Home Blog Page 290

Chicago Brokerage Slammed by the U.S. Commission with US$ 1.5 Million Fine

U.S. Commodities Futures Trading Commission

Phillip Capital (PCI), a Chicago-based futures brokerage, was fined US$ 1.5 million for lack of cybersecurity measures. According to an order from the U.S. Commodities Futures Trading Commission, the brokerage firm failed to disclose the cyber breach to its customers in a timely manner.  The order also finds that PCI failed to supervise its employees with respect to cybersecurity policy and procedures, a written information systems security program and customer disbursements.

“Cybercrime is a real and growing threat in our markets,” said CFTC Director of Enforcement James McDonald.  “While it may not be possible to eliminate all cyber threats, CFTC registrants must have adequate procedures in place—and follow those procedures—to protect their customers and their accounts from potential harm.”

Multiple security incidents were reported by various brokerage firms in recent times. Crypto brokerage platform, Coinmama, recently notified users that it suffered a security breach which affected around 450,000 users’ emails and hashed passwords. The company stated that a few unknown intruders compromised customer data and kept for sale on a dark web registry.

Coinmama provides a cryptocurrency exchange platform for trading digital currency globally. The security professionals at Coinmama revealed the compromised data belonged to the users who registered until August 05, 2017. Coinmama also explained the security issue affected 30 companies and a total of 841 million user records.

Coinmama established an Incident Response Team to identify the nature of the intrusion. The company also took additional security measures to thwart further loss and notified the affected users to reset their passwords upon next login and urged all other users to verify that their passwords are unique and strong.

Uber rewarded a security researcher with US$ 6500 bounty for spotting a bug

bounty for DarkSide Ransomware Group, Microsoft Offers $100,000 Bounty

Uber has paid US$ 6500 to an Indian security researcher after he discovered a bug in its API requests.  According to the official statement, the bug would have allowed attackers to take over a user’s account.

The researcher, named Anand Prakash, stated the bug was an account takeover vulnerability on Uber’s API applications which were occurred due to missing an endpoint in the authorization process.

According to the researcher, the flaw enables hackers to compromise any user’s Uber account by sending the users’ UUID in an API request to hijack accounts. The researcher explained that the flaw also affected its partners and Uber Eats users. Uber fixed the vulnerability on September 9, 2019, after the researcher reported the issue on April 19.  The researcher also asked Uber for public disclosure of his discovery.

Recently, another Indian-based security researcher discovered a bug in Instagram’s Account Recovery Process that could have allowed attackers to break into users’ accounts. The Facebook-owned Instagram rewarded the researcher with a bounty of $10,000 for reporting the vulnerability.

The researcher said that he found the vulnerability while investigating how the account recovery process of the photo-sharing application allows the user to regain access to your account when you’ve forgotten the password. According to the researcher, Muthiyah, the Instagram server uses device ID as a unique identifier to validate password reset codes. “When a user requests a passcode using his / her mobile device, a device ID is sent along with the request. The same device ID is used again to verify the passcode,” Muthiyah said in a statement.

The researcher found that the same device ID can be used to request passcodes for multiple Instagram accounts of different users, allowing an attacker to breach multiple accounts with a single device ID.

Unprotected Database Leaks 198 Million Car Buyers’ Personal Data

Lapse in Pfizer’s Security Exposes PII of U.S. Prescription Drug Users

An unprotected database exposed around 198 million personal records of car buyers’ online. Jeremiah Fowler, a security researcher at Security Discovery, stated that he discovered a database, that contained 413 GB of data, that was left online without any password protection.

“On August 19th I reported a non-password protected database that contained a massive 413GB of data and a total of 198 million records. The most shocking part was that I had seen this dataset several times in the previous weeks but was unable to identify the owner. It was clear that this was a compilation of potential car buyers wanting more information, loan and finance inquiries, vehicles that were for sale, log data with IP addresses of visitors, and more,” Jeremiah said in a post.

The researcher found that the leaky database is an Elastic database that contained a compiled list of potential car buyers who requested for information like, vehicles for sale, loan and finance inquiries, log data with IP addresses of visitors, and more. Upon further investigation, Fowler discovered that the car buyer marketing database is maintained by an agency dealerleads.com. The database was taken down by DealerLeads after Fowler reported the issue.

The exposed data included, names, phone numbers, email addresses, street addresses, ports, pathways, storage info, and other sensitive information which could be exploited by cybercriminals, according to Jeremiah Fowler.

