Home Blog Page 332

Automotive cybersecurity on the wrong road: Report

Connected Cars

Flooring the accelerator pedal of a secure vehicle may still be a thing of the future. According to a recent study by Ponemon, nearly 30 percent of companies in the automotive segment do not have a proper cybersecurity team to handle its technology and security infrastructure, let alone secure smart cars. The state is so dire that many do not even engage a third party vendor to secure the software in the connected cars.

“As more connected vehicles hit the roads, software vulnerabilities are becoming accessible to malicious hackers using cellular networks, Wi-Fi, and physical connections to exploit them,” data protection research group the Ponemon Institute said in the report. “Failure to address these risks might be a costly mistake, including the impact they may have on consumer confidence, personal privacy, and brand reputation.”

The study also pointed out that nearly 63 percent of all vehicle manufacturers do not even test half of their software, hardware and other technology deployed in their vehicles. The study sampled 15,900 IT security practitioners and engineers in the automotive industry.

“Unauthorized remote access to the vehicle network and the potential for attackers to pivot to safety-critical systems puts at risk not just drivers’ personal information but their physical safety as well,” the study found.

As further detailed in the study, “Seventy-three percent of respondents surveyed in our report say they are very concerned about the cybersecurity posture of automotive technologies supplied by third parties. However, only 44 percent of respondents say their organizations impose cybersecurity requirements for products provided by upstream suppliers.”

Vehicle hacking isn’t just a theory. In 2016, Nissan had to shut its proprietary app NissanConnected EV for its Leaf line-up after it was found that hackers could access the cars’ climate control and other battery operated features to drain the batteries. Also, in 2015, automaker Fiat Chrysler had to issue a recall for almost 1.4 million vehicles after researchers Charlie Miller and Chris Valasek of Wired demonstrated a wireless hack on Jeep Grand Cherokee, taking over the controls of the dashboard, steering wheel, powertrain, and even the brakes.

Recently, WikiLeaks released documents blowing a whistle on the CIA suggesting journalist Michael Hastings’s fatal car crash triggered by a car hack. In 2013, Hastings died after the car he was driving abruptly sped up and crashed into a tree. Media has, however, considered this to be a conspiracy theory, but has given into the potential havoc a hacked car can wreak.

Stealth mode startup Blue Hexagon raises $31 million

Start up funding

Network security provider Blue Hexagon, which has recently emerged from stealth mode, raised $31 million investment in a funding round led by Benchmark and Altimeter. Founded by security veterans Nayeem Islam and Saumitra Das, Blue Hexagon claims that it launched the first real-time and deep learning platform for network threat protection.

The company helps enterprises prevent cyber threats with its deep learning cybersecurity platform for network security. Blue Hexagon offers a security platform which is designed as a modern Software-as-a-Service (SaaS). It claims that its security solutions detects known and unknown network threats, including zero-day malware variants, automatically delivering a verdict, and blocking threats in sub-seconds.

“With four new, unique malware samples released every second, traditional security methods can’t keep pace with the speed and scale of hacker innovation,” said Nayeem Islam, CEO of Blue Hexagon. “A new approach is needed, and recent advancements in deep learning make it the ideal technology to address the velocity and volume of attacks. Blue Hexagon is applying our expertise in deep learning to detect network threats at all times, in sub-seconds, and at wire speed.”

“The state of the art for network security until now has been sandboxes and signatures. There hasn’t been a new approach to tackle the hundreds of thousands of malware variants that are created every day. Blue Hexagon changes the paradigm; their technology is a big leap forward in the arms race against the bad guys,” said Eric Vishria, General Partner at Benchmark.

Chinese security head pulls a practical joke and steals from his own bank

HUAXIA BANK

This may seem like a scene straight out of a heist movie, but a Chinese programmer did something as spectacular. Qin Qisheng, a former manager in Huaxia Bank’s technology development centre, stole $1 million in free cash by exploiting a loophole in the bank’s core operating system. In the Huaxia Bank, the withdrawals made in midnight were not recorded. After discovering the flaw way back in 2016, he inserted a few scripts into the system where he could make transactions without triggering an alert.

