Home Blog Page 285

Ransomware shuts down hospitals in the U.S. and Australia

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Multiple hospitals and health service providers from the U.S. and Australia were forced to shut down some of their operations after being hit by ransomware attacks.

According to an official statement, the attack affected and disrupted the IT systems of the DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center from West Alabama’s Tuscaloosa, Northport, and Fayette.

“A criminal is limiting our ability to use our computer systems in exchange for an as-yet-unknown payment,” said DCH Health System. “We will continue to divert any new admissions, other than those that are critical, to other facilities.”

The Victorian Government stated that seven hospitals and health services from south-west Victoria and Gippsland have lost access to their IT systems and went into manual operations.

The affected hospitals are turning away new patients and even canceling some surgeries. The government authorities stated that they’re working with the impacted health services and cybersecurity professionals to investigate the incident.

Describing the unknown hackers as “sophisticated cybercriminals,” the Victorian Government clarified that there is no sign of patients’ data breach as of now.

“The cyber incident, which was uncovered on Monday, has blocked access to several systems by the infiltration of ransomware, including financial management,” a spokesperson from the Victorian government said in an official statement.

“Hospitals have isolated and disconnected a number of systems such as the internet to quarantine the infection. The priority is to fix all affected systems and prevent any further compromise. This isolation has led to the shutdown of some patient record, booking and management systems, which may impact on patient contact and scheduling. Where practical, hospitals are reverting to manual systems to maintain their services,” the statement added.

Healthcare organizations have become an easy target for attackers, as they hold sensitive information of their patients.

In a recent ransomware attack, Protected Health Information of more than 300,000 patients of the physician group named Premier Family Medical at Utah was compromised. The group confirmed that it suffered a ransomware attack but didn’t disclose the number of patients affected in the attack.

According to the official statement, the incident occurred on July 8, 2019, and barred access to patients’ data and other network systems. The physician group stated that it notified law enforcement authorities about the attack and appointed a technical team to investigate the issue and regain access to its systems and patient data.

Symantec and Anomali join hands for Threat Intelligence Driven Solutions

Threat Intelligence

Threat intelligence platform provider Anomali recently announced a strategic partnership with cybersecurity firm Symantec Corp. to meet global demand for threat intelligence-driven solutions.

Anomali helps organizations find and respond to cyber threats. The US-based cybersecurity company notifies organizations against cyber actors and other distrustful activities on their networks through internal security monitoring programs.

The new partnership establishes a platform for sharing information on cyber threats and focuses on enhancing the methods of dealing with cyber threats. The alliance also expands the availability of threat data, information, and intelligence to drive effective cybersecurity decisions.

Commenting on the new alliance, Anomali CEO Hugh Njemanze, said, “Threat actors frequently know all about their victims’ networks, whereas their targets often know very little about their attackers. This situation has given adversaries an unfair advantage. Our partnership with Symantec delivers an entirely new layer of intelligence to a wider set of customers, giving them a deeper understanding of the varied threats, they are up against.”

“Symantec’s industry standing as a cybersecurity leader is recognized around the world, as its solutions protect a variety of environments – from enterprises, to government agencies, to consumer devices,” said Adam Bromwich, SVP & GM, Endpoint Solutions, Symantec. “By partnering with Anomali, our customer base will have access, via the Anomali technology, to the same tools and actor intelligence Symantec’s threat experts use every day to uncover targeted and advanced attacks.”

Anomali stated that it’s developing more than 250 products and services that integrate with Symantec’s Integrated Cyber Defense (ICD) Platform. Symantec’s ICD combines cloud and on-premises security across endpoints, networks, email, and cloud protecting organizations against evolving cyber threats.

Symantec, better known for its Norton Security software suite, partnered with more than 120 companies to drive down the cost and complexity of cybersecurity. The California-based company stated it had forged partnerships with major players like AWS, Box, IBM Security, Microsoft, Oracle, ServiceNow, and Splunk, as well as dozens of other technology innovators. The company stated the acquisitions reinforce the company’s leadership in cybersecurity.

