Home Blog Page 313

Baltimore hackers leak data on Twitter after no ransom was paid

Baltimore Skyline

The hackers, who infected about 10,000 of Baltimore city government’s computers last month, have allegedly leaked government documents on Twitter. It’s believed that an unknown Twitter account, which is claimed to be owned by the hacker group, has been used to leak the sensitive documents, the Baltimore Sun reported.

The officials of Baltimore and federal authorities stated that they’re investigating the documents posted by the attackers. One of the documents that hackers leaked included a detailed assessment of a woman’s medical history, the officials said. The authorities also clarified that there’s no evidence that any personal data misused in the incident.

On May 7, 2019, several of the Baltimore city services were halted after a ransomware attack hit city computers. The hackers infected about 10,000 of Baltimore city government’s computers with ransomware called RobbinHood. The attackers asked the city officials pay 13 bitcoins (about $100,000) to release the city’s systems, warning that price would go up every day after four days, and after the tenth day, the affected files would be lost permanently.

“We’ve been watching you for days and we’ve worked on your systems to gain full access to your company and bypass all of your protections,” the ransom note read.  “We won’t talk more; all we know is MONEY. Hurry up! Tik Tak, Tik Tak, Tik Tak!”

The authorities stated the attack taken the Baltimore city government hostage. The city government can’t access email accounts, parking fines database, process payments to employees and the citizens remain unable to make utility payments, property taxes, and vehicle citations.

In a similar incident, the Los Angeles Times and several Tribune Publishing newspapers recently faced printing and delivery issues after encountering a cyber-attack that reportedly involved a ransomware. The Associated Press quoted the Chicago Tribune reporting that the publishing and printing systems of several Tribune Publishing newspapers were affected due to a computer virus. The Los Angeles Times reported that some people said the attacks appeared to be in the form of Ryuk ransomware.

The Chicago Tribune’s print edition on Saturday, December 29, 2018, was published without paid classified ads and death notices due to the attack. However, the publisher clarified that no customer and financial information was leaked.

Data breach exposes personal data of 7.7 million LabCorp’s consumers

LabCorp

LabCorp, a medical testing company, recently suffered a massive data breach that affected around 7.7 million of its patients’ data. According to a filing with the U.S. Securities and Exchange Commission, LabCorp. said it discovered the breach at a third-party billing collections firm, the American Medical Collection Agency (AMCA), between August 1, 2018, and March 30, 2019.

The company stated the exposed information could include personal and financial data like – first and last name, date of birth, address, phone, date of service, provider, and balance information. The breach also exposed credit card and bank numbers attached to around 200,000 accounts, according to the filing.

“AMCA’s affected system also included credit card or bank account information that was provided by the consumer to AMCA (for those who sought to pay their balance). LabCorp provided no ordered test, laboratory results, or diagnostic information to AMCA. AMCA has advised LabCorp that Social Security Numbers and insurance identification information are not stored or maintained for LabCorp consumers,” the filing reads.

“It is in the process of sending notices to approximately 200,000 LabCorp consumers whose credit card or bank account information may have been accessed. AMCA has not yet provided LabCorp a list of the affected LabCorp consumers or more specific information about them,” the statement added.

In a similar recent incident, a data breach at Inmediata Health Group, a healthcare billing and administrative service provider, exposed the personal and medical data of Michigan residents. The Puerto Rico-based healthcare center stated that a technical glitch in the webpage settings permitted search engines to expose internal webpages online, which contained patients’ sensitive information. According to Inmediata, the exposed data included patients’ name, addresses, social security numbers, and other personal health information.

The security officials at Inmediata halted the website temporarily and contacted a digital forensic firm to investigate the incident. The center clarified that there was no discovery of any misuse of the exposed data. The affected patients are suggested to monitor their financial accounts for any fraud transactions.

Also, a recent research report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations. The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

Balbix joins hands with Tokyo Electron Device

Artificial Intelligence

Cybersecurity firm Balbix recently announced that it has entered into a reseller and distribution agreement with Tokyo Electron Device Limited (TED) to bring AI-based cybersecurity posture transformation to Japan. Founded in 2015, Balbix is a breach controlling platform that aids companies to avoid security threats.

