Home Blog Page 310

Hillary Clinton to deliver a keynote speech at cyber defense summit

Former Secretary of State and Democratic presidential nominee Hillary Clinton is going to serve as a keynote speaker at the forthcoming  Cyber Defense Summit, which is organized by the cybersecurity company FireEye in October 2019.

“We are pleased to announce that Former U.S. Secretary of State Hillary Rodham Clinton will be a featured keynote at our #FireEyeSummit in October! Secretary Clinton will engage in an intimate Q&A keynote discussion,” a tweet from the FireEye read.

The Cyber Defense Summit is intended to bring together many of the world’s leading security veterans, including frontline heroes, government leaders, and executives from various industries to address the challenges of evolving threat landscape, the company said in a statement.

The announcement was met with severe criticism and laughter online. People reiterated about the scandal around Hillary, when her personal server was subject to repeated intrusion attempts from Germany, China, and South Korea in 2014, according to federal investigators. She was also one of the biggest political victims of a cyber attack when her emails were leaked just ahead of the 2016 democratic elections thereby influencing the results at an unprecedented scale.

But the buck did not stop there. While Trump administration was stirred in controversies where citizens were fed with fake news, a fact-checking website Verrit was launched which took a dig at Trump’s administration and extended support to Hillary Clinton.

Verrit was created by former Clinton staffer Peter Daou, which was his attempt to create an online hub for Clinton backers so that they can find easy-to-share facts, stats and other “information you can take out to social media when you’re having debates on key issues people are discussing,” Daou said in an interview.  But soon after Clinton, herself, endorsed the website, the site became prey for hackers, and Verrit fell victim of a Distributed Denial of Service (DDoS) cyber attack, forcing the website offline.

Hillary Clinton must have several personal stories to share at the summit as there is no one else who has been affected by cyber attacks to the level as she has over her career spanning over decades.

Pokémon Go creator sues hackers who help players to cheat

Popular video games developer Niantic Labs recently filed a lawsuit against the hacker group that’s allegedly giving players an unfair advantage in its mobile games, infringing on its intellectual property rights.

Niantic, the creator of Pokémon Go, Ingress, and the upcoming Harry Potter: Wizards Unite games, stated the hacker group named Global++ is behind the hacked versions of Pokémon Go and Ingress which are dubbed as PokeGo++ and Ingress++. Niantic also stated that the group has earned money by selling subscriptions to the hacked game applications.

Niantic Labs names Ryan “ElliotRobot” Hunt as a defendant in the suit describing him as the leader of the group and the main developer of the hacked apps. It also filed Alen “iOS n00b” Hundur, who described as a promoter of the hacked apps on YouTube, in the lawsuit, including 20 other members of Global++.

“Among other things, defendants’ schemes undermine the integrity of the gaming experience for legitimate players, diminishing enthusiasm for Niantic’s games and, in some cases, driving players away from Niantic’s games altogether. Defendants’ schemes therefore damage Niantic’s reputation and interfere with Niantic’s business,” Niantic said in the lawsuit.

A recent research revealed that the gaming industry has become an attractive target for cybercriminals with 12 billion credential stuffing attacks reported in the past 17 months (November 2017-March 2019). According to the Cloud delivery network provider Akamai Technologies, the gaming community is among the most lucrative targets for hackers to make a quick profit.

In its research report, “2019 State of the Internet/Security Web Attacks and Gaming Abuse” Akamai stated that there were 55 billion cases of credential stuffing attacks across all industries. The report highlighted that nearly 67% of credential stuffing attacks target organizations based in the United States. It stated that Russia is the second largest source of application attacks and China is ranked as the fourth highest source country.

On the other hand, the United Kingdom ranked as the second highest targeted country with Japan, Canada, Australia, and Italy are all also among the countries most targeted. “One reason that we believe the gaming industry is an attractive target for hackers is that criminals can easily exchange in-game items for profit,” Martin McKeay, Security Researcher at Akamai said in a statement. “Furthermore, gamers are a niche demographic known for spending money, so their financial status is also a tempting target.”