A Malicious GIF image sent via WhatsApp could hack your Android Phone

WhatsApp and Indian governmentWhatsapp Hack

Facebook-owned messaging app WhatsApp, recently fixed a security vulnerability in its Android-based applications, after a security researcher reported the issue nearly three months back.

According to a researcher, who goes by a name Awakened, the vulnerability could have allowed hackers to compromise Android devices remotely, allowing them to steal files and chat messages. The vulnerability, named CVE-2019-11932, is a double-free memory corruption bug that exists in the open-source GIF image library that WhatsApp uses to generate previews for videos, images, and GIFs.

The researcher stated the flaw allows the attackers to execute arbitrary code on targeted devices. To exploit this flaw, an attacker needs to send a specially created malicious GIF to targeted Android users. The malware triggers when the user opens the image in WhatsApp.

“The exploit works well for Android 8.1 and 9.0, but does not work for Android 8.0 and below,” Awakened writes. “In the older Android versions, double-free could still be triggered. However, the app just crashes before reaching to the point that we could control the PC register,” the researcher said.

The researcher urged WhatsApp users to update their apps to prevent potential threats. “Facebook acknowledged and patched it officially in WhatsApp version 2.19.244. WhatsApp users, please do update to the latest WhatsApp version (2.19.244 or above) to get rid of this bug,” the researcher added.

This is not the first time for WhatsApp to deal with such vulnerabilities in its software. Recently, Symantec’s Modern OS Security team discovered a flaw affecting WhatsApp accounts for Android devices. The flaw allows malicious attackers to manipulate and expose media files in WhatsApp.

Symantec stated the security flaw, dubbed Media File Jacking, affect WhatsApp for Android by default, if certain features are enabled. The flaw, if exploited, allows the attackers to misuse and manipulate sensitive information like personal photos and videos, corporate documents, invoices, and voice memos.

“Women should be actively safeguarding healthcare systems”

Luigi Rebuffi, Secretary General of ECSO (European Cyber Security Organization) wins an award for the Women4Cyber intiative at Cyber Security Nordic 2019.

By Augustin Kurian

The third edition of Cyber Security Nordic, which is touted to be one of the most renowned cybersecurity events of Northern Europe, kicked off on Wednesday, October 2, at Messukeskus, Helsinki, Finland.

A highlight of the event was the Cyber Security Nordic Award which was won by Women4Cyber initiative. The award was funded by the Finnish Fair Foundation, F-Secure, Insta Defsec and The Finnish Electrical Safety Board STEK.

CISO MAG had an exclusive interview with Luigi Rebuffi, Secretary General of ECSO (European Cyber Security Organization) about the Women4Cyber initiative at Cyber Security Nordic 2019. 

Can you tell us about the genesis of the Women4Cyber initiative?

It is estimated that by 2022, 350,000 new cyber experts will be needed in Europe and 1.8 million globally. To combat the impending skill gap, we must first have to understand where it all begins. And it was evident that the representation of women in the cybersecurity domain has been stagnant for years. For a long time, it never went past the 11 percent mark. How can we move ahead without fifty percent of our population?

We felt that Europe must be able to respond to the increasingly tough competition for the best professionals in the field. In January 2019, the ECSO launched a new initiative, Women4Cyber, which focuses on increasing the cybersecurity expertise of female leaders and experts and building their professional networks through concrete actions.

The patron of the initiative is Mariya Gabriel, Member of the European Commission, responsible for the digital economy and society. We also founded this Women4Cyber initiative as a homage to our dear friend Mari Kert-Saint Aubyn, who was one of the greatest thought leaders of our time but had an untimely demise.

Even though the initiative highlights women, we are targeting everyone and want to broadly increase cyber awareness in the European region. Behind the initiative is a group of influential women from public administration and the business world.

Women constitute a major part of the healthcare system. With healthcare data becoming a beehive for cyber-attacks, it is also important that women should also play an active part in safeguarding the systems. At present, there are relatively few women in technological fields; we are on a mission to change that.

