Home Blog Page 288

Forget Passwords. These Earphones Can Unlock Your Smartphone

EarEcho Authentication

The way we identify ourselves to our smartphones has evolved over the years — passwords, fingerprint, and facial recognition, etc. And now, researchers came up with a new biometric authentication process that uses a new part of our body to unlock the smartphones — our Ear Canal.

Zhanpeng Jin, a researcher from University at Buffalo, State University of New York, has invented a new biometric tool dubbed as EarEcho, which uses wireless earphones to authenticate users by scanning their ear canal.

How EarEcho Works?

According to Zhanpeng, the EarEcho tool uses a microphone inserted in a regular wireless earbud, which records the sound that bounces back from the ear canal when earbuds play audio, creating a unique profile of the user’s ear canal. The sounds captured by the microphone are sent to the smartphone via Bluetooth to authenticate the user. Zhanpeng claimed that his new invention is 95 percent effective in unlocking users’ smartphones.

“It doesn’t matter what the sound is, everyone’s ears are different, and we can show that in the audio recording. This uniqueness can lead to a new way of confirming the identity of the user, equivalent to fingerprinting,” Zhanpeng said in a statement.

However, with technology advancing day by day, the cyber-attackers too are finding innovative ways to get into our devices.  In a recent research, security experts have discovered that hackers can use the microphone on the smartphone to steal the phone password and gain access to the device’s data. So, these hackers may sooner or later get round to finding a vulnerability in EarEcho.

Academic researchers from England and Sweden designed a malware that can exploit the smartphone’s microphone to steal the device’s passwords and codes. In their report, Hearing your touch: A new acoustic side-channel on smartphones, the researchers claimed that they’ve found the first Acoustic side-channel attack that presents what users type on their touch-screen devices. The malware is created to figure out the PIN code and password to your phone or tablet by simply hearing your keystrokes, according to the researchers.

IoT Attacks Rising in Cybercriminal Underground Communities: Trend Micro

IoT Connections to Reach 83 Billion by 2024: Report, CISA alerts critical infrastructure, CISA – FBI holiday season alert

Trend Micro, a cybersecurity solutions provider, stated that the Internet of Things (IoT) has become a primary target for cybercriminals. In its latest research, named the Internet of Things in Underground Communities, Trend Micro detailed the rising trend for IoT attacks.

The research explained how online intruders exploit vulnerabilities in connected devices. It has examined several hacker forums in the Russian, English, Portuguese, Spanish, and Arabic languages to determine the hackers’ activity on IoT attacks.

According to the research findings, the Russian and Portuguese-speaking forums are most prominent in financially driven attacks than the other cybercriminal markets. It’s said that the main activity of these forums is selling access to compromised devices such as webcams, routers, and printers.

In order to mitigate cyber risks from the design phase itself, the researchers at Trend Micro urged the IoT manufacturers to partner with security experts.

“The Russian cybercrime underground market is the most sophisticated out of all the underground communities we discuss in this paper. The money-driven criminals make up a market thriving with exploits for routers, customized firmware for smart meters, talks of hacking gas pumps, and router-based botnets for sale. There is a variety of conversations taking place around devices, including fewer common platforms. Most of these talks have a monetization angle. In general, a Russian underground is a place for business where hacking and technical information is mere details,” the report stated.

In its earlier research, Trend Micro revealed that there is a 265 percent increase in Fileless Attacks in the first half of 2019 when compared with the same period in 2018. A Fileless Attack, also known as a zero-footprint attack or non-malware attack, will not install any malicious software on a user’s computer, as it exploits applications that are already installed in the device.

Trend Micro stated that cybercriminals are using sophisticated attack formats that aren’t visible to traditional security procedures. In its Mid-Year Cybersecurity report, Trend Micro revealed that out of 1.8 billion ransomware threats, from January 2016 to June 2019, the highest number of ransomware threats (42.98 percent) are suffered by businesses in Asia. And the companies in India reported around 23.88 percent of ransomware attacks in the first of 2019, the report stated.

Cybersecurity could become a Revenue Model for Indian Telcos: IBM India

American multinational information technology company IBM stated that cybersecurity is going to become a major revenue opportunity for Indian telecom operators that may offer security as a service to enterprises. Through its IT outsourcing deals, the technology giant is engaging with major telcos in India for its security-related products, IBM said in a statement.

According to industry sources, IBM is overseeing Vodafone Idea’s Internal Security Operations Center as per its recent IT outsourcing deal. Under its cybersecurity portfolio, IBM is concentrating on threat and fraud management services, IoT security monitoring, managed security, trusted digital identity, and secure authentication.