The new alliance will offer companies in Japan with access to Balbix’s AI-powered platform for an automatic asset, vulnerability discovery, continuous risk assessment, and prioritized mitigation actions. Balbix claims that its security platform discovers and analyzes customers’ attack surface to provide accurate visibility of breach risks. The company says that by using Balbix, CISOs and CIOs can transform their organization’s cybersecurity posture.

“In today’s modern IT environment, there are practically unlimited combinations of methods by which adversaries can breach an enterprise. As a result, analyzing and improving cybersecurity posture is no longer a human scale problem,” said Gaurav Banga, CEO and Founder of Balbix. “We are very pleased to be working with TED as a strategic channel partner in Japan and bring to their customers a new level of capability to tangibly transform cybersecurity posture.”

“Through our relationship with Balbix, we will be able to offer customers a market-leading platform for enabling dramatic and measurable reduction in breach risk,” said Atsushi Tokushige, President and Representative Director of Tokyo Electron Device. “As a value-added partner with extensive reach across Japan and deep security solutions expertise, we will sell Balbix to enterprise customers across a full range of industry verticals, as well as via managed service providers in an easily consumed, cloud-based service model.”

In an attempt to avoid cybersecurity adversities, Balbix raised $20 million towards its business expansion. The funding allows the company to further develop an advance preventive model that detects and resolve cyber threats. Earlier, Gaurav Banga raised $8.6 million toward business growth. He’s also the co-founder of Bromium, a cybersecurity provider founded in the year 2010.

The company is making smart moves in developing the preventive model uses artificial intelligence and machine learning techniques in finding out vulnerabilities in an organization and strengthening security architecture. The solution plugs into an existing operational model to generate the company’s security weaknesses and threats.

“We started this company so that we could use cutting-edge machine learning algorithms to automatically and comprehensively measure the security and attack surface, and to produce relevant insights for all stakeholders. You look at the numbers and you could easily have hundreds of millions or tens of billions of data points to watch for vulnerabilities- you have to make sure they are OK,” Banga said.

With cloud expanding, users need umbrella the most

Cloud Security Market

Security concerns will continue to be a problem for consumers and corporations. In one of its security predictions, Gartner stated that through 2020, 95 percent of cloud security failures will be the fault of customers. “Only a small percentage of the security incidents impacting enterprises using the cloud have been due to vulnerabilities that were the provider’s fault,” the report said. “The characteristics of the parts of the cloud stack under customer control can make cloud computing a highly efficient way for naive users to leverage poor practices, which can easily result in widespread security or compliance failures. The growing recognition of the enterprise’s responsibility for the appropriate use of the public cloud is reflected in the growing market for cloud control tools.” Gartner had also predicted that by 2018, nearly 50 percent of organizations with more than 1,000 users will move to the cloud, with cloud security brokers monitoring and managing their data, which became true.

“Recent history has shown that virtually all public cloud services are highly resistant to attack and, in the majority of circumstances, represent a more secure starting point than traditional in-house implementations. No significant evidence exists to indicate that commercial cloud service providers have performed less securely than end-user organizations themselves. In fact, the most available evidence points to the opposite. Only a very small percentage of the security incidents impacting enterprises using the cloud have been due to vulnerabilities that were the provider’s fault,” the report stated.

One of the biggest issues of cloud security is identity and access management. A recent survey from the Cloud Security Alliance showed that nearly 22 percent of respondents linked a data breach to compromised credentials. One key area is to focus on is Identity and Access Management (IAM) policies for cloud apps. Companies embracing big data solutions also must adopt more perimeter and identity security solutions. The first step must begin with ensuring a proper verification process that can defend the systems from modern-day hackers and their techniques. There must also be continuous testing of security solutions already in place.

Another key area of concern should be the internal access control policies as these must be extended to outsourced information technology vendors and other third parties, and there must be a central body that controls these aspects. “The corporate IAM policy needs to be extended to encompass the cloud apps that you have identified, and then combined with alerting mechanisms that can report on unusual logon activity on cloud services. By undertaking this process, it reduces the likelihood that credentials can be stolen and misused without the organization being aware,” suggests a report in Tech Target, last year.

