Home Blog Page 258

Cisco Patches 12 DCNM Vulnerabilities

Cisco Vulnerabilities

On January 2, Cisco published a series of advisories for Cisco Data Center Network Manager (DCNM), a platform for managing Cisco’s data center deployments equipped with Cisco’s NX-OS. Cisco patched a total of 12 vulnerabilities that included a trio of critical authentication bypass flaws. The Cisco DCNM software versions earlier than 11.3 (1) contained these vulnerabilities.

Out of the three, two authentication bypass vulnerabilities CVE-2019-15975 and CVE-2019-15976 were found in the REST API and SOAP API endpoints of the Cisco DCNM. The cause was found to be a static encryption key shared between installations. A remote, unauthenticated attacker could gain administrative privileges through either the REST API or SOAP API by sending a special request that included a valid session token generated using the static encryption key.

The third authentication bypass vulnerability, CVE-2019-15977, was found in the web-based management interface for Cisco DCNM due to the use of static credentials. A remote, unauthenticated attacker could use these static credentials to extract sensitive information from the vulnerable device, enabling them to perform additional attacks.

Utilizing these authentication bypass vulnerabilities, attackers could leverage the remaining flaws patched by Cisco. It includes command injection vulnerabilities (CVE-2019-15978, CVE-2019-15979), SQL injection vulnerabilities (CVE-2019-15984, CVE-2019-15985), path traversal vulnerabilities (CVE-2019-15980, CVE-15981, CVE-2019-15982) and an XML external entity vulnerability (CVE-2019-15983).

Eleven of the 12 vulnerabilities were reported by Steven Seeley of Source Incite. The vulnerabilities discovered come on the back of four other flaws reported back in June 2019 by security researcher Pedro Ribeiro, including CVE-2019-1619, an authentication bypass flaw in the DCNM’s web-based management interface. Additionally, Cisco patched CVE-2019-15999, a vulnerability in the DCNM’s JBoss Enterprise Application Platform (EAP). Misconfiguration of authentication settings on the EAP led to this flaw.

Similarly, in October 2019, Cisco had released patches for critical security vulnerabilities that existed in its Aironet Access Point Software. Security pros at Cisco stated that the vulnerabilities could lead bad actors to remote code execution.

Up on exploit, the vulnerabilities, named CVE-2019-15260, CVE-2019-15261, and CVE-2019-15264, could allow an attacker to gain access to view sensitive information, meddle with wireless network configurations, and cause a denial of service. However, Cisco was quick to release fixes for all the three high-severity flaws targeting its Access Point Software.

Effective Consumption of Cyber Intelligence Program

Threat Intelligence

The accelerated development in the field of intelligence-driven cybersecurity (cyber intelligence) shows great promise as it helps predict how cybercriminals might target an organization. There is a need to not look at it as just another tool for patching technical vulnerabilities in the system and its associated networks. Its real strength lies in helping organizations define their whole approach to cybersecurity, integrating business directions, imperatives, governance, risk, monitoring, defenses, and responses to attacks.

By Kumar Ritesh, Chairman and CEO, CYFIRMA 

In the wake of the recent series of cyber-attacks that hit major companies and crippled governments across the globe, the C-suite is now wanting to know more. How does one limit the damage when a breach wreaks havoc on their systems? How does one bolster their defences against a similar attack happening in the future? How do you set up an incidence response team? What’s the next battlefront – and how do you defend the organization against it?

There are infinite questions. But the idea of a more proactive and predictive approach holds a key message:  malicious software is becoming ever-more sophisticated in avoiding detection, and new methods of attack come to the fore. This year, for instance, saw ransomware make headlines with several high-profile attacks that hit organizations below the belt, including WannaCry, Petya, and Bad Rabbit outbreaks. When researchers got together and tried to analyse these attacks, they found patterns in their origination and the methodology for spreading them. Patterns in the business domains, the regions where they were carried out, the manner in which they were carried out and so on. But researchers were more surprised with the fact that these threats are still spreading.