In its recent survey, IBM revealed that the average cost of a data breach in India has grown 7.29 percent to reach Rs 12.8 crore from Rs 11.9 crore last year (Rs 12.8 crore is approximately 1.8 million USD). A crore denotes 10 million. The exchange rate is currently Rs 70.94 to a dollar. According to the survey report dubbed Cost of a Data Breach 2019, the Per capita cost for a stolen record was raised to Rs 5,019 ($US 70.75), which is an increase of 9.76 percent when compared to the last year.

The survey findings, which are based on in-depth interviews with 507 companies around the world, highlighted that the root cause for 51 percent of data breaches was malicious or criminal attacks, 27 percent of breaches due to technical issues, and human error led to 22 percent of breaches in India.

“Data breaches can cause devastating financial losses and affect an organization’s reputation for years. From lost business to regulatory fines and remediation costs, data breaches have far-reaching consequences. The annual Cost of a Data Breach Report, conducted by the Ponemon Institute and sponsored by IBM Security, analyzes data breach costs reported by 507 organizations across 16 geographies and 17 industries,” IBM said in a post.

IBM stated that they’ve surveyed the cost of data breaches in different industries which suffered a data breach last year. The survey also discovered that data breaches in the U.S. are more expensive, costing USD8.19 million, then the average of the companies worldwide.

Aware Appoints Robert A. Eckel as its New Chief Executive Officer & President

Cybersecurity

Aware, a supplier of biometrics software and services, recently appointed Robert A. Eckel as its Chief Executive Officer and President. Eckel will also serve as a member of the Board of Directors of Aware. Aware provides biometrics software products and development services to governments agencies, system integrators, and solution providers globally.

Previously, Eckel served as the Chief Executive Officer and President North America at Idemia, an Identity, and Security business. Eckel holds significant expertise in biometrics, secure identity, air traffic control, and defense systems.

“I’m excited to be joining an Aware team known for its customer relationships, employee dedication, and exemplary domain knowledge and passion.  Together we’ll continue to expand Aware’s leadership position in the industry and bring effective biometric technology into people’s lives.  One of my passions is to build and lead companies that enable individuals to experience the life we deserve through technology. My background in secure identity solutions, biometrics technology, and complex systems will help me drive this mission for Aware,” Eckel said.

Commenting on the new appointment, Brent Johnstone, Aware’s Chairman of the Board said, “Over the past several years, the Aware team has done a great job expanding our industry-leading biometric technology and platforms to enable us to grow beyond our traditional government market and penetrate the commercial market with a range of robust, flexible, biometric applications and solutions.  We’re excited to name Bob Eckel as the President and Chief Executive Officer of the Aware team to drive our leading biometric technology into the government and the commercial markets as well as explore strategic partnerships. Bob brings a wealth of direct industry experience as well as a track record of driving commercial success.”

Be Prepared, Be Proactive and Practice to Deal with Cyber Threats: Verizon

tech, tech provider

According to the latest Verizon Data Breach Investigations Report and the Verizon Insider Threat Report by American telecommunications company, Verizon, businesses are now more aware than ever of how cybercrime could impact their reputation, and their bottom line. In an industry which has always been marred by lack of cybersecurity talent and cybersecurity being an afterthought, the study highlights a change of thought and trend. It continues to highlight how security has become a boardroom topic.

The company had often stressed on how cyber-threats and trends that should be on every organization’s radar in its annual reports in the last three years. According to the report, it is not only important to understand the threat landscape but also have a comprehensive approach toward dealing with cybersecurity incidents.

“Companies think that having an IR Plan on file means they are prepared for a cyber-attack. But often these plans haven’t been touched, updated or practiced in years and are not cyber-incident-ready,” comments Bryan Sartin, Executive Director, Verizon Global Security Services. “Having an out-of-date plan is just as bad as having no plan at all. IR Plans need to be treated as ‘living documents’, regularly updated, and breach scenarios practiced in order for them to be truly effective,” Verizon said in a statement.

John Grim from Verizon Threat Research Advisory Center (VTRAC) and Investigative Response Team said, “IR Plans can be kept current by including stakeholder feedback, lessons learned from breach simulation testing as well as intelligence insights on the latest cyber-tactics being used. This enables the plan to constantly re-create itself reflecting the ever-changing cyber-security landscape.”

Verizon has also identified six typical phases every incident response plan which begins with: Planning and preparation; Detection and validation; Containment and eradication; Containment and eradication; Collection and analysis; Remediation and recovery; and Assessment and adjustment.