For nearly a year, made transactions of between 5000 and 20,000 yuan, until by 2018 where he amassed nearly seven million yuan without the knowledge of anyone. Most of the money stayed in the dummy account while a few were invested in stock market.

Even though his bank accept his explanation of testing the security of the bank and that the money was  simply resting on a dummy account he had created, the authorities did not buy it and have sentenced Qin for theft.

“Qin Qisheng said that the matter was complicated and involved lots of work … he believed the bank would not pay attention even if he reported it,” a bank representative told the trial. “We think this reason for not reporting is legitimate,” he added.

“The core business system of Hua Xia Bank was bought from overseas supplier, it was designed without considering the problem of night trading,” Qin said during his trial. “The customer generally would not report to the bank, [so] we were not informed about this situation. The problem was definitely there, the bank just couldn’t find the reason.”

No security breach occurred, SBI clarifies

State Bank of India

State Bank of India (SBI) clarified that no data breach occurred in their banking system. Responding to the recent media statement about failing to safeguard the financial records of its customers, SBI officials declared that there was no incident of customer data loss.

Responding to media queries on recent reports of data leakage involving the bank, SBI chairman Rajnish Kumar said, “Customer data security is the top most priority for us. None of our customers lost data, there was a gap in the process that caused the error, but no incident of customer data loss was reported. Also, no customer-identifiable information, username or passwords of any account holder, was kept on the system.”

“We are reviewing the entire systems. We have been examining the issue in totality to ensure complete safety and security of data and storage.” Kumar added.

The declaration comes after TechCrunch reported that an unprotected SBI’s server allowed potential attackers to view the data of millions of SBI account holders. It’s believed that the back-end text message system of SBI’s mobile banking services exposed the sensitive information, including customers’ phone numbers, partial account numbers, balance details, recent transactions, and other sensitive information. It’s unclear that how long the insecure database, that store data from SBI’s Quick, YONO app, and other cell-based banking services, exposed the customers’ data online, the publisher stated.

In order to advance the preparedness of Indian banks against cyber-attacks, the RBI is working on enhancing cybersecurity mechanisms. The central bank announced an enhanced security mechanism as part of its agenda for the fiscal year 2018-19 to provide high-level protection against cybersecurity threats.

The RBI’s report said the new agenda includes taking effective steps to initiate the process of developing a cybersecurity culture, endeavor to make cybersecurity a responsibility, and ensure confidentiality, integrity, and availability of information system and resources. According to the report, the new private sector and foreign banks accounted for 36 percent each of all cyber frauds reported in debit, credit, and ATM cards.

 

Zero Trust security provider Aporeto raises $20 million

Startup funding

Aporeto, an Identity-Powered Security services provider, recently announced that it has raised $20 million in a series B funding round led by Comcast Ventures along with the participation of existing investors Wing VC, Norwest Venture Partners, and others. As a result of the funding round, David Zilberman, the managing director of Comcast Ventures, will now be on the board of directors of Aporeto.

The California-based company stated the new funds will support the market expansion and innovation plans for its identity-based segmentation solution for cloud applications and networks. Aporeto provides Zero Trust security solutions for microservices, containers, and cloud applications to prevent potential cyber risks by authenticating all communications with a cryptographically signed identity assigned to every workload.

The company claims its Identity-Powered Security makes an identity-based segmentation method that implements Zero Trust security. Aporeto’s security platform provides the ultimate segmentation for modern applications based on cryptographic workload.

Speaking on the new investment move Jason Schmitt, CEO of Aporeto said, “The market is recognizing that cloud adoption is compromising the effectiveness of last-generation network security tools designed for static data centers and IP addresses. The automation, flexibility, and scale of cloud environments demand identity-based security that can adapt dynamically and secure absolutely. We’re really excited about the incredible quality of the new investors joining Aporeto and the tremendous market validation and geographic expansion that they bring to our team.”

“We are excited to work with the Aporeto team as they rapidly expand their unique approach to securing cloud applications and networks,” said David Zilberman, managing director of Comcast Ventures. “Aporeto is taking a unique approach to securing dynamic cloud workloads at scale and disrupting the network security incumbents that are still trying to shoehorn static, appliance-based solutions into a cloud environment where they don’t fit.”

