Home Blog Page 300

State-backed Chinese attackers target multiple German-based companies

BlackMatter ransomware

A number of firms in Germany have confirmed that they have been targeted by a state-backed Chinese hacker group. A report from public broadcaster ARD stated that hackers targeted blue-chip industrial firms like BASF, Siemens, Henkel, and Roche, the Reuters reported.

Alongside the German firms, the other companies including hotels group Marriott, airline Lion Air, conglomerate Sumitomo, and chemicals group Shin-Etsu were also targeted by the hackers. However, the companies clarified that no sensitive information was compromised. According to ARD, the hackers used a malware named Winnti, which allows attackers to remotely access a victim’s network systems.

Earlier, Chinese hackers targeted WhatsApp users in India to extract their personal data. The Indian Army took to the microblogging site, Twitter to urge users to use WhatsApp with caution. Indian Army’s official handle, the Additional Directorate General of Public Interface (ADGPI) also posted a video that said, “Stay cautious, stay alert, stay safe! The Chinese were penetrating the digital world.”

The video urged users to save contacts by name and to constantly keep a vigil on all WhatsApp groups and numbers. “Chinese are using many platforms to penetrate your digital world. WhatsApp groups are a new way of hacking into your system. Chinese numbers barge into your groups and start extracting all the data,” it advises. “If you change your mobile number, inform the group admin; if you change your SIM card, destroy it completely,”

Smartphones manufactured by Chinese firm Xioami were under the radar of the Indian Army and the Indian Air Force over security hazards. As per reliable inputs, a number of Android/iOS apps developed by Chinese developers or having Chinese links are reportedly either spyware or another malicious ware. Use of these apps by our force personnel can be detrimental to data security having implications on the force and national security.

VPN: A volatile market with high potential

Nearly 800,000 SonicWall VPNs Were Affected Due to Portal Critical Flaw

Unlike the regular run-in-the-mill virtual private networking (VPN) that people use to masquerade their location or to access sites that are forbidden in the region, VPN for enterprises plays a huge part in making sure the function of a company is seamless even when employees are accessing the servers through remote location.

The market for VPN is poised for an incredible growth, with several surveys forecasting that VPN revenue is set to exceed $54 billion by 2024 from up from $17 billion in 2018. According to a study, VPN market is propelled by the rising number of advanced and complex cybersecurity threats. The VPN often provides a safe and cost-effective solution to protect the company networks.

That being said, critical flaws in any of the vectors in VPN may take a toll on the entire business landing them in jeopardy. Several security experts are talking about an apparent death of VPN. According to Chase Cunningham, an analyst with Forrester. “The broader topic is the death of the VPN,” he said to Dark Reading. He also added that around that there has been a $250 million worth of acquisitions over the last one year solely intended to get rid of VPN technology as a discrete market.

“Security people are good with security technology … the general population is not,” Cunningham says. “Exploitation occurs on the user side of the equation with bad passwords, logins, etc.”

Recently, the security flaws in corporate VPNs providers Palo Alto Networks, Fortinet, and Pulse Secure put the entire future of VPN in jeopardy. The flaws could have enabled attackers to steal confidential information from the company’s network.

Tsai and Meh Chang who were the researchers who first noticed the bugs stated that the SSL VPN from Palo Alto also suggested that anyone can silently break into the company’s network without the need for a username or password. “About the vulnerability, we accidentally discovered it during our Red Team assessment services. At first, we thought this is a 0day. However, we failed reproducing on the remote server which is the latest version of GlobalProtect. So we began to suspect if this is a known vulnerability. We searched all over the Internet, but we could not find anything. There is no public RCE exploit before[1], no official advisory contains anything similar and no CVE. So, we believe this must be a silent-fix 1-day!” they wrote.

“A few SSL VPN vendors dominate the market. Therefore, if we find any vulnerability on these vendors, the impact is huge,” Tsai told TechCrunch. The vulnerability only affected older versions of the software, but is still widely used including ride-sharing firm Uber.

Amid these trends over corporate VPNs, the scenario isn’t all that rosy at user-end VPNs. The major problems users face are slow speed with only a few servers, old cracked security protocols, weak encryption, among others.

Users can test drive VPN trial from providers which addresses all the problems we discussed above in the same order. We are talking about companies that have over time shown its prowess in the space of user and corporate VPNs. These have extreme speeds with over 800+ servers, have one most advanced security protocols and unbreakable encryption, have a strict no logs policy, doesn’t collect any user data, helps to overcome bandwidth limitations, blocks ads, trackers, and malware and even provides 24/7 live customer support.