Around 6,200 cyber-attacks reported in Singapore last year: CSA

Singtel data breach

A recent survey report revealed that a total of 6,179 cybercrime cases were reported in 2018 in Singapore, which is an increase when compared to 5,351 reported cases in 2017.

According to the report Singapore Cyber Landscape 2018 by the Cyber Security Agency of Singapore (CSA), Singapore continues to be the primary target for hackers with advanced cyber-attacks, which are accounted for about 19 percent of the overall crime. The CSA, an agency which is part of the Prime Minister’s Office and managed by the Ministry of Communications and Information, provides dedicated and centralized oversight of national cybersecurity functions.

According to the CSA, the businesses in Singapore suffered losses of around S$58 million in 2018, which is an increase of about 31 percent from 2017. The report highlighted that around 1,204 cases were investigated under the Computer Misuse Act with about 2,125 e-commerce scams and 378 business email impersonation scams reported in 2018. However, the report revealed that common cyber threats like website defacements, phishing, and ransomware attacks were decreased in 2018 compared to the last year.

“Cybersecurity incidents made some of the biggest headlines in 2018. Data breaches across various industries affecting high-profile organizations were reported but smaller businesses and individual users were not spared either. We have to learn from these incidents and push further in our cybersecurity efforts collectively as a nation, so that we can defend ourselves against increasingly sophisticated threats and prepare ourselves for a digital future,” said David Koh, Commissioner of Cybersecurity and Chief Executive of CSA.

A recent research from endpoint security firm Carbon Black revealed that 90 percent of the Singapore businesses have been breached in 2018. In its report named Singapore Threat Report, Carbon Black examined the survey results from different industries, organization sizes, and IT team sizes to show modern attacks and cyber defense landscape in Singapore region.

According to the research findings, 96 percent of surveyed Singapore-based companies reported breaches last year and 92 percent of them said they’ve seen an increase in attack volumes. Also, 95 percent of the organizations stated the attacks have become more sophisticated and 97 percent of them stated they’ve planned to increase spending on cyber defense.

In order to boost cybersecurity and tackle next-generation cyber threats, the Singapore government recently updated the guidelines on data breach notification and accountability. Unveiled by the Personal Data Protection Commission (PDPC), the new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident before 72 hours after discovering a data breach.

Managed Security Service startup Expel raises $40 million

Pipeline Cybersecurity

Expel, a managed security service provider, announced that it recently secured $40 million in a series C funding round led by Index Ventures along with the participation from Battery Ventures, Greycroft, NEA, Paladin Capital Group, and Scale Venture Partners. As per the investment deal, Shardul Shah, a partner at Index Ventures will join Expel’s board of directors.

Expel stated that it will use the new funding to expand its cloud monitoring capabilities, accelerate product innovation, and fund sales and marketing programs.

Founded in 2016, Expel provides transparent managed security services to the organizations on-premises and in the cloud.  The company claims that it offers continuous monitoring services via its security operations center-as-a-service. It also helps customers make better, faster decisions about security issues by giving them real-time recommendations.

“Expel is the only managed security provider that can demonstrate ROI to customers within minutes of turning on the service, not months,” said Shardul Shah, partner at Index Ventures. “Expel’s technology-first, transparent approach to managed security is the best solution for managing security risks in the cloud age.”

“There are some fundamental beliefs we have here at Expel, and one of those is that people are really good at two things: using judgment and building relationships,” said Dave Merkel, CEO and co-founder of Expel. “Having a security operations center full of people chasing loads of alerts isn’t the way to ‘do security’ in the 21st century. Expel’s technology-first approach allows CISOs and their teams to stop playing a game of alert whack-a-mole and focus on managing the risks unique to their business.”

Onapsis acquires cybersecurity firm Virtual Forge

Acquisition

Onapsis, a provider of business application cyber resilience, recently announced the acquisition of cybersecurity firm Virtual Forge. Founded in 2006, Virtual Forge is a provider of solutions to automatically prevent, detect, and remediate cybersecurity and compliance risks in customizations and extensions of SAP applications.

Headquartered in Boston, Onapsis provides cybersecurity solutions to enterprises to protect their SAP and Oracle applications, keeping them compliant and safe from insider and outsider threats. The company claims that its security platform is the widely used SAP-certified cybersecurity solution in the market.