It is often said that one of the biggest reasons for the dearth of women in the cybersecurity space is the lack of role models. In fact, men make up most of the key commenters and high-profile influencers. How do you plan on changing that?

We understand that there are very fewer role models in cybersecurity for women to follow and that has been one of the most deriving factors for lack of women representation. In fact, even at this conference, you would have noticed the ratio of women speakers compared to men, and that itself speaks volumes about it. In that front, we have more than 300 cybersecurity women becoming a part of our initiative.

Apart from that, we are also creating a roster of women cybersecurity leaders in the space and will make sure that several thought-leaders from that list will be a part of several upcoming cybersecurity conferences all across Europe — to make sure that there is better visibility of women in the space.

We are also planning to leverage the list of women leaders and are also planning to have a national chapter of Women4Cyber all across Europe.

What according to you are the major challenges for women to join this space?

There is this thought that the cybersecurity sector is more of a man’s job and women are not much inclined towards it. The first step toward changing this must begin from the fundamental understanding that it is wrong. In fact, nearly 30 percent of all cybersecurity jobs are also non-IT. If it is the notion that technology is becoming the major hinderance, then we must tell the women that cybersecurity is not only about IT engineers and coders, but it is also a vast spectrum of opportunities. And if you, as a woman, are inclined toward the technological part of cybersecurity, the opportunities are even more for you.

What is highly crucial here is to change the mindset. We not only want to propagate the fact that the information security industry needs more women, but also shed light on the fact that cybersecurity must be for everyone without any gender bias. And that thought must be taught to the kids, as they will drive the future tomorrow.

What are the fundamental action plans for Cyber4Women initiative?

We call it our three concrete actions. These include awareness and visibility, spreading and creating a network and finally influencing the career and job market. We are here to propagate one crucial message and that is: cybersecurity is for everyone.

Who according to you can make a huge difference and bring more women into cybersecurity?

As we have discussed, influencers and role models play a major part in improving cybersecurity in the region. Apart from that, the major responsibility also lies on recruiters. Women should be aware of how fulfilling the opportunities at cybersecurity is, and recruiters can play a big part in making a difference. The cybersecurity industry has untapped potential, and even public administration can also help boost this sector.

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features. He was invited to Finland to report on Cyber Security Nordic.

Singapore and UK sign Joint Statement on Cooperation to promote ‘Security by Default’

Joint-Statement-Signing-between-UK-and-Singapore

 

The governments of Singapore and the United Kingdom recently joined hands to promote user ‘Security by Default’ in both countries.

According to the official report, the Chief Executive of the UK’s National Cyber Security Centre, Ciaran Martin, and Chief Executive of Singapore’s Cyber Security Agency, David Koh, signed a joint statement on cooperation between Singapore and the United Kingdom on the Internet of Things.

Both countries agreed to work together on areas of common interest, including alignment, cooperation, and coordination to support the cause ”secure by default.”. The Singapore-UK strategic alliance is intended to drive improvements in the security of smart consumer devices.  The agreement also accelerates the IoT industry to grow and innovate.

“Both nations will adopt a multilateral approach by working with our partners, both internationally and regionally, including industry and consumer groups, to promote the implementation of good practice as set out in the relevant industry global standards. Implementing clear good practice principles from industry across all their consumer IoT devices will result in citizens and the wider economy is made safer and more secure whilst using their products,” an official statement read.

The UK and Singapore governments urged the IoT manufacturers to implement industry best practices like: Discontinuing the security shortcomings; Regulating vulnerability disclosure programs across the IoT industry, and developing software security updates to protect the users’ data throughout the lifetime of IoT products.

“We support the development of IoT assurance schemes and other efforts designed to give consumers confidence in the security of their products. The UK and Singapore have a shared interest in enhancing our bilateral cooperation in this area, as we develop our national approaches,” the statement added.

In a similar cooperation deal, Australia and the United Kingdom pledged to intensify the fight against state-sponsored cyber-attacks. The announcement was made by British Prime Minister Theresa and Australian Prime Minister Malcolm Turnbull after both the leaders released an agreement joint declaration by the 53 nations of the Commonwealth on the dangers to civilian and military networks.

