Home Blog Page 317

Several websites in Sri Lanka attacked!

Sri Lanka cyber attack

Several websites in Sri Lanka have fallen victim to a series of cyber-attacks. According to the Sri Lanka Computer Emergency Readiness Team (SLCERT), a group of unknown intruders allegedly attacked numerous Sri Lankan websites, including other websites like Kuwait Embassy in Colombo, the Tea Research Institute in Talawakelle, the Rajarata University in Mihintale, and 10 other private institutions’ websites.

SLCERT stated that they’re investigating on the incident combinedly with the TechCERT and the Cyber Operations Center that operates under the Ministry of Defence.

Commenting on the incident Dileepa Lathsara, the CEO of TechCERT, the attackers targeted on vulnerable websites that are equipped with minimum cybersecurity measures. Lathsara stated that most of the affected websites were restored to their previous condition and urged citizens to fortify security measures to their websites.

In a similar incident, cybercriminals attacked Pakistan’s Ministry of Foreign Affairs and the Army websites recently. According to the spokesperson Mohammad Faisal, the ministry received several complaints from various countries reporting that the websites were inaccessible from February 16, 2019. It’s believed that the attack was originated from India, Pakistan’s news site Dawn reported.

The cyber-attack was the wake of the terrorist strike in Pulwama, Kashmir on February 14, 2019, that claimed the lives of 40 Indian CRPF personnel. The Pakistan-based terrorist group Jaish-e-Mohammed claimed the responsibility for the attack. “The IT team is currently occupied in thwarting the hackers’ onslaught. The website is functioning without any issues in Pakistan. However, visitors to the website from Holland, Australia, Britain, and Saudi Arabia are facing difficulty opening it,” Faisal said in a statement.

Pakistan encountered a similar incident in November 2018, when hackers attacked almost all the banking websites in the country. Every person holding a bank account may have become vulnerable to cyber threats, as data from almost all the banks of the nation was stolen in a security breach. The incident was revealed by the Federal Investigation Agency’s (FIA) cybercrime chief, Captain (retd) Mohammad Shoaib.  In an interview with Geo News, he said, “Almost all [Pakistani] banks’ data has been breached. According to the reports that we have, most of the banks have been affected.”

According to him, there are over 100 cases that the agency is currently been investigating. The agency has also arrested several gangs that have been involved in cybercrime and recovered the stolen money. One of the recent apprehended gang used to withdraw money from people’s accounts while masquerading themselves as military officials.

Configure your buckets else leaks are going to cost you

IaaS

With several benefits that accompany digital transition, adoption to a cloud environment has also left several cracks in the system, thereby opening several windows of vulnerability. In fact, among the enterprises in APAC that have embarked on the digital transformation, the cloud has the highest adoption rate with nearly 69 percent. But what about cloud security? As we, at CISO MAG, publish the Power List of powerhouses in cloud security, we hark back to the few major threats and vulnerabilities in the space.

It is very evident from the stats and figures doing the rounds that cloud, be it traditional or hybrid, will rule the roost as one-stop solution for data center solutions for the next decade or so, until newer methods come to fore. Around cloud, one single or rather the most potent name to come to everyone’s mind is Amazon Web Services (AWS). But, AWS Simple Storage Service (S3) buckets have often been marred by configuration errors from vendor’s end, making buckets from AWS perhaps having rather larger holes than the data it accommodates. The recent and the famous one being the leak at Facebook.

Cybersecurity firm UpGuard was the first to notice the glaring error and ended up finding two data breaches in two different regions. The first originated from Mexico-based media company Cultura Colectiva which exposed around 146 GB of data that contained over 540 million records detailing comments, likes, reactions, account names, FB IDs, and other sensitive information. The second was a separate database from a Facebook-integrated app named ‘At the Pool’ which exposed data via an Amazon S3 bucket. This database contained the backup information like fb_user_id, fb_user, fb_friends, fb_likes, fb_music, fb_movies, fb_books, fb_photos, fb_events, fb_groups, fb+checkins, fb_interests, and passwords, according to UpGuard.