Google to offer anti-hacking tools ahead of EU elections

Google Announced US$1 Million for its “Be Internet Awesome” Initiative

Search engine giant Google announced that it’s going to offer anti-hacking technology, named as Project Shield, to political organizations in Europe ahead of the European Union elections in May 2019, the Telegraph reported.

The technology used in Project Shield will safeguard websites from DDoS attacks by using a technique called Reverse Proxy. This technique monitors the website traffic and scans it for malicious content.

Jigsaw, Google’s experimental incubator, said it will offer free cybersecurity protection to political parties and candidates to defend elections from digital attacks. Jigsaw was previously developed and used to protect news organizations and human rights groups in the U.S. midterm elections for a similar purpose.

“Project Shield was launched in 2016 to protect independent news and human rights organizations from DDoS attacks, but in the wake of major election breaches and targeted political cyber-attacks, Project Shield can now be used to give political groups the same defense,” said Scott Carpenter, Managing Director of Jigsaw.

Recently, Google was fined for 50 million euros (around $57 million) by the French data regulator CNIL (National Data Protection Commission) for violating the General Data Protection Regulation. The data protection watchdog stated it had levied the fine for Google’s lack of transparency and valid agreement regarding ads personalization. The regulator also said that Google didn’t sufficiently inform the people about how it collected the users’ data to personalize ads.

The issue started when CNIL received complaints from the associations, None of Your Business (NOYB) and La Quadrature du Net (LQDN) in May 2018. The associations complained on Google for not having a valid legal basis to process the personal data of the users for ads personalization, as mandated by the GDPR.

Orange announces acquisition of SecureData

Acquisition

Orange, a provider of global IT and telecommunication services to multinational companies, recently announced the acquisition of cybersecurity solutions provider SecureData and its subsidiary SensePost. SecureData provides integrated security solutions designed to assess risks, detect threats, protect customer’s IT assets, and respond to security incidents. The United Kingdom-based company claims that its consulting arm SensePost is expert in tackling cybercrime and carrying out security research and penetration testing.

SecureData also owns an advanced cyber-SOC (Security Operations Center) in the UK dedicated to monitoring and responding to security breaches on behalf of its customers. Through its technical cooperation, SecureData will help strengthen Orange’s cyber defense posture by bringing a new source of expertise and innovative technology. The new acquisition deal also reinforces Orange’s international reach, especially in Europe.

Commenting on the new acquisition deal Hugues Foulon, the executive director of strategy and cybersecurity activities at Orange said, “We are very proud and happy to announce the acquisition of SecureData, which will mark a major milestone in Orange’s development in Europe’s cybersecurity market. SecureData, just like Orange Cyberdefense, has successfully made the transition toward Managed Security Services, and shares the same passion for Cyber. We will progressively co-build together the operational and commercial synergies, with the patronage and experience of Michel Van Den Berghe, CEO of Orange Cyberdefense. Cybersecurity has become a critical element for both large and small companies as they evolve in an increasing digital-reliant world.”

Ian Brown, executive chairman at SecureData stated, “We are both thrilled and excited to be joining the Orange Cyberdefense family. Both organizations share the same vision and aspiration for the cybersecurity market and have many complimentary services and skills. By being part of Orange, we will be able to better serve the international needs of many of our existing customers as well as providing enhanced cyber services to Orange customers with the UK”.

Check Point partners with Ericom to jointly prevent browser-based attacks

Acquisition

Cybersecurity solutions provider Check Point Software Technologies recently announced the integration of its software solutions with Ericom Software, a web security solutions provider for digital workspace, to jointly prevent browser-based attacks.

Check Point offers cybersecurity solutions to private and government enterprises globally. The company claims that its multi-level security architecture enables its clients to defend against malware, ransomware, cloud and mobile operations, and other targeted attacks across all networks.

Ericom supports connected workforce and IT organizations by securing desktop, application, and web content delivery to any connected device. Founded in 1993, Ericom claims that it provides enterprise-grade secure remote access and web security solutions to a global customer base with a focus on application delivery, cloud enablement, and secure browsing.

The latest partnership combines Ericom’s Remote Browser Isolation (RBI) technology with Check Point’s threat intelligence security protection to generate a robust defense system that enables organizations to prevent web-borne threats and secure user access to all vital browser-based services and assets.