In another study, according to research by Infosys Knowledge Institute (IKI), the research arm of Infosys, titled ‘Assuring Digital-Trust’ nearly half i.e. 48 percent of corporate boards and 63 percent of business leaders are actively involved in cybersecurity strategy discussions.

IKI surveyed 867 senior executives from 847 firms with annual revenues over US$500 million. These firms were from countries like the U.S., Europe, Australia and New Zealand (ANZ). The research points out that security has finally taken the center stage.

FortifyData Announces Bob Morrell as its New President and CEO

Cybersecurity software company FortifyData recently announced the appointment of Bob Morrell as its new CEO and President. Bob Morrell was previously co-founder and CEO of Riskonnect. He is also a serial entrepreneur and a pioneer in risk management software.

In his new role, Morrell will lead the deployment of FortifyData’s cyber risk platform. He also oversees the strategic direction of the company and growing its global sales.

FortifyData helps public and private enterprises enhance their cybersecurity posture. It’s said that FortifyData’s cyber risk management platform allows companies to comply with industry security standards, including ISO 27001, PCI, HIPAA, SOC 2, NIST, and 23NYC500.

Speaking on his new role, Bob Morrell said, “What excites me most about FortifyData is the opportunity we have to protect companies from their biggest risk: cybercrime. Ultimately, companies are looking for a platform that provides a clear line of sight to their cyber risk exposure with an integrated, holistic solution, and that’s what we provide. It’s not just the bigger companies that need help. I see a lot of opportunities to help businesses of all sizes to navigate this increasingly complex world of cybersecurity.”

“We’re thrilled to have Bob Morrell join the company. Bob has vast experience establishing and growing software technology companies and we’re confident he can help us build on our solid foundation to take FortifyData to the next level. We are all excited about our future as we charge ahead to deliver the best cyber risk management platform in the world,” said Victor Gamra, founder and CTO of FortifyData.

Yahoo Data Breach Victims will get US$ 100 Compensation

Yahoo

In one of the biggest class-action lawsuit settlements in the United States history, Yahoo Inc. has agreed to pay US$ 117.5 million over a series of data breaches that affected its users between 2012 and 2016. The affected users will likely get US$ 100 in compensation or two years of credit monitoring services for free.

Yahoo urged the Settlement Class Members to claim for the reimbursement. In case users already hold credit monitoring services, they can opt for cash payment, which is less than US$ 100 or more (up to US$ 358) per user, depending on how many users are claiming for the settlement, Yahoo said in a statement.

According to Yahoo, anyone who had a Yahoo account between January 1, 2012, and December 31, 2016, and is a resident of the United States or Israel is eligible for the settlement.

“You may additionally provide documentation or proof to receive reimbursement of up to $25,000.00 in out-of-pocket losses, including lost time, that you believe you suffered or are suffering because of the Data Breaches. As to documented lost time, you can receive payment for up to 15 hours of time at an hourly rate of $25.00 per hour or unpaid time off work at your actual hourly rate, whichever is greater. If your lost time is not documented, you can receive payment for up to five hours at that same rate,” the statement added.

In December 2016, Yahoo had admitted that more than one billion accounts were compromised in the infamous 2013 breach. However, the company later revealed that all three billion company’s accounts were compromised.

The hack exposed user account information, which includes name, email address, hashed passwords, birthdays, phone numbers, and, in some cases, encrypted or unencrypted security questions and answers. However, the company’s investigation confirmed that credit card and bank account data was not hacked in the breach.

In a post titled, “Yahoo 2013 Account Security Update FAQs”, the company said, “Yahoo is providing notice to additional user accounts affected by an August 2013 theft of user data previously announced by the company in December 2016. This is not a new security issue. In 2016, Yahoo previously took action to protect all user accounts”.

Google Calendar Possibly Revealing Users’ Data: Researcher

Google Calendar

Security researchers have issued a warning over how attackers are exploiting Google’s Calendar feature to target users with a credential-stealing attack.

Avinash Jain, a security researcher from India, explained how misconfigured settings in google services can be exploited. The researcher revealed that by using Google dork (advance search query), he was able to see all the public google calendars/users who’ve set their calendar as public. He also stated that hackers are making phishing attacks, by abusing Google Calendar services, to trick users into giving away sensitive information like passwords, card details, and other financial data.

