Home Blog Page 320

Orange acquires cybersecurity firm SecureLink

FireEye Acquires Respond Software

Orange, an IT and telecommunications services provider, recently announced that it has entered into an agreement to acquire cybersecurity services provider SecureLink in a cash deal of €515 million ($577 million). The latest acquisition allows Orange to expand its reach in the European cybersecurity industry.

SecureLink is an independent cybersecurity services provider in Europe, with headquarters in Sweden, Belgium, the Netherlands, the UK, Germany, Denmark, and Norway. Founded in 2003, SecureLink provides a range of cybersecurity services to enterprises globally, including specialized security consulting, security maintenance and support with 24/7 service desks (SOCs), advanced managed detection and response capabilities (MDR).

Speaking on the new acquisition, Hugues Foulon, the Executive Director of Cybersecurity at Orange, said, “Cybersecurity is a growing priority for companies of all sizes, and we believe the two most important success factors are Scale and Proximity. Scale because today’s threats are global, complex, and require matching protection capabilities. Proximity because in the global IT world, you want a trusted local partner to secure your most strategic assets. With the acquisition of SecureData and SecureLink, Orange has the highest scale to anticipate and fend off attacks, as well as local defense teams in all the main European markets, positioning the combined organization as the go-to defense specialist. I am looking forward to building the integrated organization with Michel [Van Den Berghe, CEO of Orange Cyberdefense], Thomas Fetten and all the teams”.

Thomas Fetten, the Chief Executive Officer at SecureLink, commented “We have been very impressed by the ambition and successful development of Orange Cyberdefense over the past few years, and are very excited to build a pan-European leader of cybersecurity together. Orange Cyberdefense, SecureData and SecureLink are highly complementary and share a common vision for the sector, and the combined organization will be in a phenomenal position to address the needs of our customers, partners and employees.”

Recently, Orange acquired cybersecurity solutions provider SecureData and its subsidiary SensePost. SecureData provides integrated security solutions designed to assess risks, detect threats, protect customer’s IT assets, and respond to security incidents. The United Kingdom-based company claims that its consulting arm SensePost is expert in tackling cybercrime and carrying out security research and penetration testing.

SecureData also owns an advanced cyber-SOC (Security Operations Center) in the UK dedicated to monitoring and responding to security breaches on behalf of its customers. Through its technical cooperation, SecureData will help strengthen Orange’s cyber defense posture by bringing a new source of expertise and innovative technology. The new acquisition deal also reinforces Orange’s international reach, especially in Europe.

Continuous innovation is the key to cyber safety

Uncertain Data Sharing Practices Keep Educational Organizations at Risk: Research

Contributed by Tony Cole, Chief Technology Officer, Attivo Networks

When the first automobile was manufactured, it wasn’t very safe.

Many drivers and passengers died because safety simply wasn’t a motivating factor in the design and creation of the automobile. Since then, a parade of features has been added to increase car safety. These initially included brakes and lap belts, then seatbelts, directional  blinkers, headlights, taillights, brake lights, fog lights, and eventually advanced innovations like anti-lock brakes, traction control, airbags, lane keeper assists, auto braking, lidar, backup cameras, and front facing cameras.

Manufacturers didn’t just iterate on the same things. They improved the existing safety features and continued to innovate by adding new systems and features each decade. Why? Because even though cars are much safer, many people still die in car accidents each year. There are plenty of reasons: drivers make mistakes, people don’t obey rules, systems fail, Mother Nature throws us curveballs. When will we stop adding safety features to vehicles? Probably not in the foreseeable future—if ever. Not until we can protect everyone all the time. We will continue to innovate to try and save lives. It’s what humans do.

When the Internet was initially assembled, it was designed for communication and sharing. As with automobiles, safety simply wasn’t a consideration. No one knew that it would grow to what it is today. They couldn’t have predicted that it would become a fabric connecting all of society and a driver of the global economy.

Since no one had foreseen its potential for market penetration and global growth, protecting people and their data on the Internet wasn’t an initial priority. As attackers began to wreak havoc though via webpage compromises, distributed denial of service attacks, system compromises leading to data theft, data destruction and data integrity manipulation, preliminary safeguards were added to make the Internet a less dangerous place for businesses, consumers, and governments.

Unsurprisingly, it didn’t work. Anti-virus software was added to endpoints. Intrusion detection systems, firewalls, intrusion prevention systems, data leakage prevention systems, and much more were added at network perimeters across the enterprise. Yet intrusions continued, escalating in scope, severity, and number.