AWS cannot be blamed here the data was stored without any kind of password protection and could have easily be accessed by anyone with a mediocre knowledge of cloud systems.

“The public doesn’t realize yet that these high-level systems administrators and developers, the people that are custodians of this data, they are being either risky or lazy or cutting corners,” said Chris Vickery, director of cyber risk research at UpGuard. “Not enough care is being put into the security side of big data.”

Detectify Labs took a deep dive into ‘AWS S3 access controls – taking full control over your assets’ on a blog. It notes that “If you are vulnerable, attackers could get full access to your S3 bucket, allowing them to download, upload and overwrite files.”  It points out the S3 bucket name is most often not a secret. Once an attacker knows the name of the bucket, he can leverage multiple misconfigurations to access or even overwrite data, “leading to three different scenarios. By using the AWS Command Line to talk to Amazon’s API, the attacker can: Get access to list and read files in S3 bucket; write/upload files to S3 bucket; Change access rights to all objects and control the content of the files (full control of the bucket does not mean the attacker gains full read access to the objects, but they can control the content).”

According to the research firm, the company may not even find out that the attacker has full access to S3 bucket. The key solution is to change the privileges of your buckets. “AWS are aware of the security issue, but are not likely to mitigate it since it is caused by user misconfigurations,” it adds.

Securing buckets are of the biggest issues with AWS. Even though, the security teams from Amazon can apply security policies for the entire cluster of containers but providing security to each pod is often beyond their control. And this makes the system vulnerable. Even when you are trying to communicate or troubleshoot with the pod, the insight will stop traffic between the host and the cluster resulting in a security blind spots around your pods. One method to combat this is to have two solutions on your cloud network, one for handling VM policies while the other for governing the containers. But the only problem with the deployment of the two-step system is the complications that accompany it. You have probably moved to cloud to make sure that data management is easier and free of risk, not to make it even more complicated.  Another major hurdle with AWS is the lack of visibility. There is a belief among several cybersecurity leaders of large enterprises that storing data on premises means better control and visibility, which is not often the case when the data is moved to cloud servers and containers.

Here is the thing, necessity for cloud adoption varies from company to company. And in most cases, the benefits of cloud computing depend on the kind of business the organization is. Just like with any tool, organizations ultimately must consider their risk profiles, staffing and access, resource allocation, and regulatory policies within the organization, and risk appetite before making a decision about cloud storage.

It all comes back to you. There are reasons why AWS is the behemoth in the space, it is one among the most reliable ones out there. All you need to do is check all the boxes for any configurational glitches.

Data orchestration startup Tealium secures $55 million

Building Pro-Active Security Hygiene Helps in Preventing Ransomware Attacks: Microsoft

Tealium, a provider of real-time customer data orchestration, recently secured $55 million in Series F funding round led by Silver Lake Waterman along with the participation from ABN AMRO Digital Impact Fund, Declaration Partners, Parkwood, and other existing investors. The U.S.-based company stated the new funding will be used to expand its data integration ecosystem, accelerate new product development, and market-reach, globally.

Founded in 2008, Tealium is focused on building a real-time customer data platform that meets the business requirements for protecting the privacy of customer data. It transforms present digital businesses with a universal approach to customer data orchestration like spanning web, mobile, offline, and Internet of Things devices.

Tealium claims that its AudienceStream customer data platform (CDP) allows organizations to manage diverse regulations in countries globally. The CDP connects customer data across technology stacks and digital assets, including websites, mobile applications, point-of-sale (POS) systems, and call centers, enabling data freedom and agility across the organization.

Commenting on the new investment Jeff Lunsford, the CEO of Tealium said, “Our customer data platform is the vendor-agnostic foundation that allows data to flow freely and securely across the organization — rendering it accessible and useful to every team and technology and solving departmental or technological silos that limit opportunity for data agility. By democratizing the data collection and delivery process, we help organizations meet the changing needs of their business and customers and protect the integrity of their data.”

“Tealium enables companies to overcome challenges related to customer data fragmentation by integrating and enriching data across sources in real time, while providing data governance and fidelity,” said Shawn O’Neill, Managing Director of Silver Lake Waterman. “Jeff and his team have built a robust platform, and we are excited to support the company’s continued growth and investment in innovation.”