Thus, we now dig into the heads of the C-suite and hackers alike, to know more about their approach towards cybersecurity and cybercrime.

Organization’s Approach vs Hackers’ Approach

The Traditional approach used is to install new security appliances, software and hardware; create firewalls and layered defences, thinking it will provide better protection. But this has clearly not worked. Organizations are always looking inwards without understanding what they’re up against–who are their adversaries, their motivation, their state of readiness, the tools, techniques and methods.

Whereas if you look at the hackers, they are sharing hacked information, vulnerability/exploits and attack methods, with each other more efficiently than ever before.

On one side we do not understand the external risk profiles properly and neither share threat information, whereas hackers are collaborating.

The ancient warfare principle of knowing your enemy relies on intelligence about the adversary’s motives, access to resources, strengths, and weaknesses to secure victory. But sadly, this has been adapted by the hackers and not the organizations. Intelligence agencies apply the concept of Tools, Tactics, Techniques, and Procedures, or TTTPs, to map out how individual hackers orchestrate and conduct attacks. But is this enough?

Current Issues with Cyber Threat Visibility and Intelligence Programs

  • Cyber intelligence companies are primarily focused on operational intelligence, while equally important strategic and management intelligence is often overlooked. This translates to incomplete intelligence and hence, a lack of preparedness against upcoming attacks.
  • Failure to get quicker insights into which cyber-attacks can be carried out, who are the suspects, what were they looking for. In short, it is a failure to understand the WHO, WHY, WHAT, WHEN and HOW of cyber-attacks.
  • A majority of the organizations still have a ‘reactive’ approach to cybersecurity events. They fail to employ cyber threat intelligence and insights beforehand. Having proactive cyber posture management helps in identifying threats at the planning stage of cyber-attacks. But organizations miss this trick.
  • Threat hunting often starts with fact-finding and using Indicators of Compromise (IOCs), whereas national intelligence agencies always start with an Indicator that could be as simple as a conversation or geopolitical issue driving the cyber threat. This hard-coded approach needs to change and evolve.
  • Consumption of intelligence is limited to just the security controls. If you give a serious thought, intelligence can actually be applied to all other verticals of cyber posture management, including managing risk register, compliance management, governance, investment, and resource management.
  • A distinct lack of deeper insights into situational awareness, news, cyber event, incidents, vulnerabilities, technology or regulatory shift.
  • It is being limited only to technology i.e. security controls and not on people and processes.
  • The main focus is only on operational/tactical intelligence; everybody is talking about Indicators of Attack (IOAs) and Indicators of Compromise (IOCs).
  • We have multiple data feeds giving us the same information rather than focussing on the wider spectrum.
  • Missing contextual information in threat feed.
  • Frequency of intelligence is not aligned with the speed of hackers.
  • No emphasis is been given on mapping of attack surface and scenarios with intelligence capability.
  • Lack of domain expertise.

Cyber intelligence insights form the basis of any cybersecurity strategy. A cybersecurity strategy and goal can be defined only when an organization has the correct and precise information of the looming cyber threats. Knowing the issues helps in applying intelligence more effectively and efficiently on the people, process, and technology, and your organization possesses, and helps you prepare for possible cyber-attacks. Defining a strategy requires you to ask the right questions.

The 4 Ws and H of a Cyber Intelligence Program

It is important to understand that an effective cyber threat intelligence program should provide answers to your questions of WHO, WHY, WHAT, WHEN, and HOW. If your cyber threat visibility and intelligence program are not answering the above questionnaire, then you need to re-look and review your overall program.

WHOWho are the individuals, hackers, groups interested in you? Their background, past acts.

WHYWhy are they interested in you? What is their motivation (financial gains, reputation damage, productivity loss) behind attacking you?

WHATWhat do they want from you? Personally identifiable information (PII), financial information, sensitive data including patents / Intellectual property/credentials.

WHENWhen can they potentially target you? Based on a hacker’s readiness or an organization’s readiness?

HOWHow can they target you? What are the potential tools, techniques, and the method they can use to target you?

