Home Blog Page 305

Cyber-attackers nab $500,000 from Seven & I customers

Credit card scam

Seven & I Holdings Co, a popular convenience store chain in Japan, recently suffered a cyber-attack that resulted in a loss of ¥55 million ($510,000) from its 900 customers. According to the official statement, the attackers hijacked customer mobile payment application, 7pay app, and made fraudulent transactions.

The incident came into light after the customers reported Seven & I that they’ve charged for the goods which were not purchased by them. It’s believed that the incident was occurred due to a security flaw in the design of the 7pay mobile payment app, which is recently launched on July 1.

The Ministry of Economy, Trade and Industry of Japan, has stated that Seven & I Holdings has failed to follow guidelines to prevent unauthorized access and urged the retailer to establish robust security measures. The attackers have exploited the payment application’s poorly designed password reset function to make purchases on customers’ accounts, the Ministry said.

The Seven & I, which operates more than 20,000 stores in Japan, has apologized its customers and promised full reimbursement to the affected customers.

Recently, the Japanese cryptocurrency exchange Zaif has resumed its operations after the cyber-attack that crippled the company in September 2018. In the attack, Zaif lost nearly $60 million in bitcoin, bitcoin cash, and MonaCoin (MONA) from its hot wallets. Following the attack, Zaif suspended its new registration, as well as trading, depositing and withdrawing MONA for the next one month. It also assured refund to users who lost holdings in the breach.

Post the attack, the company entered into a strategic agreement with Fisco Digital Asset Group. As part of the agreement, Zaif would receive a ¥5 billion ($44.5 million) investment in exchange for a share of ownership. The sale of the exchange was part of the efforts of the company to compensate the users who lost MonaCoin in the hack. Now, the affected users have been repaid entirely in their original cryptocurrency while MONA users have been refunded 40 percent in Japanese yen and 60 percent in crypto.  “The yen conversion rate will be 144.548 yen per MONA. Zaif said, “MONA physical trading is scheduled to resume from April 23, 2019.”

Heather Mills breathes sigh of vindication

After a decade long battle, ex-wife of Paul McCartney, Heather Mills and her sister Fiona Mills have won an apology and settlement from Rupert Murdoch’s News of the World. The newsgroup was accused of hacking their phones in a bid to find stories surrounding the celebrities. Following the scandal, Murdoch had to force shut his News of the World newspaper in 2011.

Both the parties received a formal apology in the High Court in Britain. The amount of the settlement was not disclosed. Mills shared she felt “joy and vindication” at the ruling.

“My motivation to win this decade-long fight stemmed from a desire to obtain justice, not only for my family, my charities and myself, but for the thousands of innocent members of the public who, like me, have suffered similar ignominious, criminal treatment at the hands of one of the world’s most powerful media groups,” Mills said in a statement.

Mills is among several other celebrities who became a victim of scandal that ran for nearly a decade and was spearheaded by a news organization. The newspaper was charged with breaking into voicemails of several Brit celebrities in gross violation of privacy.

Ben Silverstone, the lawyer for the defendant stated that News Group Newspapers offered its sincere apologies to the Mills sisters. “The defendant accepts that such activity should never have taken place and that it had no right to intrude into the private lives of Ms Heather Mills or Fiona Mills in this way,” he said.

According to the statement produced before the court, Mills experienced “strange activity with their telephones, journalists, and photographers turning up in unexpected locations,” and the scenario continued “without any apparent identifiable source.”

The publication of news surrounding them “caused a lot of distrust and suspicion” toward their family and friend that someone was “betraying them and selling stories to the press”, the statement read.

Kaspersky partners with INTERPOL to jointly fight Cybercrimes

Kaspersky Lab

Cybersecurity firm Kaspersky and INTERPOL have recently signed a new five-year agreement to jointly fight against cybercrimes around the world. The new contribution agreement signed by Eugene Kaspersky, CEO of Kaspersky, and Tim Morris, Executive Director of Police Service at INTERPOL, will provide human resources support, training, and threat intelligence data on the cybercriminal activities to INTERPOL.