“As a long-time Tealium customer, we’ve seen the benefit of the technology firsthand,” said Frank Verkerk, Chief Digital Officer of ABN AMRO. “Tealium has helped us streamline and standardize our data flows and has given us the tools we need to make better marketing and business decisions.”

WhatsApp draws flak from Indian government and Telegram creator Pavel Durov

The Ministry of Electronics and Information Technology (MeitY) of India has asked WhatsApp for details on the recent spyware attack, that allowed hackers to spy on users, and any corrective measures taken.

The Ministry also asked the authorities of WhatsApp whether any users in India have been affected in the incident, after which it will decide whether to issue an advisory to government officials, who use the messaging app, the Economics Times Reported.

“We sent an email to WhatsApp asking them to explain the vulnerability and steps undertaken to address the situation,” the Ministry said in a statement.  “We are concerned over this and we know this is a global issue, but we need to understand if any Indian users have also been hit by this. But this stokes the larger issue of national cybersecurity and how to regulate this sphere.”

Quoting the incident as “highly sophisticated attacks”, WhatsApp stated that it informed the U.S. law enforcement agencies about the incident for further investigation.

The comments from the Indian Ministry comes after WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. The Facebook-owned social messenger stated the spyware can exploit the mobile device, its calls, texts, and other data. It can also activate the phone’s camera, microphone, and able to perform other malicious activities. According to Facebook, the malicious spyware was developed by Israel-based cyber intelligence company NSO Group.

Following the attack, Pavel Durov, the creator of the popular messaging app Telegram, took to the internet to slam WhatsApp. In his blog post, Durov wrote an article, Why WhatsApp will never be secure, criticizing WhatsApp on its latest data breach.

“This news didn’t surprise me though. Last year WhatsApp had to admit they had a very similar issue a single video call via WhatsApp was all a hacker needed to get access to your phone’s entire data,” Pavel Durov stated in his blog post. Every time WhatsApp must fix a critical vulnerability in their app, a new one seems to appear in its place. All their security issues are conveniently suitable for surveillance and look and work a lot like backdoors.”

“Unlike Telegram, WhatsApp is not open source, so there’s no way for a security researcher to easily check whether there are backdoors in its code. Not only does WhatsApp not publish its code, they do the exact opposite: WhatsApp deliberately obfuscates their apps’ binaries to make sure no one is able to study them thoroughly,” Durov added.

WhiteHat Security and Rural Sourcing join hands to remediate application security threats

WhiteHat Security, an application security provider for enterprises’ businesses, recently announced its partnership with the U.S.-based IT outsourcing services provider Rural Sourcing to offer enhanced solutions to identify and remediate application-level exposures.

The new alliance will integrate the SaaS-based WhiteHat Application Security Platform with Rural Sourcing’s vulnerability remediation services to alleviate the challenges of DevSecOps and help organizations in digital transformation.

WhiteHat provides services that are required for organizations to secure the entire software lifecycle (SLC) from the development through deployment and operation. The WhiteHat Application Security Platform technology solutions include Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST).

“Companies looking to secure their digital business are acutely aware of application-level vulnerabilities but lack the resources to identify and fix them in a timely manner,” said Derek Perry, vice president, Innovation at Rural Sourcing. “Whether utilizing inhouse or offshore resources, there are significant challenges to overcome, which can be addressed by sourcing IT resources onshore. WhiteHat and Rural Sourcing bring a unique combination of technology and talent, which can identify and remediate application-based threats, ensuring a company’s digital business is properly defended.”

“The WhiteHat platform was designed to enable true DevSecOps and help companies catch critical vulnerabilities in their code before it’s too late,” said Debbie Klett, director of Channels, WhiteHat Security. “While we’ve always provided guidance on remediating these issues, the Rural Sourcing partnership will enable customers to leave that final step in the hands of some of the industry’s top experts, so they can focus on growing their business. We are thrilled to begin this joint effort in making application security more accessible for all organizations.”