“This is an intended feature provided by Google Calendar but what if a user doesn’t intend to share the calendar until he shares the link and still someone is able to find the public link of their calendar. Then that becomes a problem. And what if someone belonging to an organization makes their official google calendar public — They might end up disclosing internal information of the company,” Avinash said in a blog post.

Perhaps, the issue is not the latest. Earlier, threat intelligence and cybersecurity firm Kaspersky stated that it detected many unsolicited pop-up calendar notifications sent to Gmail users by cybercriminals as a sophisticated spam email attack. The calendar phishing emails exploited the automatic addition and notification of calendar invitations feature for people using Gmail on their mobiles.

The scam occurs when an attacker sends an unsolicited calendar invitation carrying a link to a phishing URL and encourage the recipient to click on the link. The user then redirected to a fake website, appears to be original, that features a simple questionnaire and offered a prize after completion.

The victim will be asked to fill in personal details like name, phone number, address, and bank details in order to steal the victim’s money or identity. The researchers urged the users to turn off the ‘automatically add invitations’ option to the Google calendar to avoid calendar scams.

Microsoft owned GitHub acquires Semmle

Acquisition

Microsoft-owned GitHub recently announced that it has acquired code analysis provider Semmle in an undisclosed amount. Based in San Francisco, Semmle develops an engineering analytics solution. It helps developers and security researchers discover potential vulnerabilities in their code.

Founded in 2006, Semmle claims that its products have been used by NASA, Uber, Google, and Microsoft to enhance their cybersecurity posture.

GitHub stated that it’s now a Common Vulnerabilities and Exposures (CVE) Numbering Authority and with the latest acquisition it will become easy for code contributors to report potential vulnerabilities directly from the repositories.

“Open source has had a remarkable run over the past 20 years. Today almost every software product from any vendor or community includes open-source code in its supply chain. We all benefit from the open-source model, and we all have a role to play in making open source successful for the next 20 years,” GitHub said in a blog post. “Both of these announcements are part of our larger strategy to secure the world’s code.”

“We’re so excited to be joined by the Semmle team and to welcome their world-class engineers and security researchers to GitHub. Together, we’ll bring their work to all open source communities and to our customers. As a community of developers, maintainers, and researchers, we can all work together toward more secure software for everyone,” GitHub added.

GitHub faced severe criticism recently due to a series of data breaches. Canonical, the maker of the Ubuntu operating system, recently revealed that it has suffered a hacker attack. In an official statement, the company stated that hackers have compromised its GitHub account, a code-sharing site, on July 6, 2019, and created 11 new repositories. It’s believed that the attackers apparently didn’t access any sensitive information or manipulated source codes.

Github faced a similar issue when a Chinese drone maker Da-Jiang Innovations (DJI) landed itself into a cybersecurity row over a bug bounty issue. On November 21, 2017, Kevin Finisterre, an independent security researcher, claimed that he found a private key publicly posted on code-sharing site Github, after which he was able to access confidential and sensitive customer information and saw “unencrypted flight logs, passports, drivers’ licenses, and identification cards.”

Cybersecurity startup Acronis secures US$ 147 million

Cybersecurity solutions provider Acronis recently secured US$ 147 million in an investment round led by Goldman Sachs. With the latest investment, the Singapore and Switzerland-based company reached to the valuation of over one billion dollars.

Serguei Beloussov, the founder and CEO of Acronis, stated the new proceeds will be used to expand the company’s engineering team, build additional data centers, grow its business reach in North America, and pursue acquisitions.

Founded in 2003, Acronis offers cyber protection, solving safety, accessibility, privacy, authenticity, and security (SAPAS) challenges with innovative backup, disaster recovery, and enterprise file sync and share solutions to enterprises in hybrid cloud environments and on-premises. The company claims that its Acronis Cyber Platform protects all the data in any environment, including cloud, physical, virtual, mobile workloads, and applications.

Speaking on the new investment, Serguei Beloussov said, “We are excited about Goldman Sachs’ investment. In 2018, Acronis achieved 20% business growth, and in 2019 it is on track for over 30% growth with the Acronis Cyber Cloud business growing by over 100%. Recently we announced the Acronis Cyber Platform, enabling third-parties to customize, extend, and integrate our cyber protection solutions to the needs of their customers and partners. The investment round led by Goldman Sachs will help us to fast-track the product development through acquisitions of companies and additional resources, and accelerate the growth.”

“We are excited to invest in Acronis at this stage of rapid growth,” said Holger Staude, Vice President GS Growth. “The traditional backup and data protection market is changing due to an innovative solution delivered efficiently by Acronis Cyber Protection through a vast channel of service providers.”