Home Blog Page 277

5 Cybersecurity Solutions to Steamroll Hackers and Scammers in 2020

anti-hacking

By Joshua Blackborne

Cyberattacks have become a part of the reality of doing business in today’s digital landscape. Almost every company relies on computers, digital tools, and the internet these days, and this leaves us all exposed to cyberthreats.

Hackers and scammers today have easier access to increasingly sophisticated methods that allow them to exploit vulnerable devices and users. Companies whose digital infrastructures fall victim to these attempts are exposed to a variety of attacks such as data breaches, ransomware, and fraud. According to its latest threat report, McAfee Labs saw an average of 504 new threats per minute in Q1 of 2019 alone.

Experts expect attacks to persist and even grow in the coming years. As such, security needs to be part of every company’s business strategy. Fortunately, the cybersecurity community has been putting up a good fight against attacks, developing tools that help mitigate the risks posed by hackers and scammers.

Here are five security solutions that you can use to protect your company from vulnerabilities, attacks, and scams as we all get set for 2020.

Secure Your IoT With FirstPoint’s Virtual Mobile Networks

Companies are now aggressively adopting mobile and Internet-of-Things (IoT) devices. Many of these devices, however, rely on cellular connectivity.

The problem is that cellular networks can be exploited. Hackers can now use fake cell towers, location tracking, SMS phishing, and SSL loopholes to intercept data or even gain access to devices that rely on cellular connectivity. Once they take control of these connections, the hackers can readily eavesdrop on all the data being transmitted over the network and even install malware into connected devices, often without anyone even knowing.

FirstPoint’s Virtual Mobile Networks

Employed by telecoms who are looking to cater to key clients who require a high-fidelity security solution, FirstPoint has created a solution designed to specifically secure cellular connections at the network level. Once integrated, FirstPoint essentially routes all information between a user and the cellular network through a secure virtual network. Using advanced algorithms, all traffic that passes through this secure network is scanned for threats.

Should any malicious traffic or processes be detected, FirstPoint can effectively screen and prevent these from executing.

Get All Hands on Deck With Cymulate’s Attack Drills

Another major challenge for businesses is knowing whether their chosen cybersecurity tools actually work. Typically, testing defenses involves performing penetration tests that probe networks for vulnerabilities. IT teams can also form “read teams” that take on the role of hackers and employ similar attack methods to test their security.

Unfortunately, both approaches require high levels of technical skills to pull off. Contracting third parties to perform these can also be expensive.

Cymulate’s Attack Drills

As an alternative, organizations can use Cymulate’s breach and attack simulation (BAS) platform to test their defenses. Cymulate simulates various attacks across vectors. It can test the effectiveness of endpoint security solutions such as anti-viruses and anti-malware by deploying payloads on target machines. It can also test the security of email, web applications, and servers to ensure that all components comprising a company’s infrastructure are protected.

After testing, the platform generates a comprehensive report and a score to help security teams identify weak and vulnerable areas so that they can commit to corrective actions. Since solutions and threats evolve, Cymulate can automatically test periodically to ensure that everything works as it should.

Reward Social Reengineering with Hoxhunt’s Phishing Drills

The human element continues to be the weak link in cybersecurity defense. An Egress study showed that human error was the main cause of 60 percent of personal data breaches reported between January 1 and June 20 of 2019.

Human fallibility is why hackers continue to perform social engineering attacks as a means to gain access to enterprise systems. Phishing, or the use of fraudulent messages to trick users into giving up information or installing malware into their devices, remains a popular attack method among hackers.

Hoxhunt’s Phishing Drills

Hoxhunt allows enterprises to enhance security by focusing on improving the human element. It provides automated phishing training for all members of the organization in a sustained manner, and while in a real working environment.