Recently, NTT Security Corporation (Tokyo) signed a definitive agreement to acquire WhiteHat Security. Post-acquisition, WhiteHat Security will operate as an independent, wholly-owned subsidiary of NTT Security Corporation.

As per the new alliance, NTT Security will provide end-to-end cybersecurity solutions. Together, the two organizations will address enterprise security needs that range from IT infrastructure to critical business applications, covering the full lifecycle of digital transformation. The acquisition expands NTT Security’s portfolio, allowing its customers and partners to benefit from WhiteHat Security’s industry-leading, cloud-based Application Security Platform. WhiteHat’s customers and partners will have access to NTT Security’s consulting and advisory services, along with their next-generation platform-based Managed Security Services.

Cyber-attack affects over 460,000 online store accounts

data breaches, Verizon Data Breach Investigation Report

The popular online stores in Japan, UNIQLO Japan and GU Japan, recently revealed that it suffered a cyber-attack that affected more than 460,000 of its customers. Fast Retailing, the parent company behind the UNIQLO Japan and GU Japan online stores, stated the unknown hackers allegedly accessed its customers’ accounts from April 23, 2019, to May 10, 2019, following a credential stuffing attack.

According to Fast Retailing, the compromised information included, customer name, address, phone number, email address, gender, date of birth, purchase history, clothing measurements, and credit card information.

“It was confirmed on May 10, 2019, that an unauthorized login by a third party other than the customer occurred on the online store site operated by our company (UNIQLO official online store, gu official online store). Although the number of targets and the situation may change according to the progress of the future survey, we will report the facts confirmed at present and our response situation,” Fast Retailing said in a statement.

Citing the attack as a “list-type account hacking”, Fast Retailing stated this kind of attack is performed by using the user ID and password that may have leaked from other companies’ services. The company also notifying the customers to update their passwords to avoid further loss.

“This fraudulent login was performed from April 23 to May 10, 2019, by the method of “list-type account hacking (list-type attack)”, and the number of accounts logged-in illegally as of the present is 461,091 It will be. We deeply apologize to our customers and stakeholders for any inconvenience or concern. We will strive to further enhance security and ensure safety so that similar events do not occur,” the statement added.

Recently, the Japanese government announced that it will be hacking the IoT devices of its citizens. The new initiative is part of a unique survey the government will be undertaking with the intention of securing IoT devices of its citizens. The survey will be carried by the National Institute of Information and Communications Technology (NICT) with active involvement of the Ministry of Internal Affairs and Communications.

As part of the survey, employees of NICT will try to hack IoT devices of citizens using default passwords and password dictionaries. After this, they will prepare a list of insecure devices that uses default passwords or easy-to-guess passwords and will submit the list to relevant authorities, as well as internet service providers who will then alert the citizens and ask them to change passwords as well as secure their devices.

Donald Trump declares national emergency over cyber threats against U.S.

With an aim to protect the United States communications and computer networks from “foreign adversaries”, President Donald Trump has declared a national emergency over threats against American technology. The president signed an executive order which effectively bars U.S.-based companies from using foreign telecoms, which are believed to pose national security risks, the White House said.

The executive order does not name any company, but it’s believed that the move is expected to precede a ban on U.S. firms doing business with the Chinese telecommunications company, Huawei.

According to the White House statement, Trump’s order aims to “protect America from foreign adversaries who are actively and increasingly creating and exploiting vulnerabilities in information and communications technology infrastructure and services”.

“The order gives the secretary of commerce the power to prohibit transactions posing an unacceptable risk to the national security,” the statement added.

Following the executive order, the U.S. Department of Commerce declared the addition of Huawei Technologies and its affiliates to the Bureau of Industry and Security (BIS) entity list. The addition makes the U.S. companies not to sell or transfer technology to Huawei without a license issued by the BIS. The Chinese Telecom giant Huawei hit back after the announcement of the executive order. The company criticized the move as “unreasonable”.

“If the U.S. restricts Huawei, it will not make the U.S. safer, nor will it make the U.S. stronger. It will only force the US to use inferior and expensive alternative equipment, lagging behind other countries and ultimately harming US companies and consumers,” Huawei stated in a statement.