European authorities launch initiative to bring young hackers out of jail

Facebook Indicts Two Developers for Scraping Users’ Data, Europol

With an aim to reduce the number of young hackers ending up in jail, the Police in the United Kingdom and the Netherlands have launched a new legal intervention campaign dubbed ‘Hack_Right’. The new initiative, which is rolled out in the UK, is intended to educate 12-23-year-old hackers, who are committed cybercrimes due to ignorance.

According to the European authorities, the new legal intervention campaign has already helped 400 young hackers in the UK, the Cyberscoop reported.

“We do this … to get out and find them and get them into computing clubs before we have to investigate someone and lock them up,” said Gregory Francis, acting national prevent lead at the National Cyber Crime Unit. “Cybercrime is not a law enforcement problem. It’s a societal problem.”

As per the new legal campaign, instead of charging legal penalties, the hackers are offered a cyber-community-service option that consists of 10 to 20 hours of ethical computer training. Also, the police officials put them in touch with security professionals from the tech industry who will help them with their career prospects to play by the rules.

In order to qualify for the campaign, the suspects must confess to their crimes and should be willing to change their criminal path.

Different countries follow different approaches to cybercriminal enforcement. Recently, Bulgarian police released a 20-year-old hacker who is accused of hacking the country’s National Revenue Agency, and accessing information about 5 million people. The police arrested the suspect on July 17,2019, and has launched an investigation to know the damage occurred due to the incident. “We have a suspect that has been detained,” the Bulgarian police said in a statement.

It’s believed that the compromised data belonged to the country’s National Revenue Agency (NRA), a department of the Bulgarian Ministry of Finance. Boyko Borissov, the Bulgarian prime minister, called an emergency meeting after the cyber-attack, the Capital.bg reported.

Vladislav Goranov, the Finance Minister of Bulgaria, said the stolen data included names, personal data, personal identification numbers, addresses, and financial earnings of individuals and companies. Goranov stated their government has requested help from the European Union’s cybersecurity agency.

Israel-based cybersecurity startup Cervello secures $4.5 Million

Railway cybersecurity startup Cervello Ltd recently secured $4.5 million in a seed funding round led by Tel Aviv-based North First Ventures of Israel and Toronto-based Awz Ventures, along with the participation from the founder of Israel-based Comsec Consulting Ltd., Nissim Bar-El.

Founded in 2017, the Israel-based Cervello develops a service that monitors the operational networks of rail and metro systems to detect potential threats.

Cervello helps rail and metro companies avoid safety incidents and service disruptions caused by cyber-attacks. The company claims that its security platform is designed to meet the unique cybersecurity needs of the rail industry. Cervello said that it detects cyber threats in the signaling and control networks, trackside and onboard, and assisting rail and metro companies in preventing cyber-attacks.

“The Cervello Dashboard provides operators with full visibility of their railway signaling systems and critical assets and alerts on cyber incidents in the day to day operation. Cervello’s technology can either added to support existing rail equipment or installed during the manufacturing and design process,” CEO Roie Onn said in a statement.

In a similar funding round, Cylus, the rail and metro cybersecurity services provider, recently raised $12 million in a Series A funding round to accelerate its business expansion. The funding round was jointly led by the company’s existing investors, Magma Venture Partners and Vertex Ventures, including several new investors Cyient, Cerca Partners, GlenRock, Leon Recanati’s private investment company, and FollowTheSeed. The round was also joined by former Chancellor of Austria, the Blue Minds Company managing director Christian Kern, and Cylus’ previous backers Zohar Zisapel and SBI.

The Israel-based startup stated the new investment will be used to push its activities in the European Union, the U.S., and in the Asia-Pacific region. Cylus also planning to support its research and development, strengthen its team of cybersecurity, and rail experts.

Cybersecurity startup Securicy Data Solutions raises $1.2 million

Startup Investment

Securicy Data Solutions Ltd recently secured $1.2 million in funding from private equity firms and angel investors, including Hub Angels, Panache Ventures, and Concrete Ventures. The Cape Breton based cybersecurity startup stated the new proceeds will accelerate the company’s marketing, sales, and improvement of its software-as-a-service product line.

Founded in Sydney in 2016 by Darren Gallop and Laird Wilton, Securicy offers web-based tools to small and medium-sized businesses to easily navigate the process of implementing, maintaining, and demonstrating compliant cybersecurity practices.

“Securicy built up a “fairly vast network” of contacts within the information technology industry, particularly due to four months spent in Boston at a top-tier global startup accelerator called Techstars. Securicy was one of 10 tech companies that were invited to join the Techstars 2018 cohort, joining a select club of businesses that gained valuable expertise from leading mentors in the tech world,” said Darren Gallop, the co-founder of Securicy Data Solutions. “We are a Techstars alumni company and have spent a good chunk of our year last year in Boston and in that (ICT) ecosystem. We focused a lot of attention on meeting investors in that community.”