The necessity for cloud adoption varies from company to company. And in most cases, the benefits of cloud computing depend on the kind of business the organization is. Just like with any tool, organizations ultimately must consider their risk profiles, staffing and access, resource allocation, and regulatory policies within the organization, and risk appetite before making a decision about cloud storage.

We at CISO MAG are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Endpoint protection firm SentinelOne secures $120 million

Funding round

SentinelOne, an autonomous endpoint protection services provider, recently secured $120 million investment in a Series D funding round led by Insight Partners. The other investors participated in the round included, Samsung Venture Investment Corporation, NextEquity and previous investors including Third Point Ventures, Redpoint Ventures, Granite Hill, and Data Collective (DCVC).

The California-based company stated the new investment will be used to accelerate the company’s next-gen endpoint, cloud, and IoT protection platforms through its autonomous AI mechanism.

Founded in 2013, SentinelOne provides autonomous endpoint protection services to organizations to help them prevent, detect, respond, and hunt attacks across all major vectors. The company claims that its S1 platform is designed to save customers time by applying AI to automatically eliminate threats in real time for both on premise and cloud environments.

“We’ve built a team and technology to disrupt and broaden the endpoint space: as the network perimeter is drastically changing, so does the notion of the endpoint,” said Tomer Weingarten, CEO and Co-founder, SentinelOne. “Endpoints are everywhere today, from classic laptops and desktops, to workloads in the cloud and the datacenter, and all IoT devices – the network edge is the real perimeter. We were the first to unify EPP and EDR – prevention, detection, response, and hunting – in a single autonomous agent. We were the first to stand behind our product with a cyber warranty. Now we are the first to take AI-based device protection to the edge, covering IoT endpoints and workloads in the cloud. We have delivered unrivaled product innovation through a sustainable growth model that’s unique to others in the space, positioning us as a leader into the future.”

Last year, SentinelOne partnered with Arete Advisors, a company that provides incident response and digital investigation services. The collaboration will further enhance both companies’ abilities to develop integrated, intelligent, technology-enabled solutions based on new and emerging threats. By deploying SentinelOne’s A.I. platform, Arete claims that it will be able to create highly customized advice specific to clients’ business size and industry.

“Our elite team of cybersecurity experts has decades of experience, having managed more than 3,500 cyber investigations worldwide.  And, we are frequently asked to provide expert opinion on data breaches to global courts and government regulators,” said Jim Jaeger, President of Arete Advisors. “We believe that SentinelOne’s Endpoint Protection Platform is a dramatic step forward in a new era of Artificial Intelligence and Machine Learning enabled endpoint software available. When coupled with our team’s experience, we will be a force to reckoned with.”

10 Key Insights on the Past, Present and Future of Enterprise Security with Mike Howard

Mike Howard

Contributed by Groupdolists

We at Groupdolists are proud to welcome Mike Howard, former Chief Security Officer of Microsoft Corporation, to our Security Advisory Council. His experience and trail-blazing accomplishments in security are already making an impact to our organization.

During Mike’s career, he brought Microsoft to new heights of security and earned his place in their C-suite. He’s been a tireless advocate and inspiration for elevating the role of CSO in all organizations. We recently talked to Mike to find out how he accomplished that and what he sees in the future for the CSO role.

You can read Incident Response 3.0, A Model for Optimal Incident Preparedness in the Digital Age, for the latest industry-leading insights shaped by the Security Advisory Council.

GDL: You’ve been called a “trailblazer” CSO because you have been a long-time advocate of getting the security function into the C-suite. And you were very successful achieving that status at Microsoft. How do you advise a CSO to sell this idea to a C-suite that may not be listening?

Mike Howard (MH): Unfortunately, that ‘not listening’ you referred to tends to be the case a lot of the time.

I think the first thing is that CSOs have to learn to change their mindsets. We used to say within my group, “We’re business people first, but our business happens to be security.” The idea is that you have to show that you enable business success in order to get C-suite buy-in and gain your seat at their table.

Each industry is of course different, but for my industry we were able to position our operation as a way to directly help the company make money. What we did was approach our sales and marketing team over 10 years ago and said, “We’ve got three state-of-the-art security operation centers that have the best Microsoft technologies along with true redundancies of operations. If one of them goes down, we have continuity of operations. We know that you bring Enterprise clients to Microsoft and want to sell them enterprise software, or you want them to re-sign up after their contract expires. Let us in security meet with them; we’re part of the business.” So, we bring those customers to our operations centers, do a dog and pony show demonstrating how well the Microsoft-enabled security system functions.

