Home Blog Page 336

15 Top Cybersecurity Searches on Google Last Year

malicious PDFs

By SecureWorld

When Google revealed its top searches of 2018 list, it was mainly focused on pop culture.

And while that’s cool, the team really wanted to know about the hottest cybersecurity search topics of the year, so we went digging into what people in the U.S. were searching for regarding InfoSec.

Here are the rising cybersecurity superstars, in Google search, for the year:

  1. DHS cybersecurity strategy (off the charts increase, called a “breakout”)
  2. Certified Ethical Hacker, +250%
  3. cybersecurity conferences 2018, +250%
  4. cybersecurity risk assessment, +190%
  5. cyberinsurance, +180%
  6. computer security incident management, +150%
  7. cybersecurity infrastructure security agency, +150%
  8. SEC guidance on cybersecurity, +150%
  9. cybersecurity certificate programs, +130%
  10. blockchain cybersecurity, +120%
  11. NYDFS cybersecurity, +90%
  12. cybersecurity major, +80%
  13. women in cybersecurity, +80%
  14. cybersecurity threats, +60%
  15. cybersecurity certification, +50%

It’s particularly good to see an uptick in searches around cybersecurity majors and certification programs, given the talent shortage in the industry.

And it is also great to see the searches on women in cybersecurity rising, as well. It is evidence that the lack of women in information security is getting more attention than ever before.

This article was originally posted here and is published here with permission

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Check Point acquires security startup ForceNock

Acquisition

Cybersecurity solutions provider Check Point Software Technologies recently acquired Web Application and API Protection (WAAP) provider ForceNock. Check Point offers cybersecurity solutions to private and government enterprises globally. The company claims that its multi-level security architecture enables its clients to defend against malware, ransomware and other targeted attacks across all networks, cloud and mobile operations. Check Point stated the latest deal will strengthen its machine learning protection capabilities.

Based in Tel Aviv, Israel, ForceNock provides enterprises accurate protection by its advanced machine learning and behavioral-based security platform Web Application and API Protection (WAAP). The acquisition allows Check Point to integrate ForceNock’s technology into its security protection architecture.

“Check Point is committed to providing the most comprehensive security architecture to prevent current and future generations of cyber-attacks. The growing usage of platforms – Cloud, Network, Mobile, Endpoint and, IoT – requires complete, simple to deploy and easy to use security technologies”, said Dr. Dorit Dor, Check Point’s VP Products. “Incorporating ForceNock’s technology into our Infinity Architecture will enable us to continue to provide the highest level of security for our customers worldwide and strengthens our machine learning protection capabilities.”

A couple of months ago, Check Point partnered with Silverfort, a multi-factor authentication solutions provider. Silverfort stated that the alliance enables customers to use Silverfort’s adaptive authentication platform to activate immediate step-up authentication against cyber threats detected by Check Point. Headquartered in Israel, Silverfort offers multi-factor authentication process across corporate networks and cloud environments. Silverfort claims its next-generation technology helps enterprises prevent data breaches, identity-based attacks, and insider threats.

Also, in its latest research findings, Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines. The researchers from Check Point, Yaniv Balmas and Eyal Itkin, stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number.

Cybersecurity startup Syncurity raises $2 million

Automation and Orchestration

Syncurity, a provider of Security Orchestration, Automation and Response (SOAR), recently announced that it has raised $2 million in a seed funding round led by the Maryland Technology Development Corporation (TEDCO) along with other investors Kluz Ventures and SixThirty CYBER.

The US-based company stated that the new investment will be used to expand its technical and channel partnerships and accelerate the company’s growth globally. In addition, Syncurity also announced that it has added Michael Sutton, a former CISO of security firm Zscaler, to its Board of Advisors.

Founded in 2014 by a security analyst JP Bourget, Syncurity claims that it helps enterprises by making their security operations center (SOC) more powerful by its security automation & orchestration platform. The company’s IR-Flow platform strengthens security operations by delivering an analyst-centric incident response platform, that integrates people, process, and technology for better cybersecurity.

“These additional funds — along with the institutional firms behind them — as well as our strong Board of Advisors will enable Syncurity to extend the lead of our IR-Flow platform to new customers and partners around the world,” said Syncurity CEO, John Jolly. “Our unique, visual, “process-first” approach and extensible case management capabilities are increasingly recognized as superior alternatives to first-generation, DIY automation tools that lack strong case management and auditing functionality.”

Speaking on the new investment move, the managing partner of Kluz Ventures, Artur Kluz, said, “Syncurity’s patent-pending product architecture, analyst-driven interface and extensible system integrations were a natural choice for us to extend our cybersecurity portfolio into the fast-growing SOAR market. Syncurity’s ability to automate and orchestrate real-world incident response processes is quickly gaining traction with global enterprises and MSSPs/MDRs.”