The alliance strengthens the relationship between the two organizations, aimed at preventing cyberattacks. Per the agreement, the cooperation allows Kaspersky to share information about its cyberthreat research and provide necessary assistance to the INTERPOL in their digital forensics.

“With the rise of sophisticated threat actors, collaboration across the ecosystem and the sharing of expertise is more crucial than ever,” said Eugene Kaspersky, CEO of Kaspersky, following the ceremony. “We are excited to continue the partnership with INTERPOL and to empower law enforcers with the information and technology needed to combat cybercrime across the globe.”

A new research from Kaspersky Lab revealed that the number of Distributed Denial of Service (DDoS) attacks increased by 84 percent in the first quarter of 2019 compared to Q4 of 2018. In its research report dubbed DDoS Attacks in Q1 2019, Kaspersky stated that cybercriminals are once again turning to DDoS attacks after a sustained time period.

The Moscow-based cybersecurity firm also revealed that it discovered a considerable growth in the number of attacks that lasted more than an hour. According to the research findings, China reported the highest number of DDoS attacks (67%) while the U.S. reported the second largest attacks (17.17%) and Hong Kong stood third (4.81%).

In a similar research, Kaspersky uncovered AppleJeus, a malicious operation by North Korea’s cyber-hacking outfit ‘Lazarus Group’ to intrude on cryptocurrency exchanges and applications. According to an official report, Kaspersky Lab’s Global Research and Analysis Team (GReAT) discovered the unusual activity of attackers who penetrated the network of an Asia-based cryptocurrency exchange using Trojanized trading software to steal cryptocurrencies. Vitaly Kamlut, the head of GReAT, stated that the cryptocurrency exchange did not encounter any financial losses during the incident.

British Airways faces $230 million GDPR fine

British Airways

The U.K. Information Commissioner’s Office (ICO) may fine British Airways with £183.39 million ($230 million) after the airline failed to protect its customers’ data. The proposed fine relates to a data breach notified to the ICO by British Airways in September 2018, that exposed around 500,000 customers’ personal information.

The ICO said its investigation found that the breach compromised customer details, including login, payment card, name, address, and travel booking information which is collected after being diverted to a fraudulent website. The data breach, which began in June 2018, occurred due to the poor security measures to protect customer information, ICO stated.

“People’s personal data is just that – personal. When an organization fails to protect it from loss, damage or theft it is more than an inconvenience. The law is clear, when you are entrusted with personal data you must look after it. Those that don’t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights,” said the information commissioner, Elizabeth Denham.

Commenting on the proposed penalty Alex Cruz, the chair and chief executive of British Airways, said, “We are surprised and disappointed in this initial finding from the ICO,” “British Airways responded quickly to a criminal act to steal customers’ data. We have found no evidence of fraud/fraudulent activity on accounts linked to the theft. We apologize to our customers for any inconvenience this event caused.”

The British Airways made an announcement regarding the breach on September 6, 2018. It notified its customers that “From 22:58 BST August 21, 2018, until 21:45 BST September 5, 2018, inclusive, the personal and financial details of customers making or changing bookings on our website and app were compromised.” Around 380,000 payment-card details were stolen during the period. The airline has notified the police and investigations are underway. The airlines also assured that it will compensate for all the losses to its customers.

Recently, a research report stated that a hacker group dubbed Magecart were responsible for the data breach on British Airways. According to the security researcher Yonathan Klijnsma from cybersecurity company RiskIQ, the attackers allegedly used a skimming script, a malicious code, designed to steal the data from the British Airways website.

RiskIQ stated that they’ve discovered some similarities in the British Airways situation and the Ticketmaster heist that happened in June. The hackers used a similar approach in both the cases and RiskIQ thinks it could be performed by the same group of hackers, according to the researcher.