Once these questions are answered, you gain insights into your organization as well as the hacker’s mindset. For better understanding and knowledge of different teams of your organization, cyber intelligence is further divided into three sections.

The 3 Layers of Cyber Intelligence

A successful cyber threat visibility and intelligence program, has three layers of intelligence: Strategic, Management and Tactical intelligence.

Strategic and Management intelligence should at least answer WHO, WHY, WHAT and WHEN, whereas, Tactical intelligence should tell us HOW.

Strategic Intelligence: It should answer the questions: “WHO is interested?” and “WHY?”. Strategic Intelligence should provide insights to cyber risks by attributing threat actors, their background, motives, tools and techniques. It should allow you to apply cyber intelligence to strategy, governance and policies.

Management Intelligence: The questions: “WHAT is exciting the hackers?” and “WHEN an organization can be targeted?” should be answered here. It should allow integration of insights on threat actor campaigns, attack mechanisms and tools into internal processes like incident management process, change, configuration, and release management process.

Operational/Tactical Intelligence: It answers the question: “HOW will your organization respond to a cyber-attack?” It should enable SOCs to proactively respond to cyber threats, support day-to-day detection and response to improve the enterprise’s cyber posture by using malicious IP, malware signatures and mutex, phishing domains, command, and control centers.

Key Elements

The three key elements to look for in an effective Cyber Threat Visibility and Intelligence Program are:

Predictability: Early warning about potential cyber risk.

Applicability: Can it be applied at all three levels; Strategic, Management and Tactical.

Accuracy: How relevant and actionable intelligence program is to the current target.

Conclusion

Cyber threat visibility and intelligence are about to grab center stage in cyber posture management. With massive incline towards e-commerce and online trade management, this is the ideal time for organizations to incorporate proper cyber threat visibility and intelligence program. Having a secure plan helps in early threat detection and containment, and if there is a tool or a platform in the cybersecurity space that provides it, then that can be deemed equivalent to, “Finding a Pearl in an Oyster”. For this, your search need not go too far — CYFIRMA is your Oyster and the proprietary award-winning cloud-based Cyber Intelligence Analytics Platform (CAP) v2.0 is the pearl you are searching for. CYFIRMA is committed to educating organizations to employ the ‘Outside-In’ approach to cybersecurity.

On an ongoing basis, and to better prepare and protect against imminent cyber-attacks, organizations need to look at the application of threat visibility and intelligence to their strategies, governance, process, procedure, controls, and people. Additionally, organizations must realize that the onus to protect their data, infrastructure, and reputation ultimately rests with them. Information security hinges massively on secured systems, constantly revisited data management practices, and an inclusive approach involving employees, third-parties, and other entities in the organization’s extended supply chains. While threats will inevitably evolve, their intended targets can always stay a step ahead with predictive threat visibility and intelligence.

Disclaimer: The article has been edited in accordance with the guidelines of CISO MAG. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

Hackers Prefer iPhones and Instagram Accounts: Study

apple vulnerabilities

A recent study from a U.K.-based firm Case24.com revealed that hackers are more likely to target Instagram accounts and Apple iPhones than other devices. The researchers stated that they’ve used Google’s search data of the U.K. and the U.S. regions for the study.

According to search results in the U.K., around 10,040 users were trying to find information on how to hack iPhones. Meanwhile, other mobile brands including, Samsung, Huawei, LG, Nokia, and Sony stood next in the targeted list.

Whereas the U.S. search data revealed that users searched for the phrase “how to hack iPhone” 48,010 times.

By using the same search results, researchers stated that U.K. users are interested in how to hack Instagram accounts, with over 12,310 search results, while Snapchat stood in the second position (7,380 searches) and WhatsApp (7,100 searches) in third position. In the U.S., around 66,960 Americans searched for “how to hack Instagram.”

The study might not have used the best approach, but the results are convincing. Both, Apple and Instagram reported severe security breaches last year.