Hoxhunt generates ML-powered personalized simulated phishing emails directed to specific users and provides feedback on how well users react to these simulated attacks. Through proper ongoing, in-context training and a gamified experience, teams can distinguish these fraudulent messages and report the emails. That’s why Hoxhunt says its customers quickly find failure rates diving to under 2 percent.

Seamlessly Prevent Payment Fraud with Signifyd’s Authentication Tool

Businesses operating in the e-commerce space are always exposed to the threat of online fraud. Stolen credit card information can be purchased on the cheap from the dark web. Scammers and fraudsters often take advantage of this by using these stolen accounts to purchase goods online.

Unfortunately for e-commerce merchants, card companies generally rule in favor of customers when these fraudulent charges are contested. When disputes and chargebacks happen, businesses have no choice but to refund the transaction and bear the brunt of expenses such as the cost of goods and shipping.

Signifyd’s Authentication Tool

As such, it’s important for businesses to have fraud prevention and protection. Signifyd offers a comprehensive service that combines big data, machine learning, and manual reviews to check the authenticity of transactions.

Integrating with popular shopping carts like Shopify, BigCommerce, and Magento, this platform also improves customer retention by minimizing instances of falsely declined payment attempts. Online shoppers readily abandon merchants that erroneously deny their legitimate transactions, so advanced fraud prevention allows companies to minimize revenue leakage from both losses and churn.

Reveal and Manage SaaS Access Permissions with Torii

The problem of shadow IT, or the use of unauthorized devices and applications, has been a constant concern of IT teams over the years. The phenomenon has become even more alarming thanks to the rise of cloud-based services and software-as-a-service (SaaS) as a distribution method for applications since it allows just about anyone to subscribe to apps and services on a DIY basis.

Shadow IT can create some major problems for organizations. Companies may be spending unnecessarily on redundant apps. But if people use insufficiently secure apps, or if they grant SaaS tools permission to access network resources like contact databases or email messages, new vulnerabilities are released into the infrastructure, without IT even knowing it. As a result, data may get lost, destroyed or intercepted, and data privacy regulations can be unwittingly violated.

Reveal and Manage SaaS Access Permissions with Torii

A leading SaaS management platform, Torii helps minimize the dangers of shadow IT by enhancing visibility and reducing latency. It can automatically identify and track all instances of SaaS use within the network. What’s more, Torii’s database displays the risk levels and access permissions that each SaaS product generally demands. This allows administrators to create an accurate, real-time inventory of all SaaS accounts and terminate subscriptions to insecure and non-compliant apps.

Torii also supports automated alerts, as well as custom onboarding and offboarding features that allow IT teams to manage and delegate access to all SaaS accounts via automated workflows.

Strategy is the Key to the Stack

Hackers and scammers are only bound to increase their malicious ways, especially now that they can so easily monetize the data that they steal from companies. Surely, you wouldn’t want your company to be part of the growing number of organizations that fall victim to cyberattacks. As such, it is crucial for you to have a comprehensive cybersecurity strategy that fits your specific context. Knowing where your company is vulnerable and investing the proper tools to strengthen your defenses will be crucial in preventing attacks.

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

51 Percent Organizations Not Ready to Handle a Cyber-Attack: FireEye

Whistle-Blower Reports to ICO Increase by 34% in the Last Year

Cybersecurity research firm FireEye revealed that nearly 51 percent of organizations don’t believe that they’re capable of handling threats like cyberattacks or data breaches.

In its latest report, FireEye Cyber Trendscape Report 2020, FireEye stated that it surveyed over 800 CISOs and senior-level executives across North America, Europe, and Asia to help organizations scale their cybersecurity standards. The report discloses the present scenario of how CISOs across the world are thinking about the current cybersecurity landscape.

According to the report, only 49 percent of CISOs are confident that their organization could deal with security incidents or data breaches. Also, nearly 29 percent of organizations with cyber-attack response plans stated that they’ve not tested them for a year. However, 76 percent of firms stated that they’re in a plan to increase their cybersecurity budget in 2020.