Tara AI raises $10 million to accelerate growth

Funding

The AI-based software management platform Tara AI recently secured $10 million in a Series A funding round led by Aspect Ventures along with the participation from Slack Fund, Y Combinator, and Moment Ventures. The California-based startup stated the new proceedings will be used to accelerate growth and expand its business reach globally.

Tara AI help enterprises scope, allocate resources, and build cutting-edge software products by leveraging machine learning models. The company claims that its zz platform predicts how to best build the software, how long projects should take, and who should execute.

“It’s ironic the very teams delivering the world’s most widely used and innovative software, still don’t have a predictive solution for their own product development life cycle. Tara AI is eliminating the status quo of flying blind – which translates into lost time and money – and is creating a new normal where product teams can securely build on best practices and institutional knowledge, enabling them to deliver better software faster,” said Iba Masood, co-founder and CEO of Tara AI.

“With 45% of IT projects running over budget and billions lost due to inefficiencies in product scoping and resource allocations, there is a clear market need for what Tara AI offers. By leveraging the latest techniques in AI and enabling more meaningful collaboration, Tara AI is creating the industry’s first comprehensive platform for product management,” Masood added.

“Tara AI is changing the way software products get built, and we’re thrilled to continue working with them,” said YC Partner Aaron Harris. “98.6% of the workforce is non-technical, including most project managers who are expected to make key estimations on crucial software projects. Tara AI helps teams scope their product builds, and in the process, is creating an entirely new category.”

Australian Postal service is not Cyber Resilient: Australian National Audit Office

The Australian National Audit Office (ANAO) recently stated that Australia Post has failed to manage cyber risks and implement a proper cybersecurity framework, highlighting weaknesses in its risk management activities.

Australia Post is a government-owned corporation that provides postal and retail services, parcel delivery and shipment, domestic and international transaction, payment services, identity verification for passports, and licenses and proof of age cards services in Australia. The company also offers data management and logistics services for public and private businesses in the country.

In its audit report, Cyber Resilience of Government Business Enterprise and Corporate Commonwealth Entities, ANAO recommended Australia Post to implement robust cybersecurity improvement measures and key controls across all its critical assets.

“Australia Post has not fully implemented controls in line with either the Top Four or the four non-mandatory strategies in the Essential Eight,” ANAO said in the report. “Despite the importance of cybersecurity in safeguarding the Australian government’s digital information, there has been ongoing low levels of cyber resilience of non-corporate Commonwealth entities and weaknesses in the regulatory framework for ensuring compliance with mandatory cybersecurity strategies.”

The ANAO stated the Australia Post has failed to fulfil the Essential Eight, a government-mandated  mitigation strategies, which includes application whitelisting, asks entities to patch applications and operating systems, disable Office macros, strengthen user applications, restrict administrative privileges, set up multi-factor authentication, and conduct daily backups.

Australia Post has not met the requirements for ICT controls in its framework, having not implemented all specified key controls, and as a result has rated the overall cyber risk as significantly above its defined tolerance level,” ANAO added.

Recently, the Australian National University discovered a major data breach that affected students’ and University’s sensitive information. According to the University’s Vice Chancellor Brian Schmidt, unknown cybercriminals attacked University’s systems and accessed personal information late in 2018, which was recently discovered by the University authorities on May 17, 2019. It’s believed that the hackers had unauthorized access to 19 years of significant amounts of information related to personal staff, students, and visitors.

The exposed information included names, addresses, dates of birth, phone numbers, personal email addresses and emergency contact details, tax file numbers, payroll information, bank account details, passport details, and student academic records, according to Schmidt.

However, Schmidt clarified that the data like credit card details, travel information, medical records, police checks, workers’ compensation, vehicle registration numbers, and some performance records were not affected by the incident.

Researchers discover multiple flaws in Huawei’s web applications

Huawei

Security researchers from cybersecurity firm Swascan revealed that they have discovered multiple vulnerabilities in Huawei’s Web Application and Servers. Swascan stated cybercriminals can exploit the critical vulnerabilities to access sensitive information. The research team said they’ve identified three vulnerabilities that could impact regular operations if exploited.