“I initially thought this database could be a directory, but there would not be such detailed information or back-end records. Another concern was that there were so many different websites that it almost seemed illogical that they could be owned by one organization. Only by manually reviewing multiple domains did I discover that they are all linked back to dealerleads.com. I immediately reached out to them regarding my discovery on Aug 19,” Fowler stated.

Shape Security reaches US$ 1 Billion valuation with US$ 51 Million Funding

startup

Anti-fraud startup Shape Security recently raised US$51 million in a funding round led by C5 Capital along with existing investors, including Focus Ventures, JetBlue Technology Ventures, Top Tier Capital Partners, EPIC Ventures, Kleiner Perkins, HPE Growth, and Norwest Ventures Partners. The California-based startup has reached the US$ 1 billion valuation mark with the latest investment.

Shape Security stated the new proceeds will accelerate the company’s product development and also support its business expansion in North America.

Headquartered in Santa Clara, California, Shape Security helps enterprises prevent automated and imitation attacks. It provides omnichannel protection for web applications, mobile applications, and API interfaces. The company claims that its Fraud Prevention Platform detects and blocks over 2 billion fraudulent transactions daily.

Commenting on the new investment, Derek Smith, co-founder, and CEO of Shape Security said, “This investment will help us scale our international operations and fuel our AI development. Our new and returning investors, coupled with our continued track record of growth, underscore our vision to protect all enterprises from fraudulent Internet transactions. Shape’s growth and product innovation are unlike anything we’ve seen in enterprise security.

“Shape Security is a pioneer and a proven leader in the war against all types of fraudulent internet transactions,” said Ted Schlein, partner at Kleiner Perkins. “The company’s technology is unmatched in its ingenuity and effectiveness. Our investment speaks to the confidence we have in its unique solution, and the vision of its leadership team.”

“Shape already protects Internet users at scale by detecting and blocking up to 2 billion fraudulent transactions daily. This new injection of capital will further the company’s global market penetration,” Schlein added.

Researchers Uncover Espionage Operation using ‘Simjacker Vulnerability’

SIM Swapping

Security researchers at AdaptiveMobile Security, a Cyber-Telecoms Security company, uncovered a new undetected vulnerability that’s being exploited by attackers for targeted surveillance of Android and iOS mobile phone users. It’s said that the flaw is linked to a technology embedded on SIM cards.

The vulnerability, dubbed Simjacker, is used to hijack SIM cards by sending a text message to target devices. When exploited, the vulnerability activates specific SIM card instructions which then allows hackers to spy on the victim’s active location, make fraudulent calls, force-install malware, send fake messages, and steal critical information.

Researchers stated cybercriminals have obtained location information from over 1 billion mobile devices globally, by exploiting the Simjacker vulnerability, without users’ consent. It’s believed that the attackers originated from a surveillance company that works with government agencies to monitor individuals who bypass signaling protection.

According to AdaptiveMobile Security, the vulnerability potentially impacted countries in North and South America, including the Middle East, West Africa, Europe, and any part of the world where this SIM card technology exists.

While commenting on the discovery of the critical flaw, Cathal McDaid, CTO at AdaptiveMobile Security said, “Simjacker represents a clear danger to mobile operators and subscribers. This is potentially the most sophisticated attack ever seen over core mobile networks. It’s a major wake-up call that shows hostile actors are investing heavily in increasingly complex and creative ways to undermine network security. This compromises the security and trust of customers, mobile operators, and impacts the national security of entire countries.”

“Simjacker worked so well and was being successfully exploited for years because it took advantage of a combination of complex interfaces and obscure technologies, showing that mobile operators cannot rely on standard established defenses. Now that this vulnerability has been revealed, we fully expect the exploit authors and other malicious actors will try to evolve these attacks into other areas,” McDaid added.

Fraud Campaign Defrauding Online Ticket Vendors Exposed: Report

e-skimming attacks , Chinese e-commerce scammers

vpnMentor, a popular VPN review website, recently exposed a massive criminal operation that has been defrauding Groupon and other major online ticket vendors since 2016.

vpnMentor’s research project, led by security researchers Noam Rotem and Ran Locar, discovered a breach in a massive database that contained 17 million records and 1.2 terabytes of data. The breach seemed to give access to personal details of anyone purchasing tickets from a website using Neuroticket—a mailing system linked to the database.

The researchers revealed the data breach was the result of a vulnerability in a ticket processing platform used by Groupon and other online ticket vendors. The investigation worked on many similar database breaches, and certain aspects of this one didn’t add up.