“The greatest number of U.S. participants (39 percent) indicated budgetary increase plans of 10 percent or more, followed by the UK (30 percent) and Korea (22 percent),” the report stated.

FireEye is a cybersecurity company that protects enterprises from the impact and consequences of cyber-attacks. In its latest security incident findings, the company discovered an undetected hacker group from Iran, that managed to steal travel and mobile data of individuals in the Middle East region.

According to FireEye, the Iranian group dubbed APT39, targeted several people in the Middle East, especially in the Gulf region. It’s believed that the espionage group is allegedly providing information to the Iranian government. The researchers at FireEye stated that they had been tracking APT39 activities since 2014 to protect organizations from cyber incidents.

The researchers said the group uses phishing emails that target specific people and include malicious attachments or links resulting in a POWBAT infection. FireEye also observed that the group uses Persian language words in encrypting data. APT39’s activities are reportedly focused on the telecommunications sector, the travel, and the IT industry, and allegedly represent Iran’s potential global operational reach and how it collects key data.

Proofpoint Acquires Threat Intelligence Firm ObserveIT for US$ 225 million

96% of Cybersecurity Professionals are Happy With Their Roles

Enterprise cybersecurity and compliance company, Proofpoint, recently announced that it has entered into a definitive agreement to acquire ObserveIT in an all-cash deal for US$ 225 million. The California-based company stated that the new acquisition helps the company to bolster its enterprise cybersecurity portfolio and improve its data loss prevention (DLP) capabilities by using ObserveIT’s technology.

Founded by Gabriel Friedlander and Avi Amos in 2007, ObserveIT designs a cyber defense system to prevent insider breaches within an organization. The company moved its control center to Boston after it was acquired by Bain Capital in 2013.

With an integrated suite of cloud-based solutions, Proofpoint helps global companies to prevent targeted threats, safeguard their data, and make their users more resilient against cyberattacks. The acquisition deal integrates Proofpoint’s information classification and intelligence offerings with ObserveIT’s endpoint and data risk analytics solutions. Proofpoint also intends to invest in ObserveIT’s insider threat management solution.

Speaking on the new acquisition, Gary Steele, Chairman, and CEO of Proofpoint said, “Today’s ObserveIT acquisition underscores Proofpoint’s commitment to providing organizations with people-centric cybersecurity and compliance solutions that protect what matters: their people and the data they have access to, in a post-perimeter, cloud-first world.”

“Proofpoint’s leadership in people-centric cybersecurity, broader intelligence, and R&D resources are significant market differentiators and directly complement our ability to quickly detect insider threats and prevent critical information loss,” said Mike McKee, ObserveIT CEO. “We are very excited to join the Proofpoint team and provide customers with even more powerful solutions to mitigate insider threats, decrease incident investigation time, and make sure users don’t intentionally or accidentally send valuable, confidential information externally.”

Recently, Proofpoint acquired Meta Networks, a technology expert in zero-trust network access (ZTNA), in a cash deal of around US$ 111 million and US$ 9 million in common stocks and options. The acquisition helps Proofpoint strengthen its cloud-based architecture and people-centric security platform.

Aimed to integrate Meta Networks’ ZTNA technology with Proofpoint’s cloud access security broker (CASB), the acquisition will offer comprehensive cloud access and advance security platform to customers. The acquisition of Meta Networks will also help Proofpoint in expanding its presence in the Israel region.

Russia Launches “Disconnect from the Internet” Law

France Fines Facebook and Google,Russia fines Google, Meta heavily New York City Law Department Hit by a Cyberattack

It seems that Russia wants to build its own Internet Firewall platform to monitor internet traffic in the country through government servers. The Russian government recently launched its controversial “Disconnect from the Internet” Law.

According to the reports, the new law allows the government the ability to disconnect the country from the global internet.

