterns and harvesting of access rights based on usage is one way to limit potential risks that could emanate, should the credentials be compromised.
  • Financial Impact: Most applications (on-premise/cloud) have user-based licenses. Privilege harvesting ensures that you end up paying not only for what you use but more importantly for what you need.

Access governance is a reasonably well-understood concept in regulated industries. Periodic access compliance audits carried out by regulators at least ensures that any irregularity linked to role vs. access rights gets trued-up over time–though in most cases this ends-up being done manually.

Industries that don’t have any compliance-related requirements; Access Governance becomes a nice capability to have. This is a thinking that needs to change if one just looks at the security risk that one is exposed to.  If you are not convinced just look at the recent reports:

  • Some Deutsche Bank Employees Kept Email Access After Being Fired (Bloomberg, 2019).
  • An average of 22 percent of a company’s folders are accessible to every employee (Varonis, 2019).
  • 71% of organizations have over 1,000 inactive users, and that means an additional 29% could have nearly that many (Lepide, 2020).

It is time now, for enterprises regulated and otherwise to move beyond paying lip service and seriously look at the potential risks that an ungoverned identity can pose to the organization.

About the author

Pankit Desai is Co-founder & CEO of Sequretek, a Mumbai based Pankit Desai is Co-founder & CEO of Sequretekcybersecurity company. Sequretek is focused on the Cybersecurity space and was launched in 2013 with an aim to provide enterprise clients with an end-to-end cybersecurity platform. Pankit, a veteran in the IT industry, brings 20+ years of hardcore technology and leadership experience from the information technology industry to lead Sequretek. Prior to Sequretek, he was with Rolta as the President of Business Operations. He has also served in a senior leadership capacity with NTT Data Inc, Intelligroup, Wipro and IBM India. His vast experience has given him the ability to manage and scale global business units and service lines rapidly and efficiently. Pankit has diversified business operations and created an organization that has a multidimensional growth, understanding of business support functions, Financial Planning and Analysis, Recruitment and Operations, Internal IT, Quality, Marketing and Alliance.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

KBR to Strengthen Cybersecurity of USAF Systems

KBR to Strengthen Cybersecurity of USAF Systems

KBR Inc., an American engineering, procurement, and construction company, announced that it was awarded US$26.8 million contract to provide cybersecurity engineering support to the U.S. Air Force Life Cycle Management Center (AFLCMC) Engineering Directorate Cyber Systems Engineering Division. The task order was granted under the Department of Defense Information Analysis Center’s (DoD IAC) multiple-award contract and is a part of the DoD IAC’s Cybersecurity and Information Systems Technical Area Task (CSTAT).

Under the new contract, KBR will develop cybersecurity frameworks for the U.S. Air Force command and control (C2) and rapid cyber acquisition (RCA) customers. It will also provide system and software security, risk management, mission assurance, implementing, training, verifying, and executing cybersecurity strategies across C2 and RCA weapon systems for AFLCMC. Through this task order, which will be performed at Hanscom Air Force Base in Massachusetts, KBR aims to strengthen cybersecurity and resiliency of USAF systems and establish best security practices into the engineering processes of systems.

KBR provides differentiated security solutions and technologies across the asset and program lifecycle within the government sectors. It offers an array of IT and cyber capabilities, including software engineering, big data analytics, computer network management, defense and support, cyber certification and accreditation, cyber policy development, translation and training, vulnerability assessment and evaluation, utility monitoring and control, healthcare technology, and cloud security.

Byron Bright, KBR President, Government Solutions U.S., said, “This award demonstrates the military’s trust in KBR’s ability to provide knowledge-based cybersecurity services. KBR’s growing cybersecurity portfolio underscores our position as a leading provider of cutting-edge cyber and electronic security solutions for the government.”

