Home Blog Page 334

Over 9,000 Cisco routers are vulnerable to cyber-attack: Researchers

CISCO

Potential vulnerabilities in Cisco’s small business routers could allow a remote attacker to exploit the devices to get sensitive diagnostic data. Cisco, the networking hardware company, stated that the issue existed in its RV320 and RV325 Dual Gigabit WAN VPN business routers.

According to RedTeam Pentesting, a German-based security firm, the discovered vulnerabilities are located in the web-based management interface used for the routers and can be remotely exploitable.

The researchers at RedTeam stated the flaw CVE-2019-1652 allows attackers with administrative privileges on an affected device to execute arbitrary commands on the system and another flaw CVE-2019-1653 allows intruders to retrieve sensitive information including the router’s configuration file containing MD5 hashed credentials and diagnostic information. It’s found that approximately 9,657 Cisco routers (6,247 RV320 and 3,410 RV325) worldwide are vulnerable to the information disclosure, according to the researchers.

Cisco stated that it released firmware updates to patch up the vulnerabilities and suggested the users install the updates to prevent the risks.

“A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands,” Cisco stated in a post. “The vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malicious HTTP POST requests to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux shell as root.”

Cisco faced similar issue last year when a flaw in its Smart Install Client routers was misused by a group of cyber miscreants to bring down internet services on a global scale. Over 200,000 router switches across the world were affected by this attack, of which 3500 were from Iran. According to Iran’s IT Minister Mohammad Javad Azari-Jahromi, Europe, India, and the U.S. were among those countries affected by the attack. The screens of the hacked machines had an image of the U.S. flag with the message “Don’t mess with our elections.”

In Case You Missed It: 6 Top Stories of Last Week

Due to ongoing high-profile data breaches, cybersecurity is a trending topic in all
kinds of media. It is imperative that information security executives are updated
about the incidents around them. Read on for the most important cybersecurity
stories of the last week.

6. Unprotected servers expose 24 million documents

Data Leak

An unprotected Elasticsearch server exposed more than 24 million financial and banking documents online. According to the security researcher Bob Diachenko and online publisher TechCrunch, the exposed server contained highly sensitive data of thousands of individuals who took mortgages over the past decade with the U.S. banks and other financial institutions.

Bob Diachenko stated that he identified the unprotected server on January 10, 2019, which contained 24,349,524 credit and mortgages reports in 51 GB size. The server was taken offline and the data was secured on January 15, 2019, after Diachenko reported the incident to the server’s vendor.

Read More

5. Technical glitch leaks data of 141 international airlines’ fliers

Airlines

A bug in the Amadeus online ticket booking system exposed passengers’ private data, allowing potential attackers to view and change information. According to the security researcher Noam Rotem at Safety Detective research labs, the security flaw could let anyone manipulate someone’s ticket reservation for any airline which has used the Amadeus reservation system.

Amadeus is one of the largest reservation systems that serves around 141 airlines including customers of British Airways, Air France, Icelandair, United Airlines, Lufthansa, Air Canada, and Qantas. The company provides searching, pricing, booking, ticketing, and other processing services to international travelers and travel agencies.

Read more

4. Plexal announces two global partnerships

NCSC and Microsoft Cyber Accelerator program

Global cybersecurity hub Plexal recently announced partnerships with the Global Cyber Alliance (GCA), City of New York, and the New York Economic Development Corporation. The East London-based co-working space and innovation center stated the new partnerships will help the cybersecurity companies under its umbrella to scale globally.

Plexal claims that it provides consultation and demo opportunities for cybersecurity startups through its hub in East London. Plexal also delivers LORCA, a cybersecurity program backed by United Kingdom government, through its cybersecurity innovation hub.

Read more

3. Human error exposes 20,000 BlackRock’s financial advisers’ information

BlackRock, an investment management company, recently revealed that it suffered a data breach that exposed personal information of around 20,000 of its financial advisers, including 12,000 members in the U.S. independent broker-dealer LPL Financial. The American based corporation stated that the exposed information included names, email addresses, and other sensitive information. BlackRock is a global investment management corporation based in New York City. The company provides various asset, financial and risk management services to customers.

LPL Financial stated it informed its advisers that BlackRock posted details about some of them on its website. It said that data leak affected the advisers who do business with BlackRock’s iShares exchange-traded funds unit.

Read more

2. Survey finds most Americans are wary of cybercrime

Cybercrime

PRNewswire: ERP Maestro, provider of automated and cloud-based controls for access, security and GRC, recently released The Inevitability of Cybercrime, results from a December 2018 survey examining the relationship Americans have with cybercrime and identity theft. The responses revealed that 76 percent of Americans believe they will inevitably become a victim of cybercrime, while 68 percent of cybercrime victims don’t believe they could have prevented the crime from happening.