Unprotected server exposes personal info of millions of job seekers in China

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

An unprotected MongoDB server exposed a database that contains resumes of 202 million Chinese people online, according to a researcher.

Bob Diachenko, Director of Cyber Risk Research at HackenProof, discovered that the unsecured server was left visible online without a password, thus exposing the resumes that contained personal details such as mobile phone number, email, marital status, driver license, literacy level, salary expectations, skills, and work experience. The leaky server was secured soon after Diachenko publicized the issue via a Twitter post.

“An 854 GB sized MongoDB database was left unattended, with no password/login authentication needed to view and access the details of what appeared to be more than 200 million very detailed resumes of Chinese job seekers,” Bob Diachenko said in a post.

It’s believed that the data had been taken from different Chinese classifieds like bj.58.com, according to Diachenko. However, the security officials at bj.58.com didn’t confirm that the data leaked from their source.

“We have searched all over the database of us and investigated all the other storage, turned out that the sample data is not leaked from us. It seems that the data is leaked from a third party who scrape data from many CV websites,” bj.58.com clarified.

In his similar findings, Bob Diachenko discovered that an unprotected Elasticsearch database exposed personal details of 57 million U.S. citizens for almost two weeks. Diachenko stated that the unsecured server was left visible online without a password exposing customers’ personal data. ElasticSearch, an enterprise search engine, provides technology solutions for powering search functions.

The researcher also stated he found another index of the same database that contained 25 million additional data records holding sensitive information, including names, company details, zip address, carrier route, latitude/longitude, census tract, phone number, web address, email, employees count, revenue numbers, NAICS codes, and SIC codes.

Unprotected ElasticSearch server exposes location data of 11,000 Indian buses

Indian bus

An unsecured Elasticsearch database exposed the real-time location data for over 11,000 Indian buses online over three weeks. ElasticSearch, an enterprise search engine, provides technology solutions for powering search functions.

According to Justin Paine, the security researcher who discovered the breach, the unprotected server was left visible online without a password exposing real-time GPS and bus route information from 27 Indian transportation agencies via an ElasticSearch server, ZDNet reported.

The server exposed the data of 26 road transport agencies including Kochi Metro Rail Limited. The exposed information included the details like bus license plates, start-stop stations, route names, GPS coordinates, and details of commuters like usernames and emails.

Paine said he discovered the server using search engines for connected devices on December 5, 2018, and after reaching the Indian Computer Emergency Response (ICERT) team the server was secured on December 22, 2018.

“In some cases, the username field appeared to be populated with a user-supplied username, but in other cases, it did appear to be the user’s full name. Some agencies also appeared to log the user’s email address,” Justin Paine said in a media statement.

“I was not able to determine how many unique users had their information exposed as I did not want to run such a resource-intense query on someone else’s server. I can confirm the server was accessible as far back as at least November 30, 2018. It is unclear how long the server had been exposed [before that date] though,” Paine added.

This is the latest data leak caused by the unprotected ElasticSearch servers. In November 2018, the vulnerable Elasticsearch database exposed personal details of 57 million U.S. citizens for almost two weeks. Bob Diachenko, Director of Cyber Risk Research at Hacken, discovered that the unsecured server was left visible online without a password exposing customers’ personal data.

The researcher also stated he found another index of the same database that contained 25 million additional data records holding sensitive information, including names, company details, zip address, carrier route, latitude/longitude, census tract, phone number, web address, email, employees count, revenue numbers, NAICS codes, and SIC codes.

Cybersecurity skills startup Immersive Labs raises $8 million

Startup funding

Cybersecurity training platform Immersive Labs recently raised £6.2 million ($8 million) in a funding round led by Goldman Sachs along with other investors. The Bristol-based startup stated the new funds will be used to grow its services for enterprise IT and cybersecurity teams. Immersive Labs also said that it’s going to increase the workforce and infrastructure to develop the reach of its training platform.

Founded by a former security researcher at GCHQ (the Government Communications Headquarters) James Hadley, Immersive Labs offers online training sessions for people to learn about cybersecurity skills in order to help enterprises defend against cyber-attacks. The company claims that its cybersecurity skills platform uses real-time feeds of the latest attack techniques and security vulnerabilities to build cyber war games for IT and security teams for training purpose.

“Having rolled out the Immersive Lab platform globally ourselves, we are aware of the benefits it brings to large organizations. Continuous training programmes are critical to meeting evolving cybersecurity threats. The Immersive platform has helped us hone the skills of the people at the front line of our cyber defenses and identify new talent throughout the organization,” Andy Ozment, Chief Information Security Officer of Investment banking company Goldman Sachs.

Speaking on the new investment, James Hadley, the CEO of Immersive Labs said, “Large organizations are facing a dual cybersecurity talent problem; not only is the number of professionals seriously lagging but so is the pace at which their skills are developed.  If you are able to recruit the right people in the first place, today’s attackers move so fast your team may quickly fall behind.”