The law, which was officially approved by President Putin in May this year, requires all local Internet Service Providers (ISPs) to route internet traffic through the servers managed by the country’s telecommunications watchdog Roskomnadzo. The servers act as kill-switches and disconnect Russia from external connections and re-routes internet traffic inside Russia’s own internet space, which the government is referring to as a country-wide intranet named RuNet.

It’s said that the government wanted to disconnect the country’s cyberspace from the rest of the world in the event of a national emergency or foreign cyber threats. The government reportedly expended about 30 billion rubles (US$ 460,000,000) for its execution.

Experts from both political and security sectors opined that Russia’s new law is an attempt to increase censorship and take greater control over information online.

In related news, Facebook stated that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections.

The new steps announced by Facebook include Fighting Foreign Interference, preventing inauthentic behavior, increasing transparency, labeling state-controlled media on their Page and in the Ad Library, preventing the spread of misinformation, and monitoring candidates’ accounts, elected officials through Facebook Protect.

Researchers Discover the First “BlueKeep” Mass Hacking Campaign

Bluekeep Vulnerability

BlueKeep, a critical remote code execution flaw, has been spotted by security researchers for the first time in the wild to launch a mass hacking operation.

The BlueKeep flaw exploitation was predicted by security researcher Kevin Beaumont recently when his multiple EternalPot RDP honeypot systems, a decoy computer system for detecting BlueKeep attacks, got crashed.

In May this year, Microsoft discovered the Bluekeep vulnerability in older versions of Microsoft’s Remote Desktop Protocol (RDP). If exploited, the flaw allows unauthorized access to computers running Windows XP, Windows Vista, Windows 7, Windows Server 2003, and Windows Server 2008.

According to Microsoft, BlueKeep (tracked as CVE-2019-0708) is a wormable vulnerability which is self-spreading and can be weaponized by potential malware to spread from one vulnerable computer to another automatically. It said that in order to exploit the vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.

“A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs, view, change, or delete data, or create new accounts with full user rights,” Microsoft said in a statement.

The BlueKeep flaw has been considered as a serious threat since its discovery. Microsoft, and even government agencies like the National Security Agency (NSA), urged Windows users to apply security patches. It’s said that nearly 1 million systems were found vulnerable even a month after patches were released.

“Although Microsoft has issued a patch, potentially millions of machines are still vulnerable. This is the type of vulnerability that malicious cyber actors frequently exploit using software code that specifically targets the vulnerability. For example, the vulnerability could be exploited to conduct denial of service attacks. It is likely only a matter of time before remote exploitation tools are widely available for this vulnerability. NSA is concerned that malicious cyber actors will use the vulnerability in ransomware and exploit kits containing other known exploits, increasing capabilities against other unpatched systems,” NSA said in a statement.

Phishing is No Longer an Email-Based Threat: Research

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

Security experts said cybercriminals are customizing their hacking methods to trick consumers. According to the cloud security firm Akamai Technologies, attackers are using enterprise-based development and deployment strategies like Phishing as a Service (PaaS) to target global tech companies.

In its report, 2019 State of the Internet / Security Phishing: Baiting the Hook, Akamai revealed that around 42.63 percent of attacks were targeted on large brands like Microsoft, PayPal, DHL, and Dropbox. Akamai opined that hackers expanded phishing attacks to social media and mobile devices, making it no longer an email-based threat.

The report stated that cybercriminals are targeting global companies and their users with sophisticated phishing kit operations.

“This evolving method continues to morph into different techniques, one of which being business email compromise (BEC) attacks,” Akamai said.

According to the report findings, the IT industry is the primary target for attackers with 6,035 domains and 120 kit variations. The second most-targeted industry is the financial services with 3,658 domains and 83 kit variants. Following that, E-Commerce (with 1,979 domains, 19 kit variants) and Media industry (with 650 domains, 19 kit variants). It’s said that Phishing defenses of the companies forcing hackers to change their attack operations.