In 2019, Instagram revealed that an unprotected server containing personal information of millions of Instagram influencers, celebrities, and brand accounts exposed 49 million records online.

According to security researcher Anurag Sen, who discovered the leak, the exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number.

Commenting on the security breach Facebook said, “We’re looking into the issue to understand if the data described–including email and phone numbers–was from Instagram or from other sources. We’re also inquiring with Chtrbox to understand where this data came from, and how it became publicly available.”

Development of Local Security Products Increased in Vietnam

Vietnam

The Ministry of Information and Communications (MIC) of Vietnam stated that the number of locally made cybersecurity products increased in 2019.

According to MIC, Vietnam developed 52 cybersecurity products domestically in 2019, which was two times compared to the number in 2018, and three times that in 2017. MIC also stated that it approved new licenses to 38 security firms, which is an increase of 82.6 percent from 2017.

“Vietnamese firms are able to master the technology and could meet more than 60 percent of local market demand,” said Nguyen Huy Dung, director of MIC’s Department of Information Security.

Recently, MIC created a set of policies and technical standards to develop locally made security products and ensure cybersecurity in Vietnam. The domestic security products are intended to serve smart cities, e-government systems, and critical national information systems in the country.

“Developing Vietnam’s ecosystem and mastering technology are building a shield to protect national cyberspace. Vietnam cannot rely on foreign products to protect its own cybersecurity,” a spokesperson of the MIC said in a media statement.

Last year, the MIC revealed that around 4,770 cyber-attacks were reported in the country in the first quarter of 2019. According to the Vietnam Computer Emergency Response Center (VNCERT), this number is more than half the figure for the whole of 2018, which was 8,319 cyber-attacks. The center also stated that most of the attacks were reported against e-commerce, financial, and banking systems.

The most common infringements among the attacks were violations of information security policies (40 percent) and unauthorized information collection (39 percent). And, the other data violations included denial of service (8 percent), privilege escalation attacks (7 percent), and spread and attack of malicious codes (6 percent).

The Vietnam lawmakers also approved a new cybersecurity law that controls the Internet content and global tech companies operating in the country. The new law prohibits internet users in Vietnam from spreading anti-government information and posting false information that could cause damage to the country. It also prevents the circulation of content that’s fake, slandering, or inciting violence.

Shitcoin Wallet: A Crypto-Wallet or a Crypto-Stealer?

Liquid Exchange Hack

Recently launched Google Chrome extension – Shitcoin Wallet, is not a crypto wallet but a well disguised crypto stealer informed Harry Denley, Director of Security at the MyCrypto platform. According to Henry, this crypto wallet is injecting a JavaScript (JS) code on the victim’s web pages that intends to steal passwords and private keys from cryptocurrency wallets.

What is Shitcoin Wallet?

As described in the introductory blogpost and its official website, Shitcoin Wallet is an Ethereum wallet that lets user connect to the Ethereum blockchain. It not only provides users the means for managing, transferring and receiving their Ethers (cryptocurrency) but also allows them to interact with thousands of ERC20 tokens that thrive on the Ethereum blockchain.

Why is it threatening?

Denley says the extension is threatening in two ways. Firstly, any Ethereum (ETH) coins and ERC0-based tokens managed within the extension are at risk since the extension sends the private keys of all wallets created or managed through its interface to a third-party website, erc20wallet.tk Secondly, this extension injects a malicious JS code when users navigate to certain popular cryptocurrency management platforms. The JS steals login credentials and private keys and sends the data to the same erc20wallet.tk website.

How does it happen?

As per ZDNet’s Shitcoin behavior analysis, the process of injecting the malicious code is as follows:

  • Users install the Chrome extension
  • Chrome extension requests permission to inject JavaScript code on 77 websites (listed here)
  • When users navigate to any of these 77 websites, the extension loads and injects an additional JS file from: https://erc20wallet[.]tk/js/content_.js
  • This JS file contains obfuscated code
  • The code activates on five websites: com, Idex.Market, Binance.org, NeoTracker.io, and Switcheo.exchange
  • Once activated, the malicious JS code records the user’s login credentials, searches for private keys stored inside the dashboards of the five services, and, finally, sends the data to tk

What seems to be alarming though, is the fact that virus scanning engines have not been able to detect this malicious code and shows both the 32-bit and 64-bit installer files on Shitcoin wallet’s official website as clean and legit.