In a similar contract, BAE Systems, a British multinational defense, security, and aerospace company, awarded a five-year US$188.2 million contract to provide the U.S. Navy’s AEGIS Technical Representative (AEGIS TECHREP) organization with critical large-scale system engineering, cybersecurity solutions, and testing expertise for the AEGIS Weapons and Combat Systems.

Unidentified Database Exposes 800 GB of Americans’ Personal Records

Cloud of Logs dark web market

A report from CyberNews revealed the discovery of an unsecured database comprising of over 800 GB of personal records  of more than 200 million Americans. According to the research team,, the owner of the unprotected database is untraceable. It’s believed that the exposed data may have originated from the U.S. Census Bureau. Based on the data structure, it’s suspected that the database belonged to a data marketing company or a credit company.

Large Volume of Data Exposed

The exposed records contained full names and titles of individuals, email addresses, demographics, dates of birth, phone numbers, credit card ratings, home and mortgaged real estate addresses, detailed mortgage records and tax records, and detailed data profiles about people’s personal interests. In addition to this, the exposed data also contained two separate folders containing emergency call logs of the U.S. fire department and a list of 74 bike share stations.

Potential Threats from Data Leaks

It’s unclear how long the data was exposed online and if any malicious actors have accessed it. CyberNews reported that “On March 3, 2020, the entirety of the data present on the database was wiped by an unidentified party.” However, attackers might take advantage of the sensitive information and could launch targeted phishing attacks, engage in account takeover fraud, and even sell the stolen data on the dark web.

“The database is located in the U.S. and hosted on a Google Cloud server that has been exposed for an unknown period. When we last accessed the database before the wipe, it contained close to 800 gigabytes of data, including the hundreds of millions of records of highly sensitive personal user data that we outlined above. The database itself is still online and accessible but no longer contains any records,” CyberNews added.

 Fate of the Exposed Data

The research team stated that they were unable to track the owner of the leaky database and opined that the unidentified party might be an ethical hacker who simply deleted the data to prevent cybercriminals from taking advantage of it. The team said, “After having spent several weeks looking for the owners of this unprotected database, we did not manage to discover who it belonged to before the unidentified party erased all the records and left a link to a website where a dancing pirate urges visitors to fix their security.”

The team was likely referring to an animated avatar of a “dancing pirate.”

Russian Hackers Attempting Cyber Espionage Against Middle East Defense Firms

Cyber crime, cyber espionage

As per Trend Micro’s research, since May 2019, a Russian state-sponsored notorious cyber espionage threat group called Pawn Storm (also known as Fancy Bear or APT28) has been scanning servers for reusing previously compromised emails. The compromised email addresses are used to carry out phishing campaigns, targeted mainly at defense firms from the Middle East with an intent of cyber espionage.

Although defense companies in the Middle East have been the primary targets, its operators have equally targeted other verticals including transportation, utilities, and government sectors of various countries like the U.S., Ukraine and Iran. The researchers said that APT28 has been scanning email and Microsoft Exchange Autodiscover servers for vulnerabilities, which could be brute forced and used for data exfiltration and phishing attacks. The operators are using the OpenVPN configuration of commercial VPN providers to hide their trails.

A Brief History of APT28

The threat group’s initial activities can be traced back to 2004. APT28 has been widely known to carry out cyber espionage campaigns against high-profile entities ranging from economic and political institutions, to media and government organizations. Since its inception, it has targeted the military, embassies, and defense contractors from the U.S. and its allies, including world bodies such as North Atlantic Treaty Organization (NATO).

APT28’s Attack Vectors

As per primary research carried out earlier, APT28 threat group primarily uses three attack vectors, they are:

  • Phishing Emails: The operators use a malicious spear phishing email to drop a multistage malware that fetches the victim’s system information. These campaigns are usually run keeping the geopolitical issues or upcoming events and conferences in mind to potentially increase the hit ratio.
  • Phishing Website: Additionally, the threat actors have also created several phishing websites and fake Outlook Web Access (OWA) pages using typo-squatted URLs. Entering user credentials on such malicious websites or webpages leads to credential phishing.
  • Malicious iframes: This third vector was explicitly observed being injected into Polish Government websites. For selective targets, the malicious iframe exploits led to Sednit installations as well.