“Phishing is a long-term problem that we expect will have adversaries continuously going after consumers and businesses alike until personalized awareness training programs and layered defense techniques are put in place,” said Martin McKeay, Editorial Director of the report.

“As the phishing landscape continues to evolve, more techniques such as BEC attacks will develop, threatening a variety of industries across the globe. The style of phishing attacks is not one size fits all; therefore, companies will need to do due diligence to stay ahead of business-minded criminals looking to abuse their trust,” McKeay concluded.

A similar research from email and data security company Mimecast revealed that there is a significant increase in Business Email Compromise (BEC) attacks. In its report, Email Security Risk Assessment (ESRA), Mimecast stated that emails containing viruses and malware attachments are being delivered to users’ inboxes from incumbent email security systems.

The ESRA highlighted that BEC attacks have increased to 269 percent when compared to the same findings in the last quarter’s report. Mimecast stated that they’ve found 28,783,892 spam emails, 28,808 malware attachments, and 28,726 dangerous file types that are delivered to users’ inboxes.

WhatsApp rolls out Biometric Security Lock for Android Devices

WhatsApp Biometric Security

WhatsApp recently announced the launch of biometric authentication through fingerprint sensors on the Android platform, as an additional privacy measure. The Facebook-owned messaging app stated that devices running on Google’s Android operating system will soon be able to secure their WhatsApp accounts through the biometric authentication method.

However, WhatsApp stated that the Android devices should be of a new model, with a fingerprint reader to use the new authentication platform.

Earlier this year, WhatsApp introduced biometric mechanisms for Apple’s Touch ID and Face ID. The security feature works in all iOS 9 and above iPhone devices. “iPhone users can prompt Touch ID or Face ID when you open WhatsApp on your phone. When this is enabled, you’ll have to use Touch ID or Face ID to unlock the app,” WhatsApp said.

“Today we’re introducing similar authentication, allowing you to unlock the app with your fingerprint, on supported Android phones. To enable it, tap Settings > Account > Privacy > Fingerprint lock. Turn on Unlock with fingerprint and confirm your fingerprint,” WhatsApp stated in its announcement.

In related news this week, WhatsApp has sued the Israel-based cyber intelligence company NSO Group for violating the Computer Fraud and Abuse Act. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp installed mobile devices in April and May 2019.

NSO Group is a developer of spyware for mobile devices. The firm is known for the development of Pegasus software that targets mobile phones to gather information and provides authorized governments with technology that helps them combat terror and crime.

In May, WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. It stated that the spyware can exploit the mobile device, its calls, and texts; it activates the phone’s camera, microphone, and it is able to perform other malicious activities. The malicious spyware was developed by the NSO Group, according to Facebook.

Facebook to Pay £500,000 Penalty for Cambridge Analytica Scandal

Facebook Cambridge Analytica Scandal, Facebook data breach

It seems the clash between Facebook and the U.K.’s Information Commissioner’s Office (ICO) over the infamous Cambridge Analytica scandal has come to an end.

Facebook has agreed to pay the £500,000 (around US$ 645,000) penalty imposed by ICO, the UK’s data protection watchdog, for failing to safeguard the users’ data gathered by political data firm Cambridge Analytica.

According to the settlement deal, Facebook has agreed to drop its legal appeal against the penalty. The ICO stated that Facebook can retain some documents that ICO disclosed during the appeal process to use for its own investigation into issues around Cambridge Analytica.

Commenting on the agreement, Harry Kinmonth, Director and Associate General Counsel at Facebook, said, “We are pleased to have reached a settlement with the ICO. As we have said before, we wish we had done more to investigate claims about Cambridge Analytica in 2015. We made major changes to our platform back then, significantly restricting the information which app developers could access. Protecting people’s information and privacy is a top priority for Facebook, and we are continuing to build new controls to help people protect and manage their information.”