“Our goal is to reduce this gap. With increased capital, we can help more companies continue to upskill their cyber talent in a way which keeps pace with the threat landscape,” Hadley added.

Amazon India suffers data breach; sellers’ financial information exposed

Amazon

E-commerce giant Amazon has again suffered another technical glitch on its India portal that affected its sellers and vendors. The Seattle-based e-tailer stated that a bug in its website caused a data breach on January 08, 2019, that exposed sensitive financial information, including sales, category-wise split and inventory data of its sellers and vendors. Having around 400,000 online vendors and sellers across the country, Amazon said the issue was resolved within a few hours, but, the exact figure of affected members is not yet discovered.

The issue came to light after some Amazon vendors reported that they received incorrect data while downloading their Merchant Tax Reports (MTR) from the portal. It has been said that data of some sellers were visible to other competing sellers. An MTR statement holds information of all the order transactions processed by a seller on the e-commerce platform, which is usually downloaded from the portal between 8th-10th of every month.

Amazon faced a similar issue in November 2018. The company reported a technical error that exposed users’ personal information like names and email addresses. In an email sent to its customers, Amazon Customer Service cautioned that the company unintentionally exposed the users’ data due to a technical error. However, the Seattle-based e-tailer has not yet disclosed any details about the error.

Most of the customers who received the email speculated it was a scam or some kind of a phishing attack until Amazon’s UK press office confirmed the incident. “We have fixed the issue and informed customers who may have been impacted,” Amazon stated in a press note.

Also, in August 2018, a security team from Tencent Blade exposed new security vulnerabilities around Amazon Echo smart speakers. Researchers Wu HuiYu and Qian Wenxiang gave a live demonstration at the DEFCON security conference on how to hack a smart speaker. The researchers hacked the speaker by adding a malicious device embedded with an attack program. They notified Amazon of their findings before the presentation, and Amazon has already pushed a security patch to fix the issues.

OneLogin raises $100 million to expand its Unified Access Management services

H20.ai raises $72.5 million

OneLogin, an access and identity management startup, recently raised $100 million investment in a financing round led by Greenspring Associates and Silver Lake Waterman along with the existing investors CRV and Scale Venture Partners. The California-based startup stated the new funds will be used to accelerate the adoption of its new products like Multi-Factor Authentication (MFA) to serve enterprises in the new Unified Access Management (UAM) sector. OneLogin also said the funds will be used to extend its footprints in North America and Europe regions.

Founded in 2009, OneLogin provides simple and secure application access and identity management services to enterprises. The company claims that it’s a pioneer in Unified Access Management that connects users and enterprises with technology through a secure login.

OneLogin claims that its UAM platform unlocks the apps, devices, and data that drive productivity and enable a unified approach to manage access for both SaaS and on-premise application environments collaboration.

“Every business needs Unified Access Management, and our solution is mission critical for all of our customers across both cloud and hybrid cloud environments. Our relentless focus on customer service coupled with this significant capital infusion supports OneLogin’s ongoing growth and investment,” said Brad Brooks, CEO of OneLogin.

“We believe in OneLogin’s vision for Unified Access Management and are excited to support the company as it accelerates its leadership position throughout North America and Europe,” said John Avirett, General Partner at Greenspring. “We’re at an inflection point for growth as all enterprises are faced with the challenge of managing access across SaaS and on-premise environments, as well as various devices and networks on the cloud infrastructure. OneLogin’s solution is something that every enterprise needs in its digital transformation journey.”

“The OneLogin team has built a strong platform to secure and manage access to applications. Their performance has accelerated since Brad joined as CEO, with a clear focus on culture and customers. We look forward to partnering with Brad and the rest of the leadership team in continuing this success and growth,” said Shawn O’Neill of Silver Lake Waterman.

Reddit notifies users about potential data breach

Reddit

Social media platform Reddit has alerted its users that some of their accounts have been locked out because of suspicious activity. The US-based news aggregator stated that it received many requests for new passwords that may indicate unauthorized access.

Reddit said that its security officials are working on to fix the issue. It suggested the users update their passwords and also advised to use the latest email address for Reddit accounts, enabling automated password resets and two-factor authentication for additional protection. The company notified the affected users and allowed them to reset the passwords to restore the accounts.

“A large group of accounts were locked down due to a security concern. By “security concern,” we mean unusual activity that did not correspond to the account’s normal behavior that may indicate unauthorized access,” Reddit stated in an official post. “The most common explanation for this is the use of very simple passwords or the reuse of credentials across multiple websites or services. If another site is compromised and those lists of usernames and passwords become available, it’s very likely that they will be tried against other popular sites to see if they work and this means that any account where you use the same credential combination is then at risk.”

“We’re sorry for the unpleasant surprise and are working to get you all back to redditing as usual. I’ll be monitoring this thread for a while to answer questions where I can, but please keep in mind we can’t answer