The written agreement commits both nations to a new era of practical cooperation. “Our responses will be proportionate to the circumstances of the incident and consistent with our support for the rules-based international order and our obligations under international law,” the statement read.

Everyone4cyber: The Key Takeaway from Cyber Security Nordic 2019

Cyber Security Nordic 2019

By Augustin Kurian

Amidst a legion of information security experts and stakeholders of safe internet, the third edition of Cyber Security Nordic, which is touted to be one of the most renowned cybersecurity events of Northern Europe, kicked off on Wednesday, October 2, at Messukeskus, Helsinki, Finland. The event had a slew of pioneers from the infosec space including Bruce Schneier, Mark Galeotti, Kim Zetter, Rik Ferguson, Tom Van de Wiele, and Perttu Pölönen.

The event was a knowledge-sharing platform that discussed cybersecurity from the perspectives of both business and public administration.

“The importance of cybersecurity is increasing year by year. Cybersecurity offers new business opportunities for solution providers and users. If security issues are not taken care of, damage and recovering from it can cause major problems”, says Juha Remes, Executive Director of FISC (Finnish Cyber Security). “We learn from the past, examine the present, and trust the future – which we can significantly influence by making the right decisions. Cyber Security Nordic brings together industry leaders to illustrate how cybersecurity is part of the business of companies and organizations, how it affects competitiveness, and the role cybersecurity plays in society. The event will also feature cyber industry trends and phenomena.”

The themes of the event included politics, economics and the reality of cybersecurity in the Nordic region.

Another key highlight of the event was the Cyber Security Nordic Award which was won by the Women4Cyber initiative. The award was funded by the Finnish Fair Foundation, F-Secure, Insta Defsec and The Finnish Electrical Safety Board STEK.

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features. He was invited to Finland to report on Cyber Security Nordic.

Around 96 percent of Singapore Businesses Suffer Data Breach: Survey

Singtel data breach

Endpoint security firm Carbon Black stated that cyber-attacks on Singapore firms have increased during the past 12 months, causing security breaches affecting 96 percent of organizations surveyed. In its survey report, Singapore Threat Report- Defender Power on the Rise, Carbon Black revealed 90 percent of Singapore businesses have been breached in 2018.

The research findings are based on the responses of 252 Singaporean CIOs, CTOs, and CISOs surveyed from different industries, organization sizes, and IT team sizes to show modern attacks and cyber defense landscape in the Singapore region.

According to the research findings, 96 percent of surveyed Singapore-based companies reported data breaches last year and 93 percent of them said they’ve seen an increase in attack volumes. Also, 95 percent of the organizations stated the attacks have become more sophisticated and 99 percent of them stated they’ve planned to increase spending on cyber defense.

As per the findings, Ransomware is the most high-volume attack type in Singapore with 28 percent of the organizations stated they frequently encountered it. However, the research also stated that human errors played a big part in the attacks that lead to breaches.

Speaking on the research findings, Rick McElroy, Head of Security Strategy at Carbon Black, said, “As we analyze the findings of our second Singapore Threat Report, it appears businesses are adjusting to the ‘new normal’ of sustained and sophisticated cyberattacks. Greater awareness of external threats and compliance risks have also prompted businesses to become more proactive about managing cyber risks as they witness the financial and reputational impacts that breaches entail.”

“As the cyberdefense sector continues to mature, businesses are becoming more aware of the tools at their disposal and the tactics they can use to combat cyberattacks. We believe this growing confidence is indicative of a power shift in favor of defenders, who are taking a more proactive approach to hunting out and neutralizing threats than previously,” McElroy added.

In order to boost cybersecurity and tackle next-generation cyber threats, the Singapore government recently updated the guidelines on data breach notification and accountability. Unveiled by the Personal Data Protection Commission (PDPC), the new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident within 72 hours of discovering a data breach.