Then, if we helped our marketing and sales team seal the deal, we arranged it so they would give us some credit. That way, we in security became instrumental in bringing in customers. In fact, that program was so successful we spun off that function into its own vertical. We were eventually credited with bringing in millions of dollars in revenue. Security, a former “cost center,” was now seen as improving the bottom line.

But that’s just our example. CSOs everywhere should take a look at their particular enterprise and figure out how to show the business that it can help bring in revenue.

GDL: Sounds like you had to understand the business’s overall mission in addition to its security aspects.

MH: That’s right. We had to understand the strategy of the business.

One thing that I would advise any CSO to do who’s interested in being part of the C-suite, at least those who are in a publicly traded corporation, is to take a long, hard look at your company’s 10-K.

Years ago, when you asked security pros, “Have you ever read the 10-K?” The security guys and gals would ask, “What’s a 10-K?” And we would explain that it’s a document that has to be filed with the SEC that outlines the company’s strategy, what the company is all about, etc. And there are also sections in there on risks to the company, whether it’s IT risks, risks of competition, etc., and there are also sections on physical security, cyber security, business continuity, and so on. The idea is that CSOs should ask themselves, what part of your security operations can you tie into the 10-K?

My point is that we were aligning security with the business strategy, and that’s the mindset I would advocate for every CSO to have. To put it succinctly, security professionals are business professionals first and foremost, and that business has to be secured.

GDL: It seems like that model you’re presenting could even apply to other kinds of department heads who might feel left out of the C-suite loop because they’re construed as cost centers not driving sales.  

MH: That’s 100 percent right. Anybody who’s in a cost center, HR, legal, finance, or what have you, and the company is looking to make cuts, say, to improve their quarterly earnings, you’ll want to show how your operation helps the bottom line. If you can do that, you’ll have a stronger argument for not being cut.

You’re not always going to find a receptive audience. There are bean-counter types out there who are only concerned about counting beans and are not looking strategically at what you as a cost center have to offer.

So, this can get tricky. In corporate security, we have the responsibility for duty of care. If people are travelling overseas and we don’t have a travel program, or if we know there’s a gap, say, in camera coverage, then we have the obligation to point that out and ask for the appropriate funding to get those gaps rectified. You may not be comfortable increasing overhead in a cost-cutting atmosphere, but everyone has to consider the liabilities. If something bad were to happen, and we knew we had a security gap and did nothing about it because it cost more, that wouldn’t be helpful to our cause.

GDL: Can you talk about the current and future states of the physical security industry? What trends are you seeing?

MH: Let me provide some context. Back when 9/11 happened, physical security became the focus. Everyone was worried about another terrorist attack, attacks on their facilities and personnel. So, there was a lot of funding and emphasis on the physical security. Obviously today we’re in a new world where cyber is the big concern. Today there’s more emphasis and funding for the CISOs than there is for the physical security officers.

GDL: But are those two functions being integrated appropriately?

I don’t necessarily see the kind of integration there should be. Ten years ago, there was a movement to have this uber-CSO.  And the uber-CSO would manage both the cyber and the physical side. But in most enterprises today you see a physical security group and a separate IT security group. And most of them don’t integrate well.

They’ve got to be able to talk to each other when bad things happen, when the balloon goes up, so to speak, and they have to come together. But we’re seeing a gap in, what should be, holistic security for the enterprise.

I think that a lot of the physical security leaders are struggling with the fact that they don’t see as much funding coming their way ­as they did in the past. So, they’re struggling with how to bridge the gap.

When I advocate for integrating these two functions, I like to use the word governance. There’s got to be models of governance within the enterprise in which the various verticals, cyber, physical security, IT, business continuity, risk, etc. form a coalition where they’re not following each other but are sharing information with each other and are finding out if there are gaps. You’ll also see if you’re perhaps both working on the same issues when you shouldn’t be. This form of coalition governance to me is the best formula for moving the physical security world forward to integrate better with the cyber world along with other enterprise functions.