“The Securicy leadership team has the unique experience of living in the startup space, feeling the pain of compliance and developing a simple, pragmatic, and automated approach to solving that pain,” David Verril, the founder of Hub Angels said in a statement. “That introduced me to the problem and got me privy to the importance of data security for companies. It was probably a year or so after that, that I was learning more and studying security in general that I had the idea for Securicy,” he said.

Only 50 percent of organizations are ready to handle cyberattacks: Survey

cyber attack

Less than half of organizations are equipped with proper cyber defenses to thwart the possible cyber threats. According to the information security firm CyberArk, only 50 percent of the companies have a security strategy in place for DevOps, IoT, and other technologies to cope with security incidents.

More than 50 percent of organizations stated that attackers can break into their network systems and 28 percent of them stated they’ve planned security strategies in the next two years, according to CyberArk’s survey.

The survey findings, from the interviews conducted across various organizations, stated that 78 percent of organizations believe that hackers are the real threat to their critical assets, 46 percent companies stated organized crimes are the reason, and  60 percent of the companies consider their security risks are from external attacks, including phishing and ransomware.

“Organizations are showing an increasing understanding of the importance of mitigation along the cyber kill chain and why preventing credential creep and lateral movement is critical to security,” said Adam Bosnian, executive vice president, global business development, CyberArk. “But this awareness must extend to consistently implementing proactive cybersecurity strategies across all modern infrastructure and applications, specifically reducing privilege-related risk in order to recognize tangible business value from digital transformation initiatives.”

Security researchers stated that Phishing and Ransomware attacks are the most reported types of cyber-attacks on financial services firms. According to the Audit and Consulting firm RSM International in the United Kingdom, around 819 cyber incidents were reported by Financial services firms to the Financial Conduct Authority (FCA) last year.

RSM said that Retail Banks were the most frequently affected by cyber-attacks (486 security incidents) followed by wholesale financial markets (115 attacks), and retail investment firms (53 incidents). In 2018, financial firms reported around 93 cyber-attacks, in which half of these (48 attacks) were phishing attacks while 20 percent (19 attacks) were ransomware attacks.

RSM said the sudden increase in the companies reporting security incidents was due to the introduction of the European Union’s General Data Protection Regulation (GDPR) laws that took effect last May.

ZeroNorth and CyberProof Join Hands to Strengthen Infrastructure Risk Management

U.S. and Australia to Jointly Develop Cyber Training Platform

ZeroNorth, a provider of orchestrated risk management services, recently partnered with cybersecurity company CyberProof to provide customers with comprehensive solutions and services for managing risk across applications and infrastructure.

The ZeroNorth platform accelerates and scales infrastructure risk management continuously orchestrates the discovery and remediation of vulnerabilities. The company claims that its orchestration platform detects and adapts to changing code, applications, and identifies potential threats. CyberProof provides cybersecurity services and platform provides organizations a faster way to prevent security threats and create a secure digital ecosystem.

The new alliance integrates CyberProof’s security orchestration automated response (SOAR) with the ZeroNorth orchestrated risk management platform to provide an end-to-end solution for assessing, planning, and implementing vulnerability management across the organization.

“Digital transformation is redefining organizations in all industries into software-centric businesses. As this happens, reconciling the need for continuous development and delivery of software with security has become a major challenge. Through this partnership, CyberProof and ZeroNorth can now deliver customers complete visibility into risks and the ability to quickly detect, respond and remediate threats that pose a risk to their business,” said Tony Velleca, CEO of CyberProof. “By partnering with ZeroNorth, we can provide customers a single pane of glass for understanding and addressing risk end-to-end. No other product we’ve seen has the same capability of supporting risk and vulnerability management across both applications and infrastructure.”

“From code commit to build to deploy – across data centers, virtual environments and the cloud – customers need the ability to understand and address risk across applications and infrastructure. As an organization that works every day to help customers navigate the risks of digital transformation, Cyberproof understands this just as well as anyone,” said Ernesto DiGiambattista, ZeroNorth’s CEO and founder. “Together, we’re able to strengthen Cyberproof’s solutions and services to help joint clients take significant steps towards improving their security posture so they can focus on the competitive advantages of their digital transformation while knowing that the risks are managed.”

Attackers using fake Office 365 Site to inject Trickbot Trojan

Hackers Target Office 365 Users with SurveyMonkey Phishing Campaign

Cybercriminals are using popular online sites or services to spread malware and exploit, a research claimed. Hackers are using phony Office 365 website to trick users into downloading the TrickBot password-stealing Trojan masked as Chrome and Firefox browser updates, the Bleeping Computer reported.