Cryptocurrency and its associated exchanges have been constantly under the attack from hackers in recent years. One such example is BITpoint, a Japan-based cryptocurrency exchange. It discovered an unauthorized withdrawal of $32 million from its hot wallet. The incident came to light when BITpoint tried to make a payment using the cryptocurrency Ripple and got an error message.

BITpoint held five cryptocurrencies in its hot wallet–Bitcoin, Bitcoin Cash, Ethereum, Litecoin, and Ripple. However, the company clarified that its cold wallet and cash holdings were not affected in the incident. BITpoint had halted all the payments In and Out of the exchange temporarily, “to prevent any harm to customer assets.”

Attackers Compromised School Management Platform Blue Bear

U.S. Schools Suffer Over 1,300 Data Breaches Since 2005

Active Network, a provider of web-based school accounting software for K-12 schools and districts, recently disclosed a critical security breach.

According to official notice, unknown intruders gained access to Active Network’s Blue Bear platform, a software that facilitates administration and management of school accounting, student fees, and online stores on behalf of schools and other educational institutions.

Active Network stated that the personal information of students or parents who accessed the school’s Blue Bear software between October 1, 2019, and November 13, 2019, might have affected in the incident.

It’s believed that hackers might have accessed users’ private data like name, payment card number, expiration date, security code, and Blue Bear account usernames and passwords. However, the company clarified that the incident didn’t affect users’ Social Security numbers, driver license numbers, or similar government ID card numbers.

Active Network is still investigating the issue and started notifying the affected parents and students.

“As soon as we identified the suspicious activity, our counsel engaged a leading cybersecurity firm to investigate the incident and took steps to enhance its monitoring tools and security controls. We are also offering you free identity monitoring services.,” Active Network said in a statement.

Security pros at Active Network opined that the incident appears to be a web skimming attack, where attackers planted malicious code in Active Network’s Blue Bear platform and collected users’ payment details while they were paying fees.

K-12 district schools have been a soft target for cybercriminals. To address the same, two U.S. Senators, Gary Peters (D-Mich.) and Rick Scott (R-Fla.), both members of the Senate’s National Security and Government Affairs Committee recently tabled a new bill: K-12 Cybersecurity Act.

The Act directs the DHS Cybersecurity and Infrastructure Security Agency (CISA) to first study the specific cybersecurity risks associated with K-12 educational institutions. Once the study is done, CISA will then be responsible to develop cybersecurity recommendations and set up online tools to help schools with their cybersecurity requirements.

Austrian Foreign Ministry Faces a “Serious Cyber-Attack”

Austria cybersecurity

The Austrian Foreign Ministry sounded the alarm bells of an ongoing “serious cyber-attack” that started in the late hours of Saturday January 4, 2019. Considering the signatures and the pattern of the attack, experts suggest this cyber-attack could possibly be carried out by a state sponsored threat actor. The attack, which began on Saturday night, was continuing and, “as per experts it could last several days,” a foreign ministry spokesman added.

The cyber-attack took place on the same day when Austria’s Green party backed forming a coalition with the conservatives, the People’s Party, at a congress in Salzburg. The Austrian Foreign Ministry stressed on the fact that it detected the attack quickly and set up the countermeasures immediately.

“Despite all intensive security measures, there is never 100 percent protection against cyber-attacks,” the ministry said. It further added that services such as its information system for travelers remained available and the official website of the ministry was made accessible on Sunday itself.

Last year the EU adopted powers to punish those outside the bloc who launch cyber-attacks that cripple hospitals and banks, sway elections and steal company secrets or funds.