According to Swascan, the three discovered flaws in Huawei’s web applications include: CWE-119 (Improper Restriction on Memory Buffer) — The hacker can access the memory and can possibly execute malicious codes. CWE-125 (Out-of-bounds Read) — This flaw allows an attacker to read sensitive information. CWE-78 (OS Command Injection) — The attackers can use this flaw to execute unauthorized commands to crash the software and access the restricted data.

The security team at Swascan informed Huawei counterparts about their discoveries. “In the world of cybersecurity, the principle of collaboration is finally establishing itself. The risks increase by a huge margin every year and this has mandated a cultural as well as technological Paradigm Shift. Our experience with Huawei shows that if these values are correctly understood they can be an additional backbone to create an effective and efficient Cyber Security Framework,” said Pierguido Iezzi, Co-Founder of Swascan.

With an aim to protect the United States communications and computer networks from “foreign adversaries”, President Donald Trump has declared a national emergency over threats against American technology. The president signed an executive order which effectively bars U.S.-based companies from using foreign telecoms, which are believed to pose national security risks, the White House said. The executive order does not name any company, but it’s believed that the move is expected to precede a ban on U.S. firms doing business with the Chinese telecommunications company, Huawei.

According to the White House statement, Trump’s order aims to “protect America from foreign adversaries who are actively and increasingly creating and exploiting vulnerabilities in information and communications technology infrastructure and services”.

“The order gives the secretary of commerce the power to prohibit transactions posing an unacceptable risk to the national security,” the statement added.

Huawei faced a similar issue last year during Australia’s Shadow Minister for Defence Richard Marles’s apprehension and a possible ruling toward Huawei ban from 5G networks citing cybersecurity concerns. Huawei published a letter to Australian members of Parliament over the comments made. The company vehemently stated that the rumors and comments were ill-informed and have no factual basis.

Palo Alto Networks acquires cybersecurity startup Twistlock

Palo Alto

Global cybersecurity company Palo Alto Networks announced that it entered into a definitive agreement to acquire the cybersecurity startup Twistlock in a $410 million acquisition deal.

Headquartered in the United States, Twistlock provides comprehensive Cloud Native Security to the enterprises. The latest acquisition integrates Twistlock’s technology, which focuses on securing IT infrastructure tools, with the Palo Alto Networks’ Prisma cloud security product. The company claims that it sells cloud computing cybersecurity tools to major companies like Aetna, Walgreens, USAA, Workiva, and GridSapce.

Founded in 2005, Palo Alto Networks covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection services. The Santa Clara-based company stated the latest acquisition deal will bring it closer to using AI and machine learning to help further automate significant parts of the company’s customers’ security operations.

Palo Alto Networks recently acquired information security startup Demistro in a $560 million cash and stocks deal. The acquisition deal, which is expected to be completed in the third quarter of the fiscal year, will accelerate Palo Alto networks application framework strategy and support the company’s aim to deliver immediate threat prevention and response for security teams.

Demisto, founded in 2015, develops and markets automation tools for information security management. The company claims that its Security Orchestration Automation and Response (SOAR) Platform combines orchestration, incident management, and interactive investigation into a seamless experience. Demisto is going to jointly work with the Palo Alto Networks team to strengthen its existing integration with the Application Framework, the company said in a statement.

Palo Alto also launched a new Cybersecurity Academy in collaboration with IBM Canada and the British Columbia Ministry of Education to bridge the skills gap by preparing students for careers in cybersecurity.

The 12-month academic program gives students, across selected high schools in British Columbia, hands-on training on evolving cyber threats and how to prevent them. The special curriculum, jointly designed by Palo Alto Networks, British Columbia’s Ministry of Education and IBM Canada, focuses on firewall installation, antivirus software, zero-day vulnerabilities, and other security skills.