“The database belonged to a sophisticated criminal network. Since 2016, they have been using a combination of email, credit card, and ticket fraud against Groupon, Ticketmaster, and many other vendors. Groupon has been trying to shut this operation down ever since it started, but it has proven resilient. Working together with Groupon’s security team, we may now have the key to closing the criminal operation down once and for all,” the research team said.

According to the report, 90 percent of the database involved records from popular coupon and discounts website Groupon, totaling 16 million altogether. This can be explained by Groupon’s newsletters and promotional emails, sent out up to 5 times per day, per customer.

Two of the internet’s biggest ticket vendors, Ticketmaster & Tickpick, were also affected in the incident. The data leak also included many small, independent events spaces, and venues across the U.S., including Pacific Northwest Ballet, Joffrey Ballet, Kansas City Ballet, Dr. Phillips Center in Orlando, Fox Theatre in Georgia, Ballet Austin, and Colorado Ballet, Denver.

Commenting on their discovery, vpnMentor said, “We found this data leak as a part of our ongoing, large-scale web mapping project. Ran and Noam scan internet ports looking for known IP blocks and use these blocks to find holes in a company’s web system. Once these holes are found, the team looks for vulnerabilities that would lead them to a data breach. When they find leaked data, they use several expert techniques to verify the database’s identity.”

“As ethical hackers, we normally reach out to owners of the database or websites affected and outline the security flaws we discover. In this case, we decided to contact Groupon and the other ticket vendors,” vpnMentor added.

Cybersecurity Startup Cyware Secures US$ 3 Million

Startup

Threat intelligence and cyber fusion product-based security startup Cyware Labs, recently raised US$ 3 million in a seed funding round led by Emerald Development Managers. The New-York based startup stated the new funding will support its research and product development, accelerate sales and marketing activities, and expand its global reach.

Headquartered in the U.S.,Cyware offers a full-stack of innovative cyber solutions for all-source strategic and tactical threat intelligence sharing, cyber fusion, and orchestrated threat response. Cyware claims that its enterprise solutions enable organizations to develop proactive cyber defense capabilities, operational threat intelligence, and quickly respond to and manage security threats in real-time.

“Threat response solutions have traditionally focused on the attack at hand, without giving much thought to other key aspects of threat information available that would allow an organization to turn an attack on its head. The barometer of responding to attacks has changed and focusing on attacker’s tactics, malware, and vulnerabilities is equally critical,” said Cyware Labs CEO and Co-Founder, Anuj Goel. He further added, “Knowledge is power, and our enterprise product line has successfully broken down the barriers in automated threat intelligence sharing and threat response to promote a proactive, collaborative response to cyber-attacks.”

Charles Collins, Managing Director at Emerald Development Managers, adds, “We support innovative cybersecurity companies that are taking a new lens to problems currently baffling the industry. The work Cyware is doing to revolutionize current threat response practices is pivotal, and we are excited to join them on their mission to bolster threat intelligence sharing, cyber fusion and orchestrated a response.”

Experts say Prioritization is essential to address growing Vulnerabilities

actively exploited vulnerabilities, Vulnerabilities, risk-based vulnerability management

By Brian Pereira

The number of vulnerabilities is increasing at an alarming rate, making it increasingly difficult for enterprises to identify the ones that will impact their business. According to the Vulnerability Intelligence Report 2018, from Tenable Research, 16,500 new vulnerabilities were published in 2018. As per the National Vulnerability Database (NVD), there were 15,038 new vulnerabilities recorded in 2017. Moreover, in 2016 the number was 9,837. So the number of vulnerabilities increased by 53 percent in a single year. Tenable Research also mentions that, on average, enterprises find 870 vulnerabilities per day across 960 IT assets.

With limited resources and the shortage of skills, enterprises cannot address this massive volume of vulnerabilities.

“Out of 100 vulnerabilities that I have in my… how do I identify those ten incidents, vulnerabilities, findings that I should be addressing right away?” asks Prateek Bhajanka, Principal Analyst, Gartner. “The prioritization of vulnerabilities to be addressed should be done on the basis of the risk; not on the basis of other factors, like what the management thinks, or the default suggestions in the solution/tool. We should be taking into account the risk posed to the organization. We should be spending more time on the activities that have a higher impact (on the business),” he said.

Speaking exclusively to CISO MAG, Robert Huber, CSO of Tenable said the attack surfaces are expanding so broadly, the ability to gain visibility into that attack surface is becoming difficult. He said automation is the only way to tackle the growing volume of vulnerabilities. Tenable is proposing a technology for this called predictive prioritization.