The ministry added, “In the past, other European countries have been the target of similar attacks.” One such example is when the German government’s computer networks were attacked by APT28, a Russia-backed hacker group. The isolated attack was targeted at Germany’s foreign and defense ministries with an intention to steal data. A spokesman for the German Interior Ministry said the situation was brought under control and appropriate measures were taken to investigate the incident and protect the sensitive data within the federal administration.

This is not the first time APT28 has been associated with a cyber-attack on German government. The infamous group was accused of carrying an attack on the German Parliament in 2015. It has also carried out notorious attacks on several entities in the U.S., Eastern Europe, and other parts of the world.

All You Need to Know About India’s First Data Protection Bill

American Cybersecurity Literacy Act

By Rudra Srinivas

Most people in India have never accessed the Internet through a computer. In fact, their encounter with the Internet is only through smartphones. As India’s consumers lap up Internet services, social media and other apps, they gladly submit their personal details to service providers in exchange for free use of their services. And these details are usually stored on servers outside India’s boundaries, which worried the Government of India.

In July 2017, the Government of India formed a committee of experts to study the issues related to data protection in the country. The committee was led by retired Supreme Court Justice BN Srikrishna. After working on it for a year, the committee submitted a draft of the Personal Data Protection (PDP) Bill in July 2018 and requested feedback from the public, Ministers, stakeholders, and other industry experts.

A revised draft of the Bill was submitted in the Lok Sabha, the lower house of parliament, on December 11, 2019, and has been sent to a joint parliamentary committee (JPC) for further deliberations before being taken up for passing. There was widespread anticipation for the passing of the Bill in 2019, however that has now been deferred. The Bill is expected to become a law or an Act in 2020.

What the Bill could achieve

The Personal Data Protection Bill (PDP Bill) is India’s first attempt to domestically legislate the mechanisms for the protection of personal data and aims to set up a Data Protection Authority in the country. The Bill regulates the processing of citizens’ personal data by government, companies incorporated in India, and foreign companies that are dealing with personal data of customers in India. Through the proposed law, the Government of India is rooting for data sovereignty by mandating certain class of data to be stored within Indian borders.

The proposed Bill also allows processing of data by fiduciaries with the consent of the individual. A data fiduciary is an individual or entity that decides the purpose of processing personal data. However, the Bill also permits personal data processing without consent in some cases like, when the government providing benefits to the individual, for legal proceedings, and in medical emergencies.

Kinds of Personal Data, according to the proposal

The proposed Bill forces companies dealing with people’s personal data to reconsider their data management practices. The Bill regulates three categories of data – Personal Data, Sensitive Personal Data, and Critical Personal Data.

The Bill defines Personal Data as any information that’s collected online or offline which can be used to identify a person, like name, address, phone number, location, shopping history, photographs, telephone records, food preferences, movie preferences, online search history, messages, devices users own, and social media activity.

Sensitive Personal Data includes health care data (like private information you share with a doctor or healthcare apps), financial data (banking and payments information), sexual orientation, biometrics (facial images, fingerprints, iris scans), caste or tribe, religious and political beliefs.

“Critical Personal Data” has not yet been defined by the government.

Advantages to Citizens

The proposed Bill gives high priority for individual rights on data protection. As per the Bill, citizens’ personal information can’t be collected, processed, and shared without their consent. Only the necessary data will be collected and can be used for pre-defined purposes only.

The companies are required to be clear and concise on what data is collected, its purpose, how it’s used, and for how long the data will be retained.  The Bill also permits customers to move their data from one provider to another and allows users to know the number of companies with whom the data is shared.

Impact on Private Organizations

Private entities are required to place limits on data collection, processing, and storage of their customers’ data. They’re subjected to report any instances of security incidents to the regulator.

Additional responsibilities are also imposed on companies based on the volume of data they collect from customers. This includes periodic security audits, appointment of a data protection officer, and performing data protection assessments defined by the regulator. Social media platform providers will also be mandated to enable customers to verify their accounts.