Onapsis cybersecurity solutions automate the protection of ERP business-critical applications to protect the vital information and systems. The company claims that its software platform is the most widely used security solution that protects the ERP systems and business-critical applications.

The latest acquisition integrates Onapsis’s business application cyber resilience platform with the Virtual Forge’s technology to deliver advanced cybersecurity, visibility, incident response, management, and compliance capabilities to the organizations that run on SAP and Oracle applications.

“Business-critical application platforms such as SAP and Oracle are the epicenter of most enterprise organizations’ digital transformation, cloud migration and IoT initiatives,” said Mariano Nunez, CEO and Co-founder, Onapsis Inc. “Now with Virtual Forge, we are perfectly positioned to accelerate our international growth with a comprehensive business-critical application security and compliance platform purposely built to mitigate cyber threats, accelerate application modernization and cloud migration initiatives, and automate compliance processes for enterprises running their businesses on SAP and Oracle. This is an incredible achievement for our customers, partners and employees.”

“We are excited to join the Onapsis team,” said Dr. Markus Schumacher, CEO and Co-founder, Virtual Forge. “We have a shared vision and overall business goal – to protect the world’s most critical applications. By joining forces, we will be able to provide clients with the utmost expertise and support from the best of the best in business-critical application cybersecurity.”

Recently, Onapsis made a partnership deal with technology company Verizon Communications. The new alliance helps Onapsis to accelerate and protect SAP customers’ digital transformation initiatives. Verizon Communications, the company that acquired Yahoo, operates the wireless network and delivers integrated solutions to businesses worldwide.

Onapsis also made a technology partnership and product integration with security management platform Exabeam to give security teams access to ERP vulnerability logs in their security incident and event management (SIEM) for security monitoring.

The new alliance integrates Onapsis with Exabeam’s Security Management Platform (SMP) that allows security teams to detect and respond to threats by providing them with continuous visibility of ERP vulnerabilities. The association also offers enhanced security solutions including security monitoring, threat detection, incident response, and audit compliance.

Security bug in OnePlus Phones leaks users’ information

OnePlus

A critical security vulnerability with OnePlus device’s wallpaper application, Shot on OnePlus, leaks hundreds of the user’s email address and other information. The Shot on OnePlus is an application used to access photos uploaded by the OnePlus users.

The flaw exists in the Application Programming Interface (API), used to host the photos in the device, that facilitates the connectivity between the server and the OnePlus application. The API, which is hosted on open.oneplus.net is insecure and can be accessed by the attackers by exploiting the vulnerability, 9to5Google reported.

The vulnerability can expose the photo details, including photo code, author, email addresses, focal-length, photo topic, uploaded location, and the uploaded time. It’s believed that the app has leaked the details since its release, according to 9to5Google. OnePlus notified the users that the issue was fixed and made changes to its API.

One Plus has often been touted as the flagship killer and the subsidiary of Oppo has always lived up to its name for several reasons including build, cameras, display, the speed with value for money topping it up.  With that in mind the latest outing from the smartphone maker, One Plus 7 Pro, the flagship of flagship killers came loaded with everything you could have ever asked for, but also came with a lofty price the purist fans were not so used to. Nevertheless, the 12 GB version indeed continues to be one of the best One Plus phones to ever roll out. But then, soon after the launch, came the biggest security hindrance.

The One Plus 7 Pro like several other phones is almost bezel-less, has one of the best in class pop out selfie cameras and has an on-screen or under the screen, whichever you prefer calling it, fingerprint unlock. It seems like device security wasn’t always the forte for the brand. The new One Plus 7 Pro is no exception as well.  Days after the phone was launched, someone has managed to hack the fingerprint scanner. And all the One Plus 7 Pro need was a gum fingerprint. The host of the Max Tech video used a hot-glue gun, tinfoil, some white school glue, and made a gum fingerprint to unlock the phone and voila the phone was unlocked. The method is one of the oldest fingerprint hacking technique.

Anti-Phishing startup IronScales raises $15 million

Startup

IronScales, an automated phishing prevention, detection, and response provider, recently announced that it has secured $15 million in a Series B funding round led by K1 Investment Management.