1. Name and shame companies with poor cybersecurity practices: Researchers

A cybersecurity research group from the King’s College London notified the UK government to name and shame the companies that fail to protect consumers’ valuable data.

In its latest report dubbed UK Active Cyber Defence: A public good for the private sector, the research team urged the government to publish the details of companies that are not taking necessary steps to keep users’ data safe online. It opined that this would encourage companies to improve their cybersecurity posture and help prevent cybercrimes. The cybersecurity research group of the King’s College promotes research into cybersecurity and works to solve societal challenges.

Read more

Received more than 95,000 data breach complaints since GDPR: EC

European Commission

The European Commission (EC) stated that data protection regulators in Europe have received more than 95,000 complaints about potential data breaches, after the implementation of the General Data Protection Regulation (GDPR). The commission also said that most of the complaints are focused on telemarketing, promotional emails, and video surveillance.

The GDPR, which became enforceable on May 25, 2018, and privacy laws and regulations around the globe give new powers to privacy regulators. Designed to harmonize the fragmented data privacy framework across the European Economic Area (EEA), the GDPR allows controllers to charge fines of up to 4 percent of global revenue or 20 million euros ($23 million), whichever is higher.

“What is at stake is not only the protection of our privacy but also the protection of our democracies and ensuring the sustainability of our data-driven economies,” the commission said in a statement. It’s believed that more penalties could come as Europeans become aware of their data privacy rights, the commission added.

Recently, search engine giant Google was fined for 50 million euros (around $57 million) by the French data regulator CNIL (National Data Protection Commission) for violating the General Data Protection Regulation. The data protection watchdog stated it had levied the fine for Google’s lack of transparency and valid agreement regarding ads personalization. The regulator also said that Google didn’t sufficiently inform the people about how it collected the users’ data to personalize ads.

The issue started when CNIL received complaints from the associations, None of Your Business (NOYB) and La Quadrature du Net (LQDN) in May 2018. The associations complained on Google for not having a valid legal basis to process the personal data of the users for ads personalization, as mandated by the GDPR.

The inspections carried out by the CNIL’s restricted committee found that Google has violated two core privacy rules of the GDPR- Transparency, and Consent. The committee notified that the information provided by Google is not easily accessible for users and the structure of the information does not comply with the data regulations. It also declared the users are not able to understand the processing operations carried out by the search engine giant.

Japan set to hack devices of its own citizens

Japanese hacking

In a first, the Japanese government will be now be hacking the IoT devices of the country’s citizens. The new initiative is part of a unique survey the government will be undertaking with an intention of securing IoT devices of its citizens. The survey will be carried by the National Institute of Information and Communications Technology (NICT) with an active involvement of the Ministry of Internal Affairs and Communications.

As part of the survey, employees of NICT will try to hack IoT devices of citizens using default passwords and password dictionaries. After this, they will prepare a list of insecure devices that uses default passwords or easy-to-guess passwords and will submit the list to relevant authorities, as well as internet service providers who will then alert the citizens and ask them to change passwords as well as secure their devices.

The survey which is scheduled to take off in February will test nearly 200 million IoT devices, including web cameras and routers, as well as home devices and devices on enterprise networks.  The survey has been earmarked in tandem with the upcoming 2020 Olympics in Tokyo to ensure hackers will not be able to exploit IoT devices and infiltrate the computer systems of the game.

“This is a very interesting response to the growing IoT cyber security problem, and it is about time a government stepped in with something other than a regulatory approach or voluntary standards scheme, said Ian Thornton-Trump, international head of security at AmTrust to IT Pro. “It is not without a North American precedent. Companies and law enforcement have used the US legal system to take down domains and systems that have been used in cyber-attacks of a criminal nature, including botnets. This is the first instance of applying that same philosophy proactively to IoT infrastructure.

“I can see how privacy advocates would see this as very intrusive; on the other hand, if your device is vulnerable or acting as part of a botnet and you don’t have the resources to detect the activity, or even fix it — who else is going to? Overall, the Japanese government action on IoT may bring to light just how serious a problem IoT is and I’m sure other countries will be very interested in the results of this program,” he said.

 

IT solutions provider Electric raises $25 million

Startup funding

Electric, a real-time IT support solutions provider, recently raised $25 million in a Series B financing round led by GGV Capital along with the participation from existing investor Bessemer Venture Partners. In addition, the company announced the appointment of Rani Yadav as Chief Operating Officer and David Weiner as Vice President of Sales.

The New York-based startup stated that the investment will help in developing its software platforms, including automated IT troubleshooting, systems administration, data-driven recommendations, and SaaS applications. Electric also stated that it will invest across sales and marketing, operations, and executive teams.

Emerged from stealth mode in December 2016, Electric offers a chatbot-based interface that integrates with simple solutions that helps its users in day-to-day security, systems administration, network management, and troubleshooting remotely. The company claims that its network-to-device level IT support platform also provides system administration, employee onboarding and offboarding, onsite emergency assistance, and real-time IT support solutions for small and mid-size companies.