The reasons for the failure of these early measures are myriad, but one major issue is that most security vendors focused completely on preventative technology to stop breaches from happening rather than on detecting them once the adversary breached the network. We need to do both. The sophistication of attacks continues to grow as needed to accomplish attacker goals. Just as car safety advancements were critical to making our roads less dangerous, innovation must continue in cybersecurity. This means adopting a new perspective on the problem.

Let’s return to our car analogy. Remember all the innovative safety features added to reduce automobile accidents? They have certainly helped a lot, but accidents still happen frequently. Manufacturers understand this and address it by adding systems designed to help accident victims in today’s cars. Why? We know—and unfortunately accept—that they are going to happen, and we prepare for them. Some manufacturers have accident detection systems that close the windows, cinch up the seatbelts, brake the car automatically, deploy airbags on impact, call the authorities, and much more. Many municipalities even help save lives by monitoring high-traffic areas to enable quicker accident response.

In cybersecurity, it’s time to admit that system breaches are inevitable and innovative technologies must be more broadly applied to detect those breaches. If you can’t always stop the attacker (and you can’t), you need to detect them when they bypass preventative tools. Fast and reliable detection will help to ensure they aren’t successful in accomplishing their goals.

Today, deception technology is one of the more innovative tools that can help when the adversary infiltrates the enterprise. It sounds complex, but in reality, it’s a simple tactic to ensure the attacker is quickly detected and unsure of the environment. If we consider our car safety analogy, one innovation—fog lights—allowed drivers to see both the road and each other despite inclement weather. In internet safety, we’re doing the exact opposite: through deception, we’re literally creating a fog of confusion for the attacker to prevent them from understanding (or clearly seeing) the environment they’re wandering through. They have no fog lights. They can’t see, and they inevitably run into things we’ve placed in the network that immediately alert defenders of a breach. What makes it even more fun is that proper deception incorporates gold images as decoys. Even if the attacker had the cyber equivalent of fog lights, they would still hit things that immediately cause an alert. Even with increased visibility on the network around them, they still wouldn’t be able to tell production systems from decoys, real credentials from decoy credentials, real applications from decoy applications, or real data from decoy data.

We have a long road in front of us to make the internet completely safe. The truth is, we may never reach that destination. But by taking advantage of new technology and perspectives to mitigate breach impact and adopting an innovative approach to security, we can continue to make substantial and meaningful progress toward that goal.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Skybox Security and Indegy join hands to boost cybersecurity in critical infrastructure

U.S. and Australia to Jointly Develop Cyber Training Platform

Skybox Security, a cybersecurity management platform, recently announced its alliance with cybersecurity startup Indegy to help organizations better understand the security posture of hybrid IT and operational technology networks.

Skybox provides cyber risk management services for enterprises to address evolving security challenges. The company claims that its analytics, automation, and intelligence platforms enhance the efficiency and performance of security operations in vulnerability and threat management for the organizations globally.

Founded in 2014, Indegy develops Industrial Control System (ICS) networks, which help protect systems from cyber threats, malicious insiders and human error by providing visibility and control. The Israel-based startup claims its ICS suite combines cybersecurity expertise with hands-on industrial control knowledge, deployed by manufacturing, pharmaceutical, energy, water, and other industrial organizations to protect their systems from cyber-attacks.

The technical integration of Skybox and Indegy will help organizations see and understand risks in connected IT and operational technology networks.

“OT networks have been a mystery to IT security teams,” said Skybox Security VP of Products Amrit Williams. “But more and more, CISOs are being tasked with getting a handle on security in OT environments. That starts with literally being able to see and understand the connections between the corporate and production networks, visualizing how the two impact one another’s risk of attack. Our integration with Indegy further strengthens the visibility and insight we give customers with hybrid IT-OT networks, so they can accurately prioritize and respond to those risks.”

“Having a bird’s eye view of a hybrid IT-OT network is hugely valuable,” said Indegy CTO Mille Gandelsman. “Where Skybox provides a high-level view and insight into the corporate network, Indegy allows users to maintain deep visibility into industrial control system networks and device-level changes and provides rich, reliable information. Rolling these capabilities into a single solution will help align IT security teams with OT engineers to ensure cyber risks are understood and remedied without undue disruption.”