Cyber-attacks on Kenyan organizations rise to 11.2 million

Kenya Reports 37.1 Mn Cyberattacks in Q4 of 2019: Report

Security researchers revealed that organizations in Kenya were hit by 11.2 million cyber-attacks, with a 10.1 percent increase in the number of security incidents, in the first quarter of 2019 when compared to the previous quarter. The Communications Authority of Kenya (CA) stated that its incident response center has detected growing cases of malware, web application attacks, system misconfiguration, and online abuse.

The cyber intelligence team at CA has issued around 14,078 cyber threat advisories to the affected organizations in the country, which warned an increase from the 12,138 alerts in the last year. According to the CA, the cyber-attacks cost Kenya’s economy about Sh29.5 billion.

The banking regulator of Kenya, the Central Bank of Kenya (CBK), recently announced the launch of new guidelines on cybersecurity for the financial services sector in the country. According to Patrick Njoroge, the Governor of (CBK), the new guidelines on cybersecurity for payment services will help in curbing emerging threats in the financial industry.

“The regulatory and advisory initiatives are targeted towards safeguarding Kenya’s financial sector from cybercrime,” said Njoroge at the launch of Kenya Bankers Association (KBA) 2019 Card, Mobile, and Online Safety Awareness Campaign. “As a result, a single attack on any given commercial bank could have a devastating effect on the entire financial services system.”

“While this is an inspiring development, financial fraud is among the challenges that threaten progress in the adoption of new technologies. As an industry, we firmly believe that it is through cross-sector collaborations that we can defeat fraud and ensure a sustainable environment for growth,” said Habil Olaka, the CEO of KBA.

Last year, the Central Bank of Kenya proposed new guidelines for cybersecurity standards in order to fight against banking frauds and to get a better view of the new threats that payment service providers are facing. According to the new guidelines, banks and mobile payment operators are required to file cybersecurity reports with the industry regulator. The firms are asked to notify the Central Bank of Kenya within 24 hours of any suspicious activity and need to submit a quarterly report with CBK on the incidents experienced and how they were resolved.

Sweepatic secures 1 million EUR to accelerate growth

Funding

Cybersecurity startup Sweepatic recently secured 1 million euro ($1.5 million) from the eCAPITAL’s cybersecurity fund and eCAPITAL Technologies IV Fund in a series-A funding round. The Belgium-based startup stated the new proceeds will boost the company’s growth by strengthening management, accelerating the product development, and further building the sales & marketing operations.

Founded in 2016 by Stijn Vande Casteele and Martin Carnogursky, Sweepatic helps customers and enterprises to be more informed, pro-active and resilient against cyber-attacks. It also produces actionable insights that help to know potential cyber risks. Sweepatic claims that its cybersecurity Reconnaissance Platform discovers and monitors companies’ attack surfaces 24/7 globally, discovering digital footprints and monitoring external attack surfaces for risk exposure.

“This capital raise by a renowned German private investor, with a specialized cybersecurity fund, is proof of the market potential of our solution in the fast-growing cybersecurity market. With eCAPITAL not only do we raise capital but we onboard highly experienced entrepreneurs with an international network. We are excited about this partnership as it will allow Sweepatic to further develop its product offerings and market outreach,” said Stijn Vande Casteele, the Co-founder & CEO of Sweepatic.

“We are excited to join forces with Sweepatic which is an agile company with an innovative approach to digital footprint mapping. Through its unique capability, Sweepatic has a global reach and we are excited to actively support this ambitious team in accelerating their venture,” said Willi Mannheims, Managing Partner at eCAPITAL.

eCAPITAL, a cybersecurity-focused venture capital firm, recently invested around £5 million (around $6.3 million) in technology company UltraSoC.

Headquartered in the United Kingdom, UltraSoC makes complex circuits for automotive parts and is a developer of analytics and monitoring technology of the systems-on-chip (SoCs). The company claims that its embedded analytics technology platform allows product designers to add advanced cybersecurity and performance tuning features in order to resolve critical security issues.

Speaking on the new investment Rupert Baines, the CEO of UltraSoC, stated the new funding will be used to accelerate its growth globally to address emerging opportunities in the cybersecurity, high-reliability, and safety-critical systems markets.