Part of the problem could be human relations issues too — when the two players just don’t like each other or don’t want to work with each other. The two sides may not be interested in what the other is doing. But you’ll find that there is a hunger for physical security professionals to learn more and more about the cyber security realm. Yet they still wrestle with questions about how best to integrate.

Years ago, at Microsoft, we got together and started a governance structure that enabled each group to be transparent about its strategy and gaps we might have in our own program, and we tried to see where we could help each other out.

Most important, if you’re talking any aspect of security to the C-suite you have to do it with one voice.

GDL: Sounds like way too many companies are not even close to the ideal. Is that the case?

MH: Yes, but I think it will change. We’re seeing a demographic shift now. You’re going to see people who are CSOs who come from business backgrounds. They understand P&L and can run a business unit. And when you start getting more and more of these folks that are younger with a lot of finance savvy and business savvy, you’re going to see less and less siloes. It’s not going to be about only physical and cyber, it’s just going to be about enterprise risk.

So, I do see progress on the horizon as you get new people in there, new thinking, really true business people. That doesn’t mean that people with my background can’t adapt to that, they just have to have the right mindset and are willing to do it. In a lot of cases they haven’t been able to do that or have been unwilling to do that, and that’s also the case on the cyber side. So, I think there are opportunities for improvement on both sides.  I actually hate to say “sides,” because it’s all one security and needs to be approached that way.

GDL: You’re speaking a lot about the human relations component. But what about the technology side itself? What are some of the ways that the technology you use to fulfill a mission in physical security joins, or maybe doesn’t join, with the tools that the cybersecurity people are using? After all, cyberattacks often can cause great physical damage.

MH: People often think of cyberattacks as only being attacks from afar, from a foreign country say. But they also could be the result of someone physically plugging in a malevolent USB into a system, which crosses over into physical security.

As an example, we have operation centers with card access systems that record when and where people badge in. So, if someone’s supposed to be in Washington but they badge into UK, that’s not something that the cyber folks would probably have a handle on. But they may need to know about it because whoever is badging into UK could be involved in a cyberattack. So, it’s important to bridge that gap by being able to leverage the physical security technology so it can be put into an integrated data link to cyber security, providing end-to-end capability.

In addition to the technology piece, there’s also the fact that when it’s ransomware or other kind of cyberattack, the people on the physical security side often have very good expertise in investigating. The cyber side generally will not have that investigative expertise. Nor in many cases do they have a global footprint the way a lot of physical security groups have. So, we can help the cyber side because we have boots on the ground in different places and relations with local governments, local security services, along with our investigative expertise. We can help the cyber side not only with the technology pieces that we can leverage, but also with our investigative capabilities.

GDL: How do you evaluate technology?

MH: Evaluating technology is a big task, because you have to have the strategy before you have the technology. Today people go to trade shows, and they look at these widgets, as I call them, bright shiny objects. But they haven’t thought to ask what are the strategic imperatives for that piece of technology? Is your company going to expand globally? Do you expect more of your people to be travelling internationally? Are there terrorist threats in a particular country?  Natural disaster concerns?

Whatever the situation, you need to do a risk analysis and then determine where you are going strategically. What technology do you need to map to your company’s business strategy? Where do you need to be three-to-five years down the road while making sure you’re staying cutting edge as well as looking at the longer-term future? Only after answering these kinds of questions can you start making some reasoned decisions on what kind of technology you need to employ to get you strategically to where you need to be.

But that’s hard work. Some people say first, for example, I need more cameras. But that’s wrong. You’ll end up with something that’s not integrated, something that’s not scalable. You’ll have technologies that don’t talk to each other. And you’ll have to eventually tear that whole thing apart and start all over again. I repeat: strategy first; then the technology.

GDL: How does an organization build a pervasive culture of security awareness that goes down to individual employees and contract workers?

MH: We call that culture a force multiplier. You can have cameras, guard force personnel and so on, but still your best asset are the employees and their security awareness. So how do you create that culture?

In security, we developed a communications group. We had an issue with so-called tailgating, when one person, say, badges into an area, and 10-15 people go right in behind that person without swiping. But we’ve seen a shift now where people are badging in even when the doors are already open. How did we get there? We kept hammering over years – one person; one badge; one entrance.