Huawei faced a similar issue last year during Australia’s Shadow Minister for Defence Richard Marles’s apprehension and a possible ruling toward Huawei ban from 5G networks citing cybersecurity concerns. Huawei published a letter to Australian members of Parliament over the comments made. The company vehemently stated that the rumors and comments were ill-informed and have no factual basis.

In the letter, Huawei had pointed out that it is Australia’s largest wireless technology provider, and that more than half of the nation relies on Huawei for communication. “Our telecommunications equipment connects millions of Australian businesses and consumers every day on the Vodafone, Optus, and TPG mobile networks. As focus turns to investment in the next generation of telecom technologies in Australia, cybersecurity is a key consideration for Australian policymakers … with our 5G investments in the United Kingdom, Canada, and New Zealand, the respective governments have taken up our offers for evaluation of our technology to ensure it abides by its cybersecurity protocols,” the letter reads.

Earlier in 2017, the U.S. Senator Jeanne Shaheen pressed for a federal government-wide ban of all Kaspersky Lab products in U.S. Shaheen cited that intelligence officials during a public hearing stated that they weren’t comfortable with using Kaspersky Lab software in computers at the intelligence agencies. Adding, “Americans were outraged by Russia’s interference in our presidential election, but a wider threat is Russia’s doctrine of hybrid warfare, which includes cybersabotage of critical American infrastructure from nuclear plants to electrical grids. Kaspersky Lab, with an active presence in millions of computer systems in the United States, can play a powerful role in such an assault. It’s time to put a stop to this threat to our national security.”

CrowdStrike and InPhySec join hands to accelerate cybersecurity solutions in New Zealand

Partnership

CrowdStrike, a provider of cloud-delivered endpoint protection services, recently announced that it’s going to partner with New Zealand-based cybersecurity firm InPhySec Security Ltd to address cybersecurity issues in New Zealand.

CrowdStrike offers instant visibility and protection across enterprises and prevents attacks on endpoints network. The company claims that CrowdStrike’s Falcon platform delivers real-time protection and actionable intelligence. It protects customers against all types of cyber-attacks by using artificial intelligence and Indicator-of-Attack (IoA) based threat prevention to stop known and unknown threats in real-time.

InPhySec is an information security company, which consists of seasoned security specialists with extensive experience in the New Zealand Security, Defence, and Intelligence Community. The new alliance integrates the cloud-native architecture of the CrowdStrike Falcon platform with InPhySec’s security platform to deliver faster, smarter, and more agile solutions to joint customers.

Speaking on the new partnership move Geoff Swaine, the Channel and Alliances Director of CrowdStrike said, “Working with InPhySec in this market has enabled our joint customers to benefit from the advantages of combining the global leader in cloud endpoint protection with the local expertise needed to address market needs. We look forward to working with InPhySec to deliver enhanced security outcomes for New Zealand.”

“We selected CrowdStrike as our technology for endpoint detection and response because in our assessment, CrowdStrike is at the forefront of endpoint security and by some margin. The reliability and fidelity of this technology are impressive, but more critically is its commitment and quality of its threat intelligence that underpins its capabilities. We did not see any other solution coming close to CrowdStrike” says Marc Barlow, Consulting Partner at InPhySec. “The beauty of the CrowdStrike technology, which is important to the New Zealand market is that we can protect organizations of any size. We have a numerous and rapidly growing number of public and private sector clients protected by our managed endpoint security service, and we have deployments ranging in size from 1-15,000 endpoints.”

In 2018, CrowdStrike closed a series funding of $200 million in a round led by investors General Atlantic, IVP, Accel Partners CapitalG, and March Capital. With this, the company has tripled its evaluation to more $3 billion. The company joined the ranks of the unicorns reaching a valuation of $1billion. The company has increased 140 percent in its last fiscal year, and the value of was up 172 percent making the company reach the $3 billion mark. “We are building the business to support massive volume across the globe,” CrowdStrike president, CEO, and co-founder George Kurtz stated in a blog post announcing the Series E financing. “This round of funding will accelerate the growth of our operations and the pace of our innovation and technology development.”