Last year, Indegy raised $18 million Series B round of financing led by Liberty Technology Venture Capital. The other investors in the round included Centrica PLC, O.G. Tech Ventures and existing investors Shlomo Kramer, Magma Venture Partners, Vertex Ventures, and Aspect Ventures. The company stated that the new funds will help to expand its marketing reach in the cybersecurity industry.

Indegy also announced the appointment of Joe Scotto from BAE Systems as Chief Marketing Officer and Todd Warwick from Imperva as Vice President of Sales to its management team.

Censinet bids to protect hospitals from cyber-threats; raises $7.8 million in funding

A startup has emerged from Boston aiming to tackle security incidents like WannaCry, head-on. Censinet announced its foray into the market in a bid to woo hospitals and other healthcare providers manage threats emerging from the cyberspace. And that’s not all, the startup also raised $7.8 million in a Series A funding round led by HLM Venture Partners and Cedars-Sinai Health System.

Post the funding, Vin Fabiani, partner at HLM Venture Partners, is set to join the company’s board. Censinet plans to utilize the funds to develop its platform, market its products, and double its headcount.

Ed Gaudet, Censinet’s founder and CEO, is of the opinion the way hospitals and healthcare systems record medical date is fundamentally broken. “What’s happened over the last 10 years or so is healthcare went from a largely paper-based industry to moving everything electronic onto health records, then doubling down on medical device and IoT devices connected to the internet, exponentially increasingly the risk,” he said in an interview with Xconomy. “If you’re talking to hospitals, there’s very few who know who all their vendors are.”

Currently Censinet platforms are used by Bay State Health, Intermountain Healthcare, and Cedar-Sinai.

A recent survey revealed that employees at U.S. health care institutions may be susceptible to phishing emails. The report, Assessment of Employee Susceptibility to Phishing Attacks at US Health Care Institutions, authored by Dr. William Gordon of Brigham and Women’s Hospital and Harvard Medical School in Boston stated that many healthcare organizations remain vulnerable to phishing attacks. Another report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

Kenya announces new guidelines on cybersecurity for financial sector

Kenya Reports 37.1 Mn Cyberattacks in Q4 of 2019: Report

The banking regulator of Kenya, the Central Bank of Kenya (CBK), recently announced the launch of new guidelines on cybersecurity for the financial services sector in the country. According to Patrick Njoroge, the Governor of (CBK), the new guidelines on cybersecurity for payment services will help in curbing emerging threats in the financial industry.

“The regulatory and advisory initiatives are targeted towards safeguarding Kenya’s financial sector from cybercrime,” said Njoroge at the launch of Kenya Bankers Association (KBA) 2019 Card, Mobile, and Online Safety Awareness Campaign. “As a result, a single attack on any given commercial bank could have a devastating effect on the entire financial services system.”

“While this is an inspiring development, financial fraud is among the challenges that threaten progress in the adoption of new technologies. As an industry, we firmly believe that it is through cross-sector collaborations that we can defeat fraud and ensure a sustainable environment for growth,” said Habil Olaka, the CEO of KBA.

“It is for this reason that the banking industry has over the past few years devoted more resources towards containing fraud through staff capacity building and customer education programmes. Through the banking industry’s collaborations with the CBK and the Communications Authority of Kenya, we hope to continue securing payment platforms and innovative products in the financial sector,” Olaka added.

The Central Bank of Kenya proposed the new guidelines for cybersecurity standards last year in order to fight against banking frauds and to get a better view of the new threats that payment service providers are facing. According to the new guidelines, banks and mobile payment operators are required to file cybersecurity reports with the industry regulator. The firms are asked to notify the Central Bank of Kenya within 24 hours of any suspicious activity and also need to submit a quarterly report with CBK on the incidents experienced and how they were resolved.

In a recent press release, the Government of Kenya has dispelled the reports surrounding hacking of the National Integrated Identity Management System (NIIMS), also called Huduma Namba, as fake news. In a statement, the Ministry of Interior stated that no incident, whatsoever, has occurred.

Over the weekend, social media and local blogs were abuzz with news that Enock, an ICT student from University of Nairobi (UON) had hacked into the Huduma Namba system and deleted data collected from 21 million people.

Data breach exposes medical information of Michigan residents

Health care data breaches

A data breach at Inmediata Health Group, a healthcare billing and administrative service provider, exposed the personal and medical data of Michigan residents, the Detroit News reported.