We would put out communications on the Internet; we had signage on elevators, on doors. And we would reward people for good behaviors. We came up with the idea of giving Starbucks cards as rewards if we saw someone swipe and the person after them swipes again, and we’d thank them for doing security right.

We’re also affected by unfortunate incidents like school shootings that made people understand the importance of security. But at the same time, in the tech industry, we’re not like a military contractor with lots of armed security, very locked down. We don’t want an oppressive atmosphere. We want our people to be comfortable in an atmosphere where they can be creative and innovative, so, again, we have to be sensitive to the strategic, business needs of the company, while being secure.

So, the idea is to say that, in order to keep everyone safe, your employees need to be the first line of defense. And over time, it was amazing to watch how people would badge into a room, one after the other, even when the doors were open – a radical shift.

What you have to do is pick your targets, get a good communications group and do the traditional things like signage, but also use social media. We had multiple communications from me where we would talk about all the different things global security was doing, managing things like kidnappings or terrorism events, because a lot of employees may only see a small slice of what we do. They don’t realize that physical security is doing much more all over the world. So, over a period of time they came to understand that they can be, and should be, part of the front line of defense. But it takes a good communications strategy, a good communications group, with people who understand how to use social media to get the word out. It takes time as well. But you have to keep hammering them over and over. They may get sick of hearing it, but they’ll never forget.

GDL: Did you bring in a separate communications group or people from Corporate Communications to help you in that campaign?

MH: We did it within our security group but, relating to my earlier point about integrated governance, we were tied in with corporate communications with an umbilical cord. If we were messaging out to the Microsoft population, we would vet that messaging with corporate communications first so that they made sure we were jiving with their strategies, including the required tone and the tenor. We were all in sync.

The other piece of that is we would also need to work closely with corporate communications when doing crisis management. By working with them on the communications campaign to improve security awareness among employees, we were able to establish relationships vital to crisis management where communications play such an important role. So, when an incident actually happens, we already know each other and each other’s concerns and can work in lockstep.

Like every other company, we had to prepare for an active shooter situation. It’s a difficult thing to talk about with employees to be sure. We worked closely with PR folks in corporate communication, and we came up with this holistic strategy for how we could present this vital material to the Microsoft population without being alarmist; how we could direct them to our security intranet sites for information on what to do if an active shooter incident were to occur. We did that a few years ago, and it met with very good response, the result of a real partnership between security and corporate communications.

GDL: Well Mike I want to thank you for your time and for your interview. Congratulations on your retirement from Microsoft, and welcome to the Groupdolists Security Advisory Council.

MH: Thank you, and I look forward to being able to contribute to Groupdolists.

Australian National University breached! Attackers access 19 years of data

Australian National University

The Australian National University recently discovered a major data breach that affected students’ and University’s sensitive information. According to the University’s Vice Chancellor Brian Schmidt, unknown cybercriminals attacked University’s systems and accessed personal information late in 2018, which was recently discovered by the University authorities on May 17, 2019. It’s believed that the hackers had unauthorized access to 19 years of significant amounts of information related to personal staff, students, and visitors.

The exposed information included names, addresses, dates of birth, phone numbers, personal email addresses and emergency contact details, tax file numbers, payroll information, bank account details, passport details, and student academic records, according to Schmidt.

However, Schmidt clarified that the data like credit card details, travel information, medical records, police checks, workers’ compensation, vehicle registration numbers, and some performance records were not affected by the incident.

Commenting on the breach incident Brian Schmidt said, “We’re working closely with Australian government security agencies and industry security partners to investigate further. The University has taken immediate precautions to further strengthen our IT security and is working continuously to build on these precautions to reduce the risk of future intrusion.”

“The Chief Information Security Officer will be issuing advice shortly on measures we can all take to better protect our systems and I strongly encourage you all to implement those measures. That advice, frequently asked questions, contact details for support, and more information about the breach is available now via our homepage,” Schmidt added.

Recently, the parliament of Australia stated that they’ve noticed an unknown intruder apparently tried to hack their computer systems. According to the official statement, hackers tried to break into the parliament’s computer network that includes lawmakers’ email archives. However, the parliament officials clarified that there were no indications of data theft so far. They also stated that they’re updating all the passwords of its network systems and started an investigation. It’s believed that a foreign government was behind the attack, possibly China.