“Web browsing is an indispensable business practice in virtually all organizations today. Despite great success in identifying and protecting against threats in real-time, malware continues to penetrate organizations via browsers and wreak havoc,” said Snir Hassidim, Business and Corporate Development Manager at Check Point Software Technologies. “By integrating the clientless Ericom Shield solution with Check Point’s product line, we enable customers to block malicious content before it approaches internal networks while preserving a transparent and natural browsing experience. The joint solution can provide effective secure web browsing protection against the advanced 5th generation of cyber-attacks.”

Check Point recently acquired Web Application and API Protection (WAAP) provider ForceNock. It stated the deal will strengthen its machine learning protection capabilities. Based in Tel Aviv, Israel, ForceNock provides enterprises accurate protection by its advanced machine learning and behavioral-based security platform Web Application and API Protection (WAAP). The acquisition allows Check Point to integrate ForceNock’s technology into its security protection architecture.

Mobile security startup Guardsquare raises $29 million investment

Pegasus Spyware, Mobile Security, spyware

Mobile cybersecurity company Guardsquare recently raised $29 million investment in its first round of institutional financing round led by Battery Ventures. The Belgium-based company also added Battery Venture’s General Partner Dharmesh Thakker and Principal Paul Morrissey to its leadership team. Guardsquare stated the new funds will be used to leverage its investment in sales, marketing, R&D, and customer-success efforts.

Guardsquare provides premium security solutions for the protection of mobile applications against reverse engineering and cyber hacks. The company claims that its technology is already embedded in more than quarter of Android apps and its software products are used across various industries, like financial services, e-commerce, public sector enterprises, telecommunication, gaming, and media.

“As companies deploy rich applications quickly—including apps tied to new, Internet-enabled devices—the attack surface for hackers and other bad actors is increasing, making cybersecurity an increasingly complex problem,” said Heidi Rakels, co-founder and president of Guardsquare. “Our products are being used by the world’s biggest banks, IT providers and credit-card companies to protect their brands—and their bottom lines—against such malicious threats.”

Speaking on the investment move, Battery’s Dharmesh Thakker said, “Mobile technology, Internet-enabled sensors and other mega technology trends are transforming the cybersecurity landscape, and there is a growing recognition that endpoint security—securing your actual mobile apps on the devices were people are using them—is increasingly critical for organizations. We were also impressed with how Guardsquare has developed a compelling business model from a viral and successful open-source project, something we are seeing more and more with open-source companies in a variety of sectors. The company’s growth is extremely impressive, and we are honored to partner with Roel, Heidi, and Eric to take Guardsquare’s business to the next level.”

 

 

Thousands of cars in UK vulnerable to security breach: Report

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

Thousands of cars with keyless entry systems are left vulnerable, according to a report from consumer group Which? The report suggests that cars, including the most popular models in the United Kingdom from Ford, Nissan, and Volkswagen, can be easily stolen/hacked by attackers using wireless transmitters.

The report revealed that more than 30 car manufacturers, including Audi, BMW, Honda, Hyundai, Kia, Peugeot, Renault, Skoda, and Volvo, made cars that are not secured. The German General Automobile Club (ADAC) stated that it tested 237 keyless model cars and found that 230 of them can be unlocked and started in just 18 seconds using a Relay Attack.

“Carmakers have sacrificed the security of scores of modern cars for the sake of convenience. And, with other methods of car theft also rife and the number of cars being stolen on the rise, manufacturers must do more to make their cars more secure,” Which? reported.

Explaining how a Relay Attack performed, Which? stated, “Using relay boxes – one near your car and the other near where you keep your key – thieves can lengthen the signal produced by your key, fooling the car into thinking the key is close by. The thieves can then open and start your car and drive it away.”

In related news, a study released by Upstream Security, the first and only cloud-based Smart Mobility Cybersecurity provider, cyber hacks might cost the auto industry $24 billion within five years. Upstream issued its first comprehensive report studying the impact of more than 170 documented, Smart Mobility, cyber incidents reported between 2010-2018 and projects future trends based on that eight-year history.

The Upstream Security Global Automotive Cybersecurity Report 2019 outlines how hackers attacked—from physical to long-range to wireless and more — and who they targeted in the Smart Mobility space.