Penalties

Tough penalties have been proposed for failing to comply with the data protection requirements. According to the Bill, any organization sharing customers’ data without their consent will entail a fine of INR 15 crores (around US$ 2.1M) or 4 percent of its global turnover. Data breach and delay to address/report the same will result in a fine of INR 5 crores (US$ 0.7M) or 2 percent of global turnover. Individuals representing the companies can also be sentenced to term in prison.

Data Localization Requirements

In terms of data localization, the Bill allows transfer of personal data across borders without any limitations. However, restrictions are placed on “sensitive personal data” which needs to be stored in India. Sensitive personal data can also be processed outside the country if the regulator approves it. For “critical personal data”, the government will notify on its own, which needs to be stored and processed within the country.

Criticism on the Revised Bill

The Bill landed in controversy for being different from what was proposed by the expert group in its first draft in July 2018. The Indian government, through the proposed law, wants to allow law enforcement agencies and authorized third parties to have access to citizen data, to investigate crimes faster. In other words, it will exempt any government agency from legal obligations. This, of course, has led to a resistance, and delayed the passing of the bill. Justice BN Srikrishna, the chief architect of the draft law, also has concerns and said the law can turn India into an ‘Orwellian State’.

Several industry experts have opined that unaccounted access to personal data of customers might lead to data -misuse. “The Bill provides an exempt to any agency of government from the application of Act in the interest of sovereignty and integrity of India, the security of the state, friendly relations with foreign states, public order. The unrestricted government access is like a two-sided coin scenario. On one hand, the privacy bill is a part of the government’s efforts to have more control of data and help it track unlawful activities by using digital footprints. On the other hand, the user’s access may give the government unaccounted access to personal data of customers in the country leading to data -misuse and unauthorized access,” said Jaspreet Singh, cybersecurity leader at EY told CISO MAG.

Several privacy concerns have also been raised by experts over the revised draft Bill. The Bill states that personal and non-personal data may be processed without obtaining consent from the concerned user to help in the delivery of government services.

The changes that were made

Justice B.N. Srikrishna, who led the committee that drafted the 2018 PDP Bill, stated that there is no oversight on government agencies on accessing citizens’ data. Sharing his thoughts on the same, Pavan Duggal, the Advocate Supreme Court specialized in Cyberlaw and the Chairman of the International Commission on Cybersecurity law, said, “The chapter on exemptions under the Data Protection Bill represents a massive dilution of the bill by giving these exemptions to governmental agencies. However, we also need to be mindful of the fact that governments would want certain access to personal data for sovereign and governance reasons. But the way the current exemptions came out is independent. It is the classical piece of legislation which is going two steps forward and six steps backward.”

Impact on International Trade

Data protection discussions often revolve around discussions of transfer of data. In this regard, the proposed Bill has received a lot attention from global tech tycoons as well as Indian firms that work for international companies.

“There’s no denying that this bill, if becomes a law, will have a significant impact on foreign companies as well as trade between India and other nations.” He stressed that the bill takes a U-turn from the stance the Reserve Bank of India (RBI) took in April 2018. The RBI in its notifications stated that all data relating to banking must be physically in India and cannot leave Indian soil and that continues to be the position till today. “However, the proposed Bill is a complete walk down on the RBI stance as it allows sensitive data to be stored outside India,” Pavan Duggal told CISO MAG.

“The bill is a ground-breaking step for the nation towards building the significant base of ‘trusted’ digital India. It will change the way privacy is perceived and practiced by various businesses. Global organizations based in India and/or providing services will be particularly impacted. Considering the data transfer mandates, as most global firms which process personal data of Indians store their data at remote locations will face challenges in-terms of increased compliance costs,” suggested Jaspreet Singh.

Where the Bill Stands Today

The much-awaited Bill, which was expected to be passed by the end of 2019, has been put on hold for now following severe concerns raised about changes in the proposal. The proposed Bill was recently referred to a JPC in consultation with various groups for further analysis. The joint committee, with 20 members from the Lok Sabha or lower house, and 10 from the Rajya Sabha (upper house), will be headed by Meenakshi Lekhi, Member of Parliament. The committee is expected to submit their views before the end of the upcoming budget session.