Prime Minister Scott Morrison made clear that no Federal Government departments had been targeted in the attack. “I don’t propose to go into any sort of detailed commentary on the source or nature of this. Once further information is available then we will be able to provide further detail,” Scott Morrison added.

The Australian government faced several criticisms on its cybersecurity landscape in recent years. An inspection by the Australian National Audit Office (ANAO) exposed the failure of government organizations to implement cybersecurity requirements. The ANAO’s fourth report on the cyber resilience of government departments and agencies states that except the Treasury Department both the National Archives and Geoscience Australia failed to implement the top four mandatory cybersecurity strategies instructed by the Australian Signals Directorate (ASD).

CipherTrace partners with Rakuten to deliver anti-money laundering services

Raytheon Partners IronNet for Enhanced Protection for OT/IT Systems

Blockchain security company CipherTrace recently partnered with Rakuten Wallet, a subsidiary of Rakuten Group, to offer anti-money laundering (AML) services to the company’s cryptocurrency exchange. Rakuten Group is one of the largest e-commerce sites in Japan operating globally and in plans to enter cryptocurrency trading services.

As per the alliance, CipherTrace supports Rakuten Wallet to improve the safety of investors, protect the integrity, and compliance of the cryptocurrency exchange. Founded in 2015 by veteran security professionals, CipherTrace develops Anti-Money Laundering (AML), cryptocurrency forensics, and blockchain threat intelligence solutions.

The company claims that banks, investigators, regulators, and other digital asset businesses use its security platform to comply with regulatory anti-money laundering requirements and to mitigate threats related to the customer cryptocurrency activity. CipherTrace’s products are also used by government regulators, law enforcement investigators and auditors to enforce AML laws, combat crime and reduce fraud.

“It is a major step for an e-commerce giant like Rakuten to both acknowledge cryptocurrency’s potential and adopt it. We have made significant strides as an industry to make the cryptocurrency market grow and become more trustable. Rakuten Wallet cares about its customers and will work with CipherTrace to make sure that exchanges have optimal protections for mainstream adoption. It is our hope that proper compliance, transparency and increased trust will lead to more and more participation in the global crypto market. We are excited to blaze this trail with Rakuten Wallet,” said Dave Jevans, CEO of CipherTrace.

“We are happy to partner with CipherTrace in advance of our exchange launch. Regulatory compliance and anti-money laundering protections are of the utmost importance, and we believe CipherTrace will provide us the necessary tools needed to best support Rakuten Wallet,” said Yoshinao Kiyama, Head of the Risk Control Department at Rakuten Wallet.

Recently, CipherTrace secured $15 million investment in a funding round led by Aspect Ventures including other investors like Galaxy Digital, Neotribe Ventures, and WestWave Capital from top Silicon Valley and New York venture capital firms with deep cybersecurity and crypto asset expertise.

Along with the investment, Mark Kraynak, the director of Aspect Ventures is going to join CipherTrace’s Board of Directors team. “Great blockchain companies will be forged as crypto assets achieve mainstream adoption. We believe security and compliance with anti-money laundering and other financial regulations, as enabled by CipherTrace, will be a key first hurdle to mass adoption,” Mark Kraynak said in a statement.

 

McAfee join hands with Amazon Web Services for enhanced database security

McAfee Acquires Browser Isolation Firm Light Point Security

The device-to-cloud cybersecurity company McAfee recently announced its collaboration with Amazon Web Services (AWS) to offer cloud-based security solutions. As per the alliance, McAfee announced its Database Security for Amazon Relational Database Service (Amazon RDS). McAfee stated its new security product delivers real-time visibility into all database activities and offers monitoring services to prevent sophisticated attacks.

The new alliance allows the users to benefit from real-time protection for database workloads migrated to Amazon RDS while monitoring databases. McAfee claims that its newly designed Database Security platform is a highly scalable software solution that monitors the Database Management System.

Commenting on the new partnership Anand Ramanathan, the vice president of enterprise products at McAfee, said, “We universally hear from our broad customer base that they need to fortify their cloud database deployments with strong security tools, like how McAfee has always done with on-premises databases. By working with AWS, we are helping to facilitate our customers’ cloud journeys by pairing the security pedigree of McAfee with Amazon RDS. AWS customers can now gain access to McAfee Database Security to add an additional layer of security and rapidly implement critical workflows.”