Why Plain Virus Protection Isn’t Enough These Days: Reason Security Product Review

PRODUCT REVIEW

By Reason Security

Despite the many reports about the dangers of cyberattacks, many individuals and organizations still remain unconcerned when it comes to protecting their data and devices. While it’s true that the media reports are mostly about large-scale data breaches, ordinary users and smaller businesses are also susceptible to these attacks.

Believe it or not, small businesses are currently primary targets of privacy breaches and social engineering attacks. Hackers are routinely finding ways to steal user information in order to commit fraud. In 2018, the FBI’s Internet Crime Complaint Center (IC3) report showed that the financial losses from such attacks totaled $2.7 billion.

Spying through remotely accessed webcams and microphones has also become rampant. Hackers can remotely turn on these peripherals to record users’ private moments in hopes of capturing anything incriminating. Such recordings can then be used to blackmail or extort victims. Due to the rise in bring-your-own-device arrangements among organizations, devices used for business purposes may be exposed to such risks. Instead of private media and communication, hackers may target privileged information or intellectual property.

Reason Security has been recently making waves as a privacy-oriented antivirus that includes features that are designed to mitigate attacks that invade and exploit user privacy. Let’s take a deeper look at these features.

Pros

Real-time Protection. Reason primarily functions as both an antivirus and anti-malware. It features real-time protection that promptly notifies users when it detects viruses, malware, and other malicious files. Users can then readily quarantine and remove these threats. Users can also perform routine scans that check the memory, system files, and application folders for any suspicious files. Backed by a database of more than a million malware samples, Reason detects malware accurately and efficiently. Its data-driven analytics helps prevent false-positives and detection lapses.

Webcam and Microphone Protection. Reason also protects webcams and microphones from being accessed by unknown and potentially dangerous programs. Reason will notify users if an attempt is made to access the computer’s webcam or microphone. The settings can also be configured to identify which applications will be automatically given access and which ones will be automatically blocked.

Ransomware Protection. Given how rampant ransomware has become in recent years, Reason’s ransomware protection is definitely a welcome feature. Reason monitors any attempts to encrypt a file and automatically blocks them to prevent successful execution.

Should I Remove It? Not all applications are created equal with some legitimate programs even containing vulnerabilities that hackers can exploit. Reason also has a “Should I Remove It?” feature that checks all installed programs for their safety and security and allows users to uninstall those that may be found risky or suspicious.

Free Browser Add-Ons. Apart from the security features it offers, Reason has also made available two free Chrome browser plugins. Both plugins help users more safely navigate the web. The first one informs you which links you should avoid to keep you away from websites that look to get your personal and financial information. The other one checks if your downloaded files are safe to run.

Cons

Premium Features. Unfortunately, most users aren’t keen on spending on security and protection. Reason’s advanced features are only available in the paid Premium version. A free Essentials version is available, but it only features real-time protection, threat detection, and removal. Ransomware and webcam protection can only be unlocked by paying for a subscription.

For Windows Only. Reason is only available for Windows PCs unlike other antiviruses that have versions for other operating systems like Linux, Android, and Mac.

“Coming Soon” Features. Reason looks to offer other features such as IoT Protection and an Unwanted App Blocker in the future. Users that find these features to be essential, might have to look elsewhere for an anti-malware solution for the time being.

Cost

Reason has both free and paid versions. The free Essentials version offers standard antivirus features such as malware removal and real-time protection. The Premium version which starts at US$60 a year includes all the key privacy protection features such as webcam protection and ransomware protection. Fortunately, it is currently on sale at 50 percent off. Yearly subscriptions only cost US$30 during this period.

Final Thoughts

With the rise of cybercrimes, relying only on basic antiviruses and security solutions seems unwise. Upon closer inspection, Reason looks to be a great, affordable choice for anyone looking for protection from privacy threats. By offering its solution at a significant discount, Reason allows users to access full features at a great bargain.

CISO MAG does not evaluate the advertised product, service, or company, nor endorse any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

BlackBerry Launches New Cybersecurity Research Labs

BlackBerry Launches New Cybersecurity Research Labs

Security software and services company BlackBerry Limited recently announced the launch of BlackBerry Advanced Technology Development Labs (BlackBerry Labs), a new business unit focused on research and development in the cybersecurity space.