“The ICO has stated that it has not discovered evidence that the data of Facebook users in the EU was transferred to Cambridge Analytica by Dr. Kogan. However, we look forward to continuing to cooperate with the ICO’s wider and ongoing investigation into the use of data analytics for political purposes,” Kinmonth added.

Recently, Facebook announced that it is tightening its security for the 2020 U.S. elections after fresh signs of Russia meddling. The social media giant stated that it’s taking down accounts involved in illicit activities and stepping up searching state-controlled media trying to manipulate American voters.

Facebook pledged to use a variety of security measures, including artificial intelligence, to counter Russian attackers or other online intruders who use misleading strategies and false information to meddle in the 2020 U.S. elections. The new steps announced by Facebook include, Fighting Foreign Interference, preventing inauthentic behavior, Increasing transparency, labeling state-controlled media on their Page and in the Ad Library, preventing the spread of misinformation, and monitoring candidates accounts, elected officials through Facebook Protect.

“Smart technology for automated coding is the answer to securing mobile apps”

Tom Tovar is CEO and co-creator of Appdome, the mobile industry’s first no-code mobile solutions platform. Prior to Appdome, Tom served as executive chairman of Badgeville, an enterprise engagement platform acquired by CallidusCloud; He was also the CEO of Nominum, a DNS security and services provider that was acquired by Akamai; and chief compliance officer and VP of corporate development and legal affairs at Netscreen Technologies. He began his career as a corporate and securities attorney with Cooley Godward LLP. Tovar also holds a JD from Stanford Law School and a BBA in finance and accounting from the University of Houston.

 In an exclusive interaction with Augustin Kurian of CISO MAG, Tom talks about the trends in cybersecurity startups, the no-code model adopted by the company and several initiatives and partnerships of Appdome.

 You began your career as a corporate and securities attorney with Cooley Godward LLP. You then moved to Netscreen Technologies before starting a few of your own ventures. Tell us a bit about your journey in the information security domain.

That’s right. As a lawyer in Silicon Valley, it doesn’t take long to zero in on risks and strategies needed to preserve intellectual property, and the value of data and user privacy. To get these parts right, you have to understand the systems that protect all the elements of the value chain. NetScreen’s market-defining firewall-protected the enterprise perimeter, as well as the data and users behind it. Today, Appdome focuses on securing mobile apps inside the enterprise and in the public consumer markets. As consumers and digital workers, we all use mobile apps to conduct our work, enjoy mobile commerce, as well as share and learn from one another. Our data flows into the mobile apps we use at work and at play. Breaches, compromised processes, loss of data, identity theft, or hacked code; APIs and SDKs threaten how we use our apps. Appdome created a one-of-a-kind solution that secures the mobile data, code, connection and user in seconds, adding the highest levels of security without work, source code, IP or privacy risks.

You have closely seen the startup culture in the information security industry. You helmed major startups which were later acquired by other major infosec tycoons. Can you elaborate on the current startup scene in the cybersecurity industry?

The security market has grown into one of the most dynamic and exciting spaces ever. And when you think about it, it has to be. Threats to digital and mobile economies evolve at lightning speeds. Entrepreneurs and start-ups have to step in to close the gaps. I like companies that leverage A.I., data, and crowdsourcing to deliver solutions that customers need. Customers will continue to reward innovation, for fast outcomes and systems that work. The highest growth potential rests with those start-ups that can combine all three into a single offering. That’s what excites me about Appdome.

What are your tips for budding cybersecurity professionals who want to jump on the entrepreneurial bandwagon?

First of all, do it. Innovation comes from people and the market needs more people stepping forward to start companies. To be successful, look at the market. The companies that are winning are solving something worth solving. They’ve zeroed in on a problem that’s real, pervasive and persistent. They’ve also delivered something that is unique to them. Customers teach each company where to go and what to do next, but the entrepreneur has to take the first step.

One of the biggest concerns at endpoints is securing the mobile app’s APIs. Tell us about how Appdome is securing the mobile app’s APIs with AI and no-codes.