“We all know that you can’t patch everything–and if you patch everything it probably won’t work anymore! So I need to prioritize the vulnerabilities based on the severity of the threat and on what’s important to the business. Usually, from a revenue or loss perspective as well,” said Huber.

Huber has more than 20 years of information security experience across financial, defense, and critical infrastructure sectors. At Tenable, he oversees the company’s global security teams including physical, product and information–working cross-functionally to reduce risk to the organization and its customers. Huber is also an active member of the U.S. Air National Guard serving in a cyber-operations squadron.

“There were 16,000 vulnerabilities last year, and 59 percent are rated high and above. That’s still too many for somebody to feasible patch or address in their organization. If we apply predictive prioritization to the 59 percent, we reduce that down roughly 90 percent. So what’s left is a manageable amount of vulnerabilities that you could realistically address,” he said.

Read the complete interview with Robert Huber in the September issue of CISO MAG.  

Hackers Exposed 2.8 Billion Consumer Data Records in 2018: Survey

personal data collection, Personal data. Data Privacy

A recent survey revealed that cybercriminals exposed 2.8 billion consumer data records in 2018, that cost more than US$654 billion to enterprises in the United States.

According to a report, from identity and access management firm ForgeRock, around 97 percent of the stolen Personal Identifiable Information (PII) included names, residential addresses, date of birth details, and Social Security numbers.

The report, named U.S. Consumer Data Breach Report 2019, revealed that enterprises worldwide invested more than US$ 114 billion on security products and services in 2018, which is an increase of 12.4 percent when compared to 2017.

Healthcare organizations have become an easy target for attackers, as they hold huge sensitive information of their patients, representing 48 percent of breaches in 2018. While Banking, Insurance, and other Government entities were the second victimized sectors comprising 20 percent of breaches in 2018.

“No industry is safe from cyberattacks, and the healthcare sector is particularly vulnerable to these hugely damaging breaches,” the report stated.

“Cybercriminals today are highly sophisticated, executing a diverse range of security attacks at a greater volume and scale than ever before. While enterprises continue to invest heavily in information security products and services to defend against these threats, they are struggling to neutralize cybercriminals’ unending appetite for consumer data,” the report added.

A similar kind of research revealed that healthcare organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations. The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

Privacy by Design – Broadening the Scope Beyond the SDLC

privacy

By Robert Pellerin

We all want our personal data to be private and unseen by other eyes, right? Of course. It is also critically important that we build a culture within our organizations to protect client and customer data.

While Privacy by Design (PbD) has been around since the 1990s and many organizations have adopted its principles, the “newness” of the EU’s new General Data Protection Regulation (GDPR) and other privacy regulations may promote an internal focus on the Software Development Life Cycle or SDLC to those new to PbD. In this article I’ll explain what PbD is and offer a perspective for implementation scope that sometimes gets overlooked in the focus on “coding and development” – PbD isn’t just about the SDLC.  PbD is a good idea and a good practice in all aspects of a business.

When considering data privacy and protecting personal data, processes should be embedded / built-in across all aspects of the business and not geared only toward complying with regulations. We all need to check our boxes, but by building in data privacy concepts through employee security awareness training and client and customer data privacy concept discussions and training, we can begin to build this into culture, providing benefits that are deeper than doing something because the Chief Information Security Officer (CISO) or Chief Privacy Officer (CPO) said so.

What is Privacy by Design?

It is a concept for being proactive about data privacy and embedding the processes and controls necessary to protect personal data “end-to-end” or throughout the lifecycle of a product or service.  While Privacy by Design has recently again come to the forefront due to GDPR it should be a commonsense principle. Privacy by Design came from Dr, Ann Cavoukian who while she was the Information ad Privacy Commissioner of Ontario, Canada created the 7 foundational principles for Privacy by Design:

#1 – Proactive not reactive; preventative not remedial

A well designed PbD practice will anticipate and prevent invasive events before they happen.

#2 – Privacy as the default setting

Privacy by default means that a data subject should not need to do anything in order to keep their personal data private as settings should be configured (for example) such that protection is “on” unless the data subject requests or makes a change.

#3 – Privacy embedded into design

Embed privacy settings into the design and architecture of information technology systems and business practices instead of implementing them after the fact as an add-on.

 #4 – Full functionality – positive-sum, not zero-sum

There should be no trade-offs, for example, privacy vs. security or security vs advanced functionality.