E-Commerce Cloud Company Webscale raises $14 million

Cloud Forensics

Webscale, a provider of software-as-a-service (SaaS) of cloud automation and orchestration tools for e-commerce companies, recently announced that it secured $14 million in a series B financing round led by Mohr Davidow Ventures along with the participation from Benhamou Global Ventures and Grotech Ventures. The California-based company stated the new investment will fuel the company’s growth and international expansion.

Webscale is an E-Commerce Cloud Company that delivers managed cloud hosting and integrated web applications. The Webscale platform provides retailers and enterprises with next-generation cybersecurity, bot management, application performance, image management, and cloud automation powered by machine learning.

It allows businesses to benefit from infinite scalability, improved cybersecurity, high performance, outage prevention, and simple management in multi-cloud environments, including Amazon Web Services, Google Cloud Platform, and Microsoft Azure.

Webscale claims that its predictive auto-scaling scheme restructures apps in response to high CPU load, memory usage, and incoming traffic volume and detects anomalies and remediates faulty apps, data planes, and load-balancing servers by reimaging fresh instances automatically.

Commenting on the new investment round Sonal Puri, the CEO of Webscale said, “Webscale continues to claim market share from legacy incumbents in the hosting, web application delivery, and security markets. Innovation and a relentless focus on customer success are responsible for our impressive revenue growth, coupled with a product offering that encompasses all the key capabilities needed to execute on the promise of the cloud.”

Recently, another SaaS startup Sqreen raised $14 million in a series A round of funding led by Greylock Partners along with the participation from existing investors Y Combinator, Alven Capital, and Point Nine. The San Francisco, California-based company helps developers monitor and protect their web applications from vulnerabilities and cyber-attacks.

Sqreen was founded in 2015 by Apple’s former security veterans Jean-Baptiste Aviat and Pierre Betouin. The startup offers an Application Security Management (ASM) platform with a technology known as Runtime Application Self-Protection Security (RASP), which is used to embed microagents into applications to identify threats. Sqreen claims that it offers real-time insights on suspicious activities to companies like ZipRecruiter, Le Monde, and BlaBlaCar.

Pierre Betouin, the CEO and co-founder of Sqreen also the former leader of Apple’s security Red Team, stated that Sqreen’s security platform protects from all the common attacks, including SQL injections, broken authentication, and cross-site scripting (XSS).

ClearDATA join hands with Health Sector Coordinating Council to address security in healthcare

Abnormal Security Partners with Microsoft to Boost Cybersecurity

ClearDATA, a cloud-based healthcare cybersecurity and compliance provider, recently announced that it partnered with the Healthcare and Public Health Sector Coordinating Council Cybersecurity Working Group (HSCC) to establish frameworks and best practices to minimize the risks of cyber threats across the healthcare industry.

ClearDATA helps healthcare organizations and professionals globally in protecting their sensitive information and critical applications which are available across the public cloud platforms. It provides a unique platform to build a secure and compliant digital health infrastructure in various HSCC task groups including Medical Device Security, Supply Chain, Telemedicine, Cybersecurity Best Practices, Regulation, and Future Gazing. ClearDATA claims that its innovative platform of solutions and services protect its clients from data privacy risks and scale their healthcare IT infrastructure on a regular basis.

The new collaboration allows ClearDATA to work within HSCC to increase the national confidence in the healthcare system by enhancing technology and policy frameworks that mitigate cybersecurity threats.

Commenting on the new alliance, Chris Bowen, the founder and Chief Privacy & Security Officer at ClearDATA said, “As a leader focused exclusively on the healthcare cloud, it is important for us to contribute in ways to make healthcare better. Partnering with the Healthcare and Public Health Sector Coordinating Council (HSCC) gives us a seat at the table to contribute, serve and make patient data more resilient ultimately improving the patient experience.”

“There is a shared responsibility among healthcare stakeholders for patient safety and by collaborating across the public and private sectors, with new members like ClearDATA, we are able to build a ‘security-by-design’ framework for health tech innovation,” said Greg Garcia, executive director of the Healthcare and Public Health Sector Coordinating Council (HSCC), Cybersecurity Working Group.

A recent report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent. The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations.

The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.