Speaking on the new investment, Ryan Denehy, founder and CEO of Electric, said, “This past year has brought exponential growth for Electric and I’m proud to call us the fastest-growing company in our competitive set. Our sales, product and engineering and account management teams have scaled up to support a wide range of customers and, most importantly, make those customers happy. With the new funding, we’re excited to continue on this rapid growth trajectory and become the de-facto IT solution for small and midsize offices all over the country.”

“Small and mid-sized businesses will spend over $600 billion on technology in 2019—more than $180 billion in the US alone. Now more than ever, those companies are struggling to deploy and manage their IT infrastructure. Ryan and the Electric team have built an incredible platform that leverages modern cloud technologies like AI and chat to support customers in a scalable way we haven’t seen before,” said Jeff Richards, Managing Partner at GGV Capital.

Unprotected servers expose 24 million documents

Data Leak

An unprotected Elasticsearch server exposed more than 24 million financial and banking documents online. According to the security researcher Bob Diachenko and online publisher TechCrunch, the exposed server contained highly sensitive data of thousands of individuals who took mortgages over the past decade with the U.S. banks and other financial institutions.

Bob Diachenko stated that he identified the unprotected server on January 10, 2019, which contained 24,349,524 credit and mortgages reports in 51 GB size. The server was taken offline and the data was secured on January 15, 2019, after Diachenko reported the incident to the server’s vendor.

The insecure server allowed open access to the documents that contained loan and mortgage agreements, repayment schedules, financial and tax documents, names, addresses, birth dates, social security numbers, and other sensitive information.

“These documents contained highly sensitive data, such as social security numbers, names, phones, addresses, credit history, and other details which are usually part of a mortgage or credit report. This information would be a gold mine for cyber criminals who would have everything they need to steal identities, file false tax returns, get loans or credit cards,” Bob Diachenko said in a statement.

“It is hard to tell how many people were actually affected in the breach. Given the sensitivity of data, I have immediately initiated a responsible disclosure protocol to privately alert the alleged owner of the Elasticsearch cluster,” Diachenko added.

Also, Diachenko found another data leak from a second storage server Amazon S3, which contains the original documents around 23,000 pages in PDF format in 1.3 GB size from the first exposed Elasticsearch server. The exposed documents are from banks and financial institutions across the U.S., including loans and mortgage agreements, W-2 tax forms, loan repayment schedules from the U.S. Department of Housing and Urban Development. The Amazon server was taken down in an hour after reported the issue, Diachenko stated.

A couple of data leaks occurred due to ElasticSearch servers in recent times. In November 2018, the Elasticsearch database exposed personal details of 57 million U.S. citizens for almost two weeks. Bob Diachenko discovered that the server was left visible online without a password exposing customers’ personal data. In a similar incident, a database from the same vendor exposed the real-time location data for over 11,000 Indian buses online over three weeks.

Plexal announces two global partnerships

NCSC and Microsoft Cyber Accelerator program

Global cybersecurity hub Plexal recently announced partnerships with the Global Cyber Alliance (GCA), City of New York, and the New York Economic Development Corporation. The East London-based co-working space and innovation center stated the new partnerships will help the cybersecurity companies under its umbrella to scale globally.

Plexal claims that it provides consultation and demo opportunities for cybersecurity startups through its hub in East London. Plexal also delivers LORCA, a cybersecurity program backed by United Kingdom government, through its cybersecurity innovation hub.

GCA, a collaborative non-profit entity, works with global networks and partners to mitigate cyber risk. It provides cybersecurity solutions and expertise from government and the private sector to Plexal’s members to help them create their cybersecurity products/services. The latest partnership enables sharing of knowledge, resources, and creates a strong connection between cyber innovators based in NYC and the UK to solve cybersecurity challenges globally.

“Our partnership with the City of New York Mayor’s Office of the Chief Technology Officer and the New York Economic Development Corporation will see Plexal be the UK lead for the NYC Cybersecurity Moonshot Challenge, with a focus on creating better cybersecurity solutions for SMEs. Plexal will both ensure UK innovators are well represented as challenge participants and also act as the primary UK landing pad for challenge winners. Plexal will provide consultation, demo opportunities and a base for winners to develop in the UK through free coworking space and support at Plexal’s hub at Here East, London. The partnership will establish strong connections between cyber innovators based in NYC and the UK, enabling sharing of knowledge and resources that are vital to solving cybersecurity challenges on a global scale,” Plexal said in a statement.