The new research lab, which includes a team of over 120 software developers and security researchers, aims to investigate and incubate technologies for security and data privacy for its customers, with a focus on data science and machine learning.

BlackBerry, best known as a smartphone manufacturer, is now focused on security software for smartphones, embedded systems, and autonomous cars.

Speaking on the new establishment, Charles Eagan, BlackBerry’s CTO, said, “The establishment of BlackBerry Labs is the latest in a series of strategic moves we’ve taken to ensure our customers are protected across all endpoints and verticals in the new IoT,”

“Today’s cybersecurity industry is rapidly advancing, and BlackBerry Labs will operate as its own business unit solely focused on innovating and developing the technologies of tomorrow that will be necessary for our sustained competitive success, from A to Z; Artificial Intelligence to Zero-Trust environments. We believe this highly experienced team will allow us to remain nimble, engaged and, above all else, proactive in our efforts to be the most trusted security software leader in the market,” Eagan added.

Blackberry recently acquired artificial intelligence and cybersecurity startup Cylance to expand its technology and cybersecurity portfolio. According to the acquisition deal, which was announced in November 2018, Cylance will function as a separate entity within the BlackBerry.

BlackBerry enables the Enterprise of Things (EoT) with its robust technology that allows fixed endpoints to communicate securely and maintain privacy. The Ontario-based firm claims its Spark Platform is a secure chip-to-edge communications platform for the EoT that will create trusted connections between any endpoint.

Cylance’s machine learning and artificial intelligence technology is a strategic addition to BlackBerry’s end-to-end secure communications portfolio. Notably, its embeddable AI technology will accelerate the development of BlackBerry Spark, the secure communications platform for the Internet of Things.

Singapore Government Patches 31 vulnerabilities found by Ethical Hackers

Cybersecurity Singapore

The Government of Singapore announced that it has rectified 31 vulnerabilities in its network systems that were found by ethical hackers in the Government Bug Bounty Program (BBP). The bug bounty program was organized by the Government Technology Agency (GovTech) and Cyber Security Agency (CSA) in partnership with HackerOne, a popular bug bounty platform.

HackerOne helps organizations find and fix the potential vulnerabilities before they can be exploited by cybercriminals. The new bug bounty program is part of the Singapore government’s ongoing commitment to protect its citizens and secure government network systems. The hacking challenge will offer a monetary reward to the hackers for discovering and reporting potential vulnerabilities.

The Government has paid out S$25,950 in bounties for discovering 31 vulnerabilities, in which four were considered as High Severity and the remaining 27 were considered as medium/low severity.

Also, GovTech launched its new Vulnerability Disclosure Program (VDP) on the HackerOne platform, inviting security pros to identify and report the vulnerabilities. The Singapore government stated the bug bounty program will run over a period to find security flaws in public-facing government network systems and websites.

The VDP is a part of the Singapore Government’s ongoing commitment to collaborate with the cybersecurity community to build a secure and resilient Smart Nation. In addition to the VDP, GovTech will conduct a third government BBP in November 2019 to continue to strengthen and enhance the cybersecurity of government systems and applications.

“The Singapore Government has been a leader in their adoption of hacker-powered security solutions within the Asia Pacific region, and we are honored to be a part of this journey,” said Fifi Handayani, GovTech’s Program Manager at HackerOne. “Their implementation of both ongoing and time-bound hacker-powered security initiatives demonstrate the maturity of their cybersecurity program and the value they have seen from maximizing hacker engagement to reduce risk.”

In related news, the Monetary Authority of Singapore (MAS) announced the launch of S$30 million (US$22 million) cybersecurity capabilities grant.  The new allocation helps Singapore’s financial institutions strengthen their cyber resilience and upskill local talent through cybersecurity-related training programs like security operations, cyber threat surveillance, computer forensics, malware analysis, and cyberthreat hunting.