The PDP Bill lays down provisions for thwarting misuse of personal data in the country. It mandates data processing activities like data protection, storage, and management. On the flipside, the Bill, if passed, could bring major implications for national security, foreign investment, and international trade.

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features. 

Xiaomi Security Camera Bug Shows Other Homes’ Camera Feeds

Internet of Things (IoT) may enhance our connected lifestyle, but it has also created new attack vectors for hackers. Several security pros cautioned earlier that IoT devices have become a primary target for cybercriminals. It seems security issues with the smart home devices become creepier with recent incidents like Google Nest Hub and Xiaomi Mijia smart security vulnerabilities came to fore.

Dio-V, who owns a Google Nest Hub and several other Xiaomi Mijia cameras around his home, claimed that he received images from other random people’s homes when he streamed content from his camera to a Google Nest Hub. The exposed images included stills of infants in a cradle and people sleeping in a smart house.

“When I load the Xiaomi camera in my Google Home hub I get stills from other people’s homes,” Dio-V said.

When Dio-V asked the Google Assistant to display one of their cameras’ feeds. Instead of showing a feed from their cameras, it displayed images from other people’s homes, according to the source.

Not only him but many other Xiaomi camera users stated they’ve faced similar issues, which potentially represents a major security vulnerability. Google temporarily disabled Xiaomi integration for Google Home and the Assistant citing security reasons.

“We’re aware of the issue and are in contact with Xiaomi to work on a fix. In the meantime, we’re disabling Xiaomi integrations on our devices,” Google said in a statement.

This isn’t the first time that smart security cameras posed this kind of issue.

Recently, Amazon-owned home security products company Ring hit by a class-action lawsuit in the U.S. for reports of multiple hacking incidents on its security cameras that left victims traumatized.

According to the lawsuit, Amazon and Ring were being sued for negligence, breach of an implied contract, invasion of privacy, breach of an implied warranty, and unfair enrichment. The lawsuit also claimed that the companies were already aware of the deficiency of their products’ security.

Landry’s Restaurant Chain Disclose Malware Attack

BotenaGo, malware over encrypted connections

Landry’s, an American multi-brand dining, hospitality, entertainment, and gaming corporation, recently disclosed a point-of-sale (POS) malware attack that stole the company’s payment card data from its order-entry system. The security incident affected around 63 Landry’s restaurants and bar brands.

Landry’s stated the malware was active on its networks from March 13, 2019, to October 17, 2019, and for some locations, it was active since January 18, 2019.

In an official notice, the company stated the malware was designed to collect payment card data from cards swiped at its chain of bars and restaurants. However, Landry’s authorities stated that the impact of the malware attack will be low due to security features it implemented after the company experienced its first malware infection in 2016.

Landry’s claimed that they’ve implemented end-to-end encryption to hide customer payment card data. With this, the malware couldn’t access customer card data even it presents in the system. The company also disclosed a list of affected restaurants and beverage outlets, that it owned, which are impacted in the incident.

“The payment cards potentially involved in this incident are the cards mistakenly swiped on the order-entry systems. Landry’s Select Club rewards cards were not involved,” Landry’s clarified.

The company urged its customers, who used their payment cards at their premises last year, to review their payment history for any fraud. Landry’s also stated that it is working with law enforcement and a forensics firm to investigate the incident.

“Although the investigation identified the operation of malware designed to access payment card data from cards used in person on systems at our restaurants and food and beverage outlets, the end-to-end encryption technology on point-of-sale terminals, which makes card data unreadable, was working as designed and prevented the malware from accessing payment card data when cards were used on these encryption devices,” Landry’s said in a statement.

“Besides the encryption devices used to process payment cards, our restaurants and food and beverage outlets also have order-entry systems with a card reader attached for waitstaff to enter kitchen and bar orders and to swipe Landry’s Select Club reward cards. In rare circumstances, it appears waitstaff may have mistakenly swiped payment cards on the order-entry systems,” the statement added.