Inside each mobile application rests a treasure trove of business, backend, and user data. Mobile APIs are a big part of that story as developers rightly use APIs to enrich mobile applications for all of us. For example, at this year’s Money 2020 trade show, I saw so many awesome API-based services for everything from biometric authentication, to customer engagement and more. Appdome’s SecureAPI™ secures APIs in mobile apps in minutes, protecting the API itself, as well as the credentials used, and the payloads delivered by the API into mobile apps. Appdome’s SecureAPI™ does not rely on a gateway or highly specialized security development expertise. Users simply click a button to encrypt and shield all the API fundamentals (API URLs, Keys, Secrets, etc.), as well as protect API payloads in motion.

The U.S. Navy’s MyNavy Portal Mobile App using Appdome was one of the news that made headlines early this year. How does Appdome fare against state-sponsored actors considering the U.S. Navy would always be targeted by other nations?

Appdome is honored to provide the U.S. Navy military-grade security for the My Navy Portal mobile apps. We helped them deliver the project faster, with better security than originally scoped. Our technology ensures the Navy, and all of our other customers have the highest levels of security to protect them from all bad actors.

Tell us a bit about the anti-bot services of Appdome and even that doesn’t require coding?

Appdome has a phenomenal partnership with F5 Networks to defend mobile businesses against bots. F5 Anti-Bot SDK does the heavy lifting to protect the mobile backend from bots, while Appdome does the heavy lifting to secure the mobile client from tampering, reversing and debugging. It’s a fast, easy-to-use, end-to-end solution that helps F5 customers defend their mobile businesses without doing any manual coding. Like all of our solutions, Appdome for F5 Anti-Bot is compatible with all native, non-native, and hybrid Android and iOS apps.

This brings us to the last question. A lot of services from Appdome are no-code. Why is that? Do you think no-code formats must be an industry standard?  

The best technologies help us do more in our work and daily lives. That’s why all features, SDKs, APIs and mobile standards available on Appdome are 100 percent no code out-of-the-box. Manually building or coding security into apps takes a lot of time and expertise. Security researchers and engineers are highly specialized professionals. So, it’s easy for the rest of us to fall behind, make mistakes, and more. Appdome believes that using smart technology to perform automated coding is the answer to securing the world’s mobile apps. Build by build, app makers can use Appdome to build standard, self-adjusting, templates of mobile security features into mobile apps with the click of a button. Appdome ensures that mobile security objectives will be achieved no matter how the app, OS, SDK or API changes.

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

Domain Registrar Web.com Hacked!

Popular domain registrar Web.com and its subsidiaries Network Solutions and Register.com are the latest victims of a hacker attack that resulted in the theft of customers’ sensitive information.

According to the official report, unknown intruders accessed the company’s computer systems that gave them access to the account information of current and ex-customers. The intrusion occurred in late August 2019, but the companies said they became aware of the breach on October 16, 2019.

After its investigation, Web.com stated that attackers accessed nearly 22 million records of current and former users of Network Solutions, Register.com, and Web.com accounts. The exposed information included name, address, phone number, email address, and other details of customer accounts. However, Web.com clarified that no financial information was exposed in the incident.

“We store credit card numbers in a PCI (Payment Card Industry) compliant encryption standard and do not believe your credit card information is vulnerable as a specific result of this incident. That said, it is good practice to monitor your credit card account and we encourage you to notify your credit card provider if you see any suspicious charges,” the statement added.

“We encrypt account passwords and do not believe this information is vulnerable as a specific result of this incident. As an added precautionary measure, customers will be required to reset passwords the next time they log in to their accounts. As with any online service or platform, it is also a good security practice to change passwords often and use a unique password for each service,” a spokesperson of Web.com said.

The companies, Network Solutions, Web.com, and Register.com, stated they’re notifying the affected users via email and their websites, and have also reported the incident to federal authorities for further investigation.