The Puerto Rico-based healthcare center stated that a technical glitch in the webpage settings permitted search engines to expose internal webpages online, which contained patients’ sensitive information. According to Inmediata, the exposed data included patients’ name, addresses, social security numbers, and other personal health information.

The security officials at Inmediata halted the website temporarily and contacted a digital forensic firm to investigate the incident. The center clarified that there was no discovery of any misuse of the exposed data. The affected patients are suggested to monitor their financial accounts for any fraud transactions.

“We have an opportunity to improve Michigan law by adding the Attorney General’s Office as a required state department to be notified by companies impacted by data breaches. Data breaches can be devastating to the affected individuals. It’s important this office provide affected customers with any and all available resources to help limit the effects of this — or any — breach. And today, we’re doing just that,” said Dana Nessel, the Michigan Attorney General.

“The data security incident that may have involved the limited personal and medical information of some of its customers’ exposed online due to a webpage setting that permitted search engines to index internal webpages that are used for business operations. To date, we have not discovered any evidence to suggest that any information potentially involved in this incident has been subject to actual or attempted misuse,” Nessel added.

A recent report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations. The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

Cloud Computing startup Aiven secures $9 million funding

Aiven, a cloud computing startup that provides a managed cloud database and messaging services, recently raised €8 million ($89,56,000) in a Series A funding round led by Earlybird Venture Capital. Lifeline Ventures and Nokia chairman Risto Siilasmaa were the other participants in the financing round.

The Finland-based startup stated the new investment will be used to enhance Aiven’s cloud data platform with more integrated solutions and expand its business reach globally. Apart from funding, Aiven added Hendrik Brandis, the partner and co-founder of Earlybird, into its board of directors.

Established in 2016 by security professionals Hannu Valtonen, Heikki Nousiainen, Mika Eloranta, and Oskari Saarenmaa, Aiven is a SaaS-based ISO 27001 certified provider of cloud data platform, operating managed open-source database, event streaming, cache, search, and graphing solutions. The company claims that all its services cover all the needs of internet applications.

Speaking on the new investment, Oskari Saarenmaa, the co-founder and CEO at Aiven, stated, “We see a tremendous number of companies around the world now implementing their new real-time data platforms in the cloud. The new funding will allow us to better cater to their requirements.”

“Aiven’s ability to outcompete established market players and build a highly capital efficient international business is impressive. We’re eager to become a part of the story and continue growing the company,” discusses Brandis.

Recently, another SaaS startup Sqreen raised $14 million in a series A round of funding led by Greylock Partners along with the participation from existing investors Y Combinator, Alven Capital, and Point Nine. The San Francisco, California-based company helps developers monitor and protect their web applications from vulnerabilities and cyber-attacks.

Sqreen was founded in 2015 by Apple’s former security veterans Jean-Baptiste Aviat and Pierre Betouin. The startup offers an Application Security Management (ASM) platform with a technology known as Runtime Application Self-Protection Security (RASP), which is used to embed microagents into applications to identify threats. Sqreen claims that it offers real-time insights on suspicious activities to companies like ZipRecruiter, Le Monde, and BlaBlaCar.

Pierre Betouin, the CEO and co-founder of Sqreen also the former leader of Apple’s security Red Team, stated that Sqreen’s security platform protects from all the common attacks, including SQL injections, broken authentication, and cross-site scripting (XSS).

Hackers use Magecart attack to compromise online stores in US and Canada

Data leak

A hacker group named Magecart is responsible for the recent data breach that impacted 201 online campus stores in the United States and Canada. According to the cybersecurity firm Trend Micro, the attackers allegedly used a skimming script, a malicious code, designed to steal the data from 201 online stores that were catering to 176 colleges and universities in the U.S. and 21 in Canada.

The security researchers at Trend Micro stated that they detected the attack, dubbed as Magecart attack, against multiple campus online store websites on April 14, 2019, which were injected with a malicious skimming at their payment checkout pages. The hackers use skimming script to compromise the card information and personal details entered on the payment page by users. Trend Micro stated the attackers also compromised PrismWeb, an e-commerce platform designed for college stores by PrismRBS.

The researchers at Trend Micro disclosed their findings to PrismRBS. “On April 26, 2019, PrismRBS became aware that an unauthorized third-party obtained access to some of our customers’ e-commerce websites that PrismRBS hosts. Upon learning of this incident, we immediately acted to halt the current attack, initiated an investigation, engaged an external IT forensic firm to assist in our review, notified law enforcement and payment card companies. Our investigation is ongoing to determine the scope of the issue, including who and what information may have been impacted. Based on our review to date, we have determined that an unauthorized party was able to install malicious software designed to capture payment card information on some of our customers’ e-commerce websites,” the company said in a statement.