The Atlanta and Tel Aviv-based startup stated the new investment will be used to focus on decentralization as a method of preparing against cyber-attacks and AI. The company is also planning to expand its business operations in the United States.

Founded in 2014 by alumni of the Israel Defense Forces’ elite Intelligence Technology unit, IronScales provides automated phishing prevention, detection, and response services for emails by using a multi-layered and automated approach. Ironscales phishing mitigation solutions platform combines machine learning and AI tools that integrate with Office 365, Exchange, and G Suite to thwart evolving threats.

Commenting on the new funding Eval Benishti, the CEO of IronScales said, “With our new funding, IRONSCALES is blazing ahead with decentralized communities by encouraging the collective sharing of information through our platform, ultimately proactively preparing against attacks through automatic detection and response. Current users have access to nearly one thousand cyber analysts, and this number grows every time that a new company comes onto the platform. Ultimately, this collective cyber-defense approach strengthens how quickly our platform can respond to threats through people and technology. We call it the power of the pack.”

“IRONSCALES will also further our commitment to innovation with AI. We’ve already introduced our users to email security’s first AI-powered assistant, but that’s just the beginning. Our product roadmap continues to think outside the box so that we can ensure that our platform remains best suited to help businesses where their email security hurts the most – with comprehensive post-delivery protection, detection, and remediation,” Benishti added.

Vietnam suffered more than 700 cyber-attacks in May

Philippines-over-South-China-Sea-row-FireEye

The Vietnam government recently revealed that around 425 deface, 289 phishing, and 25 malware attacks were reported in the country in May 2019. According to the figures released by the Vietnam Computer Emergency Response Team (VNCERT), under the Ministry of Information and Communications, there were on average 23 cyber-attacks on government computers reported every day.

VNCERT stated that most of the attacks are targeted on information collection, violate information security policy, and attacks related to malicious code. It also discovered 28 warning emails to State administrative agencies to require them to resolve incidents and act fast.

Most of the Vietnamese websites were attacked affecting information security such as spam, service denial, install, and injecting malicious codes by exploiting the vulnerabilities in web browsers.

Recently, the Ministry of Information and Communications of Vietnam stated that around 4,770 cyber-attacks were reported in the country in the first quarter of 2019. According to the Vietnam Computer Emergency Response Center (VNCERT), this number is more than half the figure for the whole of last year, which was 8,319 cyber-attacks. The center also stated that most of the attacks were reported against e-commerce, financial, and banking systems.

The most common infringements among the attacks were violations of information security policies (40 percent) and unauthorized information collection (39 percent). And, the other data violations included denial of service (8 percent), privilege escalation attacks (7 percent), and the spread and attack of malicious codes (6 percent), VN Express reported.

Nguyen Trong Duong, the director of VNCERT, stated that there were 124 cases related to on-site malicious code attacks, 2,245 interface breaches, and more than 1,000 websites that were attacked by phishing codes.

Early this year, the Vietnam lawmakers approved a new cybersecurity law that controls the Internet content and global tech companies operating in the country. The new cyber law, which came into effect on January 01, 2019, requires Facebook, Google, and other international tech firms to store local users’ data on local servers and set up offices in Vietnam.

The new law prohibits Internet users in Vietnam from spreading anti-government information and posting false information that could cause damage to the country. It also prevents the circulation of content that’s fake, slandering, or inciting violence.

Israel based brewer opens new Cybersecurity Unit to prevent cyber-attacks

Anheuser-Busch InBev (AB InBev), a popular beer maker, recently announced that it’s opening a cybersecurity unit in Israel to protect itself from the evolving cyber threats.

The Tel Aviv-based company makes over 400 different brands of beer including Budweiser, Corona, Stella Artois, Beck’s. Hoegaarden, and Leffe. The new cybersecurity unit is focused on online security and threat detection, according to AB InBev.

Luis Veronesi, the Vice President of global security and compliance at AB InBev, stated the new cybersecurity hub is aimed to protect itself online and defend against hackers. The company is already facing cyber-attacks that are either attempting to disrupt operations or force the company to pay ransomware, according to Veronesi.