#5 – End-to-end security – full lifecycle protection

Continuous protection of privacy across all aspects of the business and from the first-time data is collected until it is erased or destroyed.

#6 – Visibility and transparency – keep it open

From technologies to business practices, everything is operating according to transparently stated policies and practices and are independently verified.

#7 – Respect for user privacy – keep it user-centric

Interfaces should err on the side of human-centric and not be overly complex so as to cause ambiguity leading to decisions on the part of users that erode privacy.

PbD is Foundational

Principle # 3 is “Privacy Embedded into Design”:

Embed privacy settings into the design and architecture of information technology systems and business practices instead of implementing them after the fact as an add-on

In other words don’t build it and then go back and sprinkle some privacy on it, build in privacy foundationally like the frame of a house.  You wouldn’t put up the sheetrock, run the wires for electricity, paint and then go back and put in the 2 X 6s to make it strong.

PbD Across the Entire Organization

Once we gain an understanding of the 7 principles it isn’t a stretch to realize that they should apply to anywhere in a business that collects, stores, processes, views, or utilizes personal data in any way. Determine what is being done right now to meet the principles that apply.  Then determine what if any risks to privacy (and security for that matter) are revealed due to a lack of formal adherence to the principles. If the risks are real and can be rated based on probability X business impact, they should be added to your Risk Register.

The PdB program can be set up to ensure that what the business is producing considers privacy at each phase and not just in the SDLC (developing software), but also for artifacts produced such as marketing materials and sales presentations, and in the utilization of tools like CRM, ERP and HR.  PbD should be an over-arching practice based on the 7 principles and woven into business practices until they become normal (cultural).

Beyond the SDLC

In building a new technology module to service your customers, the tech-development lifecycle is a key area, and it may be the best place to start.  However, Marketing, Sales, Human Resources, Finance (Accounting, AP, AR) and IT all can and should operate with PbD in mind.

PbD Principle #1 would apply to the following example:

Anticipate, identify and prevent privacy invasive events before they occur

Marketing attends a conference and has agreed to give a presentation or keynote.  Several of the slides have sample screenshots that contain actual personal data from your customer database. Without a process to clear communications through the offices of the CSO or CPO, that presentation could go out containing the actual customer personal data.  A mistake for sure, but a totally avoidable one.  Having good policies in place that prohibit the sharing of personal data only go so far for a person being driven to make her quarterly goals for qualified leads as the policies are not always top of mind.

A defined process that requires approval before artifacts are made public is a good start.  Using a set of Standard Operating Procedures or SoPs that document the activities necessary to execute on PbD is a practical method to use, and the SoPs can be linked to policy.

Assessment Tools – PIA / DPIA

There are key differences between a Privacy Impact Assessment (PIA) and the Data Protection Impact Assessment (DPIA).  A PIA is more in line with what we’ve been addressing in this article, typically conducted for new business processes, during consideration of an acquisition, and when a new product is being launched prior to going to production.  A DPIA, which is required by GDPR and is an essential part of an organization’s accountability obligations under GDPR, is more concerned with data processing activities that could put the rights of Data Subjects at risk.

Adopting a practice of conducting a PIA for any new product, service business process, organizational change or an artifact that will go public is one way to ensure that security and privacy are embedded and that no new risks to personal data will be created.  While not the only reason to do a PIA / DPIA, a key is that GDPR (and soon other regulations) require that an organization demonstrate Privacy by Design.  The artifacts from a well-orchestrated PIA / DPIA can assist as a compliance tool to show that PbD is taken seriously.

Regulatory Considerations

GDPR

As for GDPR, even if you are a U.S. company that does not sell to the EU and have no offices in the EU, the regulation will apply to you if you have collected, stored and /or processed personal data of an EU resident.  In other words, EU privacy laws are exterritorial, that is, regardless of where a service is provided from, it applies if EU residents are involved.

To ensure that privacy is embedded in the collection, use, and disclosure of personal data, organizations should also consider appointing privacy champions to business teams.  Privacy champions can assist with the facilitation of PbD, by considering data minimization and purpose limitation in the development of new products and services.

To conclude, any organization that is collecting, storing or processing personal data takes on a basic responsibility and requirement that if that data is personal data, the organization should practice Privacy by Design (PbD) principles and Privacy by Design should be included in any business process, product or service that must touch personal data.

Robert Pellerin is an IT, security and compliance manager and practitioner with over 25 years’ experience, with proficiency in data center, cloud and hybrid models. He has managed IT infrastructure and InfoSec for large corporations and startups. He currently holds CISSP and CISM certifications.