“We are proactively notifying potentially impacted customers to let them know about the incident, the steps we are taking to address the situation, and steps they can take to protect their end users.  We are taking steps to further strengthen the security of our systems, including enhanced client-side and back-end monitoring tools and a comprehensive end-to-end audit of our systems. Once our investigation concludes, we will be providing our customers with additional information and guidance,” the statement added.

Air National Guard and UMass Dartmouth join hands to boost cybersecurity

The Air National Guard of Massachusetts recently announced its partnership with the University of Massachusetts, Dartmouth to establish collaborative programs in the field of cybersecurity. Both the organizations have signed a Memorandum of Understanding (MOU) aimed at a mutual benefit for future training and interaction between military personnel and university students.

As per the partnership deal, the Airmen of the Air National Guard will offer relevant academic and cybersecurity courses to the university students. While the UMass Dartmouth will assist Air National Guard’s 102nd Intelligence Wing by providing access to mobile training teams and the latest developments in computer forensics.

Speaking on the new alliance, Robert E. Johnson, the Chancellor of UMass Dartmouth, said, “We’re excited to work with the 102nd to strengthen the cybersecurity of our nation. I want you and your colleagues to know that UMass Dartmouth is fully committed to making sure that our men and women serving in the armed services today and in the future have both the skillset and mindset to take on any foe or any enemy.”

“The University of Massachusetts Dartmouth is a world-class research university with an incredible cybersecurity and engineering perspective that is a natural fit,” said 102nd Intelligence Wing Commander Col. Virginia I. Gaglio. “The Air National Guard strengthens its forces by embracing local, state, federal and global partnerships. Today we’re celebrating our relationship with the University of Massachusetts Dartmouth which is at the very roots of the Air National Guard, ensuring we have the right Airmen, education and tools to be our nation’s premier fighting force.”

Recently, the U.S. Army partnered with DataPath, a provider of advanced and secure communications solutions, to provide communications services in support of Homeland Defense and Defense Support of Civil Authorities. As per the contract, DataPath will supply satellite communications hardware, software and systems installation, and maintenance services to support communications interoperability between a variety of military and civil response organizations.

The program supports the United States Northern Command (USNORTHCOM) Deployable Communications Capabilities Systems (DCCS), including North American Aerospace Defense (NORAD), USNORTHCOM Subordinate and Component Commands, mission partners, and Army North (ARNORTH).  USNORTHCOM Theater of Operations commands and controls the Army, Navy, Air Force, and Marine Corps forces in the North American continent.

Kenyan government dismisses NIIMS hack

Kenyan government

The Government of Kenya has dispelled the reports surrounding hacking of the National Integrated Identity Management System (NIIMS), also called Huduma Namba, as fake news. In a statement, the Ministry of Interior stated that no incident, whatsoever, has occurred.

“Kindly treat fake news circulating claiming Huduma Namba has been hacked with the contempt they deserve. The exercise is ongoing with 23.5 million people already registered. Report any misleading information you spot,” the ministry told on Twitter.

Over the weekend, social media and local blogs were abuzz with news that Enock, an ICT student from University of Nairobi (UON) had hacked into the Huduma Namba system and deleted data collected from 21 million people.

Interior Ministry spokesperson Wangui Muchiri also concurred on Twitter, “News circulating claiming to have hacked Huduma Namba utterly false. The exercise is going strong with 23.5 million secure registered persons.”

Two years ago, India also was under the spotlight for similar incidents, except they weren’t fake news. From the beginning of 2017, numerous reports had emerged stating a massive amount of data breach. Information of the citizens, like address, Aadhaar number, and other sensitive data like bank details were reportedly published online. This information was gathered by critical departments and ministries sites.

As per reports, the breaches, though many yet to be confirmed, did cost the data of nearly one billion Indian citizens and Aadhaar had become one of the biggest tools that infringed the privacy of nearly every citizen of India. This was until the Supreme Court of India made a landmark judgement stating that Right of Privacy is a Fundamental Right overruling an earlier bench judgment and ordered that Right to Privacy is intrinsic to Right to Life granted under Article 21 of the Constitution of India.