“With increasing digitalization, we have to be prepared to defend against anything coming. The cybersecurity office is located in Tel Aviv and will be fully-focused on discovering potential attacks against the company before they happen as well as analyzing any threats,” Luis Veronesi said in a media statement.

As a leader in cybersecurity, Israel witnessed many of the world’s largest companies opening cybersecurity centers in Israel or acquired Israel’s security firms to strengthen their cybersecurity posture.

Recently, the U.S.-based gaming and computer graphics firm Nvidia Corp. announced the acquisition of Israel’s chip designer Mellanox Technologies Ltd for $6.8 billion to boost its data center and artificial intelligence business. Along with providing gaming chips, Nvidia also offers processors to speed up artificial intelligence tasks like teaching servers that recognize images. The latest acquisition will unite NVIDIA’s computing platform and Mellanox’s end-to-end security solutions to become a major cloud service provider and computer maker.

Earlier, the Israel government-owned defense technology company, Rafael, established a cybersecurity center to strengthen its railway network system, according to a news agency. The new cybersecurity operations center (CSOC), to be operated by Israel Railways’ cyber unit, is worth $8.25 million and located in the city of Lod in central Israel.

The new cybersecurity center aids in developing measures to strengthen the information security structure of the railway network systems. According to the rail authorities, around 10 million attempts intended to compromise the railway network information and insert malicious content are blocked every month.

Akamai Technologies join hands with DreamHack for cybersecurity

Akamai MFA

Digital entertainment company DreamHack recently announced a new partnership with the cloud delivery network provider Akamai Technologies to jointly share data security insights along with analysis on the global gaming and eSports industry. Based in Sweden, DreamHack is a production company specialized in eSports tournaments and other gaming conventions.

As the popular cloud delivery platform, Akamai provides its customers with the best and most secure digital experiences on any device, anytime, and anywhere. Akamai intends to serve a larger base of carrier and enterprise customers with more comprehensive security products.  These products will be designed to more effectively identify, block, and mitigate cybersecurity threats such as malware, ransomware, phishing, and data exfiltration.

Speaking on the new alliance Marcus Lindmark, the DreamHack Co-CEO, said “DreamHack is a major influencer in the video game industry through our 15 global events that will welcome approximately 400,000 visitors in 2019. But we also have tens of millions of viewers and gamers tuning in online or try to qualify in our online tournaments. Together, with Akamai, we want to lift these questions around online data security and instead help secure the continued growth and success of esports and gaming in a market where threats are increasing, and attackers are getting smarter every day. Akamai is a trusted partner in the space and an ideal partner for DreamHack.”

Recently, Akamai Technologies published a research report, “2019 State of the Internet/Security Web Attacks and Gaming Abuse”, which stated the gaming industry has become an attractive target for cybercriminals with 12 billion credential stuffing attacks reported in the past 17 months (November 2017-March 2019).

The report highlighted that nearly 67% of credential stuffing attacks target organizations based in the United States. It stated that Russia is the second largest source of application attacks and China is ranked as the fourth highest source country. On the other hand, the United Kingdom ranked as the second highest targeted country with Japan, Canada, Australia, and Italy are all also among the countries most targeted.

“One reason we believe the gaming industry is an attractive target for hackers is because criminals can easily exchange in-game items for profit,” said Martin McKeay, a security researcher at Akamai. “Furthermore, gamers are a niche demographic known for spending money, so their financial status is also a tempting target.”

The attackers look for valid accounts and unique skins in popular games to hack them and sell. Akamai said that hackers focus on more valued video game accounts that are connected to a valid credit card or other financial resources. After compromising the account, the criminal can purchase additional items, such as currency used within the game, and then sell the hacked account at a higher price.

According to a survey, young gamers are increasingly turning into hackers to commit cybercrime. The research found that 82% of teens and young adults recruited by online criminals had developed their cybercrime skills through video gaming.

The UK’s National Crime Agency (NCA) held a forum and published a special report about the problem. The agency report looks at ways to identify those at risk of hacking, how to intervene before they go too far, and then inspire them to pursue a career in IT security.