“We’re delighted to see the launch of McAfee Database Security for Amazon RDS, providing enterprises the ability to continue their journey to the cloud with an additional layer of security,” said Sailesh Krishnamurthy, General Manager, Aurora, MySQL, and MariaDB, Amazon Web Services, Inc. “Customers using Amazon RDS will now be able to automate time-consuming tasks so they are free to focus on the performance, availability, and compatibility of their applications.”

A recent research from McAfee revealed that around 61 percent of the security professionals have experienced serious data breaches in their current organization. The research dubbed Grand Theft Data II – The Drivers and Shifting State of Data Breaches exposed that organizations are still struggling to fully secure their digital assets and protect against breaches.

The research also stated that cybercriminals are using sophisticated methods to steal organizations’ sensitive cyber information, including data and intellectual properties. According to the study, the regular methods used by cybercriminals to exfiltrate data are database leaks, cloud applications, and removable USB drives. The public disclosure of data breach incidents resulted the organizations in financial repercussions and damage to the brand and reputation.

In December 2018, a similar research from McAfee revealed that the cybercriminals are generating 480 new threats per minute. In its report, McAfee Labs Threats Report: December 2018,” McAfee highlighted the IoT malware increased to 73 percent, while the cryptocurrency mining malware was up to 71 percent in the third quarter of 2018.

The McAfee Advanced Threat Research team has noticed a shift in dark web platforms. Several individual sellers have moved away from large markets and have opened their own specific marketplaces. Further, the McAfee stated the mobile malware declined by 24% and new threats ranged from fake mobile applications to mobile banking Trojans.

Website of BJP, India’s ruling party, hacked

BJP website

The website of Bharatiya Janata Party (BJP), India’s leading political party, has been hacked by unknown intruders. According to media statements, the website, which belonged to BJP Delhi, was attacked by a hacker/hacker’s group on May 30, 2019. The hackers, who go by the name handle Shadow_V1P3R, replaced the website content with ingredients and recipes for certain beef dishes. It’s believed that the incident took place during the sworn-in ceremony of Prime Minister Narendra Modi and his Council of Ministers at the Rashtrapati Bhavan.

The attack was first reported by a French security researcher Elliot Alderson. The website was taken down and brought to its original position. “We have noticed some unusual activity on our website. We are looking into it and will fix it at the earliest,” the party’s Twitter statement reads.

The hacking of government websites has become a continuous activity for hackers. Recently, several websites in Sri Lanka fallen victim to a series of cyber-attacks. According to the Sri Lanka Computer Emergency Readiness Team (SLCERT), a group of unknown intruders allegedly attacked numerous Sri Lankan websites, including other websites like Kuwait Embassy in Colombo, the Tea Research Institute in Talawakelle, the Rajarata University in Mihintale, and 10 other private institutions’ websites.

SLCERT stated that they’re investigating on the incident combinedly with the TechCERT and the Cyber Operations Center that operates under the Ministry of Defence.

Commenting on the incident Dileepa Lathsara, the CEO of TechCERT, the attackers targeted on vulnerable websites that are equipped with minimum cybersecurity measures. Lathsara stated that most of the affected websites were restored to their previous condition and urged citizens to fortify security measures to their websites.

In a similar incident, cybercriminals attacked Pakistan’s Ministry of Foreign Affairs and the Army websites recently. According to the spokesperson Mohammad Faisal, the ministry received several complaints from various countries reporting that the websites were inaccessible from February 16, 2019. It’s believed that the attack was originated from India, Pakistan’s news site Dawn reported.

Pakistan encountered a similar incident in November 2018, when hackers attacked almost all the banking websites in the country. Every person holding a bank account may have become vulnerable to cyber threats, as data from almost all the banks of the nation was stolen in a security breach. The incident was revealed by the Federal Investigation Agency’s (FIA) cybercrime chief, Captain (retd) Mohammad Shoaib.  In an interview with Geo News, he said, “Almost all [Pakistani] banks’ data has been breached. According to the reports that we have, most of the banks have been affected.”