Speaking about the partnerships, Andrew Roughan, Managing Director of Plexal, said, “Sharing knowledge and being open to cooperation between global cyber innovators and industry is more important than ever. We’re looking forward to deepening our links with new global partners and acting as the UK landing pad and connector. These important partnerships with the New York Development Corporation and the Global Cyber Alliance will mean the emerging cyber stars we support can have even greater direct access to new markets and the networks they need to succeed.”

 

Human error exposes 20,000 BlackRock’s financial advisers’ information

BlackRock, an investment management company, recently revealed that it suffered a data breach that exposed personal information of around 20,000 of its financial advisers, including 12,000 members in the U.S. independent broker-dealer LPL Financial. The American based corporation stated that the exposed information included names, email addresses, and other sensitive information. BlackRock is a global investment management corporation based in New York City. The company provides various asset, financial and risk management services to customers.

LPL Financial stated it informed its advisers that BlackRock posted details about some of them on its website. It said that data leak affected the advisers who do business with BlackRock’s iShares exchange-traded funds unit.

“BlackRock inadvertently posted a small number of sales-related documents, which were up for a short period of time, and promptly removed. The information related to a very limited number of wealth management platforms impacting approximately 20,000 independent advisers in the U.S,” LPL Financial said in a statement.

“After being informed by BlackRock of this issue, our first priority was to reach out to our advisers to make them aware of the situation and share the details we had learned. We will continue to stay in close communication with BlackRock as they research the incident and will share information with our advisers as it becomes available,” the statement added.

The data breach came into light after Bloomberg reported that BlackRock had mistakenly published the data of its financial advisers on its website. However, BlackRock stated that the incident occurred due to human error, after inadvertently posting sales-related data on its website iShares.com. “There was no security breach and no compromise of BlackRock systems,” BlackRock clarified in a statement.

Name and shame companies with poor cybersecurity practices: Researchers

A cybersecurity research group from the King’s College London notified the UK government to name and shame the companies that fail to protect consumers’ valuable data.

In its latest report dubbed UK Active Cyber Defence: A public good for the private sector, the research team urged the government to publish the details of companies that are not taking necessary steps to keep users’ data safe online. It opined that this would encourage companies to improve their cybersecurity posture and help prevent cybercrimes. The cybersecurity research group of the King’s College promotes research into cybersecurity and works to solve societal challenges.

The research revealed that over 4 in 10 companies and one-fifth of charities in the United Kingdom were suffered a cyber breach or attack in 2017-18. It also disclosed that a UK resident is more likely to be a victim of cybercrime, which is estimated the worth of £4.6 billion (around $5.9 billion) damage to 17 million internet users in 2017.

The research team recommended companies, charities, and other organizations to follow measures included in the government’s Active Cyber Defence (ACD) programme, which is only following presently by public sector companies. The technology used by the ACD programme has resulted in a significant fall in data breaches and phishing attacks from the fake government addresses, according to the report.

“This report suggests that the ACD programme holds great potential to reduce the incidence and impact of cybercrime in the UK and, if adopted in other national contexts, can help counter the global proliferation of cybercrime. While broadly supportive of ACD, this report raises a range of considerations for the programme as it moves ahead. These include how to incentivise the private sector; resisting various forms of function and mission creep; issues around exporting ACD technologies; the possible negative externalities of ACD in adjacent fields of security and policing; and how ACD can deal with rapid technological change. We propose that ACD, if deployed carefully and sensitively, might be understood as an emergent ‘public good’, delivering significant socioeconomic benefits,” the report added.

Data discovery company Exonar raises $8.5 million

Exonar, a data discovery software company, recently raised £6.5m (around $8.5 million) investment in a funding round led by London-based venture capital firm Beringea along with the existing investors Downing Ventures, Amadeus Capital Partners, and Winton Ventures.

The Berkshire-based company stated that it helps organizations discover and manage their sensitive data. Exonar also aid companies comply with the EU’s General Data Protection Regulation by creating a framework of their valuable data. Founded in 2013 by Adrian Barrett, Exonar claims that its data discovery software platform enables businesses to create data inventories and prevent compliance issues in a secure manner. The company holds experienced security leaders from global cybersecurity companies like BT, Fujitsu, Veritas, Symantec, and EMC.

Speaking on the new investment, Adrian Barrett, CEO and Founder of Exonar, said, “These are exciting times for Exonar. To receive significant backing from Beringea and Downing Ventures reinforces our belief that the Exonar platform has a significant role to play in enterprise-level data discovery and management. We have a clear vision for future development and the investment will enable us to further enhance our product, enabling our customers to meet current and future data demands such as GDPR and CCPA swiftly, simply and at scale.”

“Data is the backbone of modern business. And yet, it also poses an existential risk, which has traditionally required substantial resources and investment to manage. Exonar transforms this dynamic with a platform that maps and understands petabytes of information in seconds. Beringea has backed Exonar’s leadership and pioneering technology to create a cornerstone of data governance,” said Stuart Veale, Managing Partner of Beringea.