Horangi Raises US$20 Million in Funding to Strengthen Cybersecurity in Southeast Asia

Horangi Raises US$20 Million in Funding to Strengthen Cybersecurity in Southeast Asia

Singapore-based cybersecurity firm Horangi raised US$20 million in a Series B funding round led by Southeast Asian private equity firm Provident Growth, along with other investors including Singapore’s Monk’s Hill Ventures, Australian venture capital firm Right Click Capital, and Southeast Asia’s venture debt fund Genesis Alternative Ventures.

Horangi stated that it will use the new proceeds to expand its business reach in Southeast Asia and strengthen its cloud security product—Warden—in the region. Warden protects organizations using public cloud infrastructure from critical security threats and compliance violations in the cloud. Horangi has over 50 clients across various sectors such as government, technology, financial services, and retail. The company builds security products that enable the rapid delivery of incident response and threat detection for its customers.

Commenting on the new investment, CEO and Co-Founder Paul Hadjy of Horangi, said, “Southeast Asia is one of the fastest-growing economies and digitizing rapidly, but due to the shortage of security expertise in the region, organizations are increasingly turning to security experts like Horangi. This is especially prevalent in Indonesia, where we have been focused on since 2016. Having a strong team, local insights and technology capabilities allow us to partner with strategic investors to help propel our next growth stage.”

Most cybersecurity startups based-out in Singapore and Southeast Asia are working on enhancing the cybersecurity standards in the region. Several industry experts highlighted the urgent need for stronger safeguards against cyberattacks. Earlier, the Singapore government established cybersecurity standards with the Association of Southeast Asian Nations (ASEAN) to strengthen the protection of critical information infrastructure in the region.

In a similar development, the governments of Singapore and the U.S. joined hands to strengthen their collaboration in the infrastructure sector, digital economy, and cybersecurity. Both countries renewed their Collaboration Platform Memorandum of Understanding (MOU) and signed a Declaration of Intent (DOI) to work together on a Singapore-U.S. Cybersecurity Technical Assistance Program for ASEAN.

How Small Businesses Can Protect Themselves from Cyberattacks

SMEs

When most people think of cyberattacks, major data breaches at humongous companies like Equifax and Yahoo!, typically come to mind. This is perfectly understandable, as these are the attacks that impact the most people and always make headlines. But cybercriminals don’t limit their attacks to large companies–they also target countless small businesses every year. And in many cases, these attacks destroy businesses and livelihoods.

By Zack Schuler, Founder and CEO of NINJIO

There’s no reason to put it delicately: The state of cybersecurity in the world of small and medium-sized businesses (SMBs) is nothing short of alarming. Not only are SMBs relentlessly targeted by hackers, but they’re also woefully unprepared to defend themselves and unequipped to handle the aftermath. This is a status quo that has to change immediately–SMBs are the biggest engine of the U.S. economy and they’re at risk like never before.

The Scope of the Problem

Every year, cyberattacks cost small businesses an average of almost US$80,000, and losses can range up to US$1 million (according to a report by the Better Business Bureau). Meanwhile, a 2018 study by the Ponemon Institute found that more than two-thirds of SMBs reported that they had been targeted by a cyberattack within the preceding year. Substantial majorities of SMBs also agree that cyberattacks are becoming more targeted, severe, and sophisticated, but despite these facts, almost half of respondents say they have no understanding of how to protect against cyberattacks.