The fake Office 365 site was found by independent security research team MalwareHunterTeam. The security team explained that the fake site gives a pop-up stating that the user’s browser needs an update. When the user clicks on the update option, an executable named upd365_58v01.exe gets downloaded that installs the TrickBot information-stealing Trojan on the computer to exploit.

“For example, when using Google Chrome to visit the page, it will show an alert titled “Chrome Update Center” and state that you are using an older version of Chrome that could lead to loss of data and browser errors,” the team said in a statement.

Microsoft recently discovered a security vulnerability that exists in its Outlook for Android app. In its security advisory, Microsoft stated that the older versions before 3.0.88 of Outlook for Android carries a spoofing vulnerability that allows attackers to perform cross-site scripting (XSS) on mobile devices.

The security flaw, named as CVE-2019-1105, could be exploited by attackers by sending a specially crafted email message to the victims. Once compromised, the attackers can perform XSS attacks and run malicious scripts. Microsoft stated the flaw was reported by multiple security researchers, including Bryan Appleby from F5 Networks, Sander Vanrapenbusch, Tom Wyckhuys, Eliraz Duek from CyberArk, and Gaurav Kumar. The company also clarified that it has mitigated the flaw and notified the users to update the Outlook applications on their devices.

Recently, Microsoft issued an alert to several users of over its mail platform Outlook hack. In a wordy notification, it stated hackers may have accessed data sent by several users on the platform between January 01, 2019, and March 28, 2019.

 

Facebook set to pay $5 billion fine for privacy violations

Facebook

Facebook is set to pay the largest fine imposed on a technology company by the Federal Trade Commission. The social media giant has been slapped with a massive $5 billion fine for allegedly violating privacy practices and mishandling user data during the infamous Cambridge Analytica scandal and other privacy breaches.

The FTC ordered Facebook to adopt new policies for protecting users’ data and expand these policies across Instagram and WhatsApp. Facebook has also been asked to create a new privacy committee that will have independent board members. Moreover, a third-party assessor approved by the FTC will be brought on board to conduct biennial assessments and monitor Facebook’s privacy-related decisions.

“The Order imposes a privacy regime that includes a new corporate governance structure, with corporate and individual accountability and more rigorous compliance monitoring,” the FTC stated. “This approach dramatically increases the likelihood that Facebook will be compliant with the Order; if there are any deviations, they likely will be detected and remedied quickly.”

The agreement has curbed Facebook CEO Mark Zuckerberg’s decision-making in privacy and security matters. “The Order significantly diminishes Mr. Zuckerberg’s power – something no government agency, anywhere in the world, has thus far accomplished,” the statement said.

Responding to the fine, Facebook wrote in a blog post that the agreement “will require a fundamental shift in the way we approach our work and it will place additional responsibility on people building our products at every level of the company. It will mark a sharper turn toward privacy, on a different scale than anything we’ve done in the past.”

Cost of Data Breach reaches Rs 12.8 crore in India: IBM

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

A recent survey from technology giant IBM revealed that the average cost of a data breach in India has grown 7.29 percent to reach Rs 12.8 crore from Rs 11.9 crore last year. According to the survey report dubbed Cost of a Data Breach 2019, the Per capita cost for a stolen record raised to Rs 5,019, which is an increase of 9.76 percent when compared to the last year.

The survey findings, which are based on in-depth interviews with 507 companies around the world, highlighted that the root cause for 51 percent of data breaches was malicious or criminal attacks, 27 percent of breaches due to technical issues, and human error led to 22 per cent of breaches in India.

“Data breaches can cause devastating financial losses and affect an organization’s reputation for years. From lost business to regulatory fines and remediation costs, data breaches have far reaching consequences. The annual Cost of a Data Breach Report, conducted by the Ponemon Institute and sponsored by IBM Security, analyzes data breach costs reported by 507 organizations across 16 geographies and 17 industries,” IBM said in a post.

IBM stated that they’ve surveyed the cost of data breaches in different industries which suffered a data breach last year. The survey also discovered that data breaches in the U.S. are more expensive, costing $8.19 million, then the average of the companies worldwide.

Security researchers have revealed that the Indian manufacturing industry is currently facing severe cybersecurity risks. According to a survey from cybersecurity firm Seqrite, the manufacturing sector in India accounted for more than 27 percent of the threats detected between January and March 2019. Seqrite, an enterprise arm of Quick Heal technologies, is a specialist provider of endpoint security, network security, enterprise mobility management, and data protection solutions.

In its research report, named Threat Report Q1 2019, Seqrite highlighted that many of the IoT devices used by manufacturers like sensors, barcode readers, quality control systems, inventory management solutions, etc. come with minimal security, giving an avenue to cybercriminals to attack and infiltrate the enterprise network.