Key findings from the report

  • Every year cyberattacks cost small businesses an average of almost US$80,000, and losses can range up to US$1 million.
  • A survey reports 88 percent of small business owners felt their business was vulnerable to a cyberattack.
  • Almost two-thirds of small businesses fail to act following a cybersecurity incident.
  • 56 percent of SMBs say, defending mobile devices from cyberattacks is extremely challenging.
  • The top three attack vectors cited by SMBs are mobile devices, laptops, and cloud systems.
  • Just 16 percent of SMBs are “very confident in their cybersecurity readiness.”
  • 60 percent of SMBs lack a “cyberattack prevention plan.”

A recent survey by the U.S. Small Business Administration found that 88 percent of small business owners felt their business was vulnerable to a cyberattack. However, due to resource constraints, a lack of technical expertise, and the rapid pace of change in the cybersecurity world, they often feel helpless or ill-prepared to defend themselves against the vast range of cyberthreats they face.

In fact, a survey of more than 4,100 SMB cybersecurity professionals recently conducted by Forrester, found that almost two-thirds of small businesses fail to act following a cybersecurity incident. Even when the threat is right at their doorstep, many SMBs don’t know what to do.

The World is Changing for SMBs

There are many factors that contribute to the challenging cybersecurity situation for SMBs. First, digital operations are no longer optional for any company–even if your market is small and local, consumers are increasingly demanding the ability to do all their business online.

SMBs are changing the way they operate in the digital era. For example, a 2018 Cisco survey of SMBs found that the percentage of their networks that are on the cloud increased from 55 percent to 70 percent between 2014 and 2017. While almost 70 percent of SMBs say they’re making this transition for security reasons, an increased reliance on cloud-based services can also open up new vulnerabilities.

Meanwhile, other aspects of the digital transition have proved difficult for SMBs, 56 percent of which say, defending mobile devices from cyberattacks is extremely challenging. Ponemon reports that the top three cyberattack vectors cited by SMBs are mobile devices, laptops, and cloud systems.

The Ponemon report also discovered that issues such as a lack of money, out-of-date cybersecurity technologies, and insufficient personnel are all major obstacles cited by SMBs. But the main threat cited in the report is employee negligence, as phishing/social engineering attacks were reported more than any other, while negligent employees or contractors were cited as the top root cause of the data breaches.

How SMBs can Protect Themselves

According to the Forrester survey cited above, just 16 percent of SMBs are very confident in their cybersecurity readiness. Despite the fact that SMBs are increasingly concerned about cybersecurity, Forrester also found that almost half of them don’t have a clearly defined strategy for protecting themselves. This is a common theme in surveys of SMBs. A 2019 Keeper survey found that 60 percent of respondents lack a cyberattack prevention plan.

SMBs have to start taking cyberthreats more seriously, and this starts with education–for business leaders as well as employees. Many SMBs have convinced themselves that they’re incapable of protecting themselves from cyberthreats, but this couldn’t be further from the truth. Not only are there powerful security tools at their disposal–such as data-at-rest encryption and multi-factor authentication–but they’re also capable of turning one of their biggest vulnerabilities into a strength.

Human error is by far and away the biggest cause of cybersecurity breaches. While this is disconcerting, it’s also empowering–when SMBs make cybersecurity training a top priority, they can drastically reduce their risk without spending tens of thousands of dollars on cutting-edge digital solutions. This isn’t to say technology isn’t an important element of cybersecurity, but it’s always worth remembering that the most advanced piece of hardware on the planet is the human brain.

About the Author

Jack Schuler, founder and CEO of NINJIOZack Schuler is the founder and CEO of NINJIO, a cybersecurity awareness company that empowers individuals and organizations– from Fortune 500 companies to small businesses – to become defenders against cyberthreats. Prior to launching NINJIO, Zack was the founder and CEO of the I.T. services company Cal Net Technology Group. In addition to his entrepreneurial pursuits, Zack is a member of the Forbes Technology Council and he’s on the board of governors for Opportunity International, an organization that provides microfinance loans, savings, insurance, and training to more than 14.3 million people who are working their way out of poverty in the developing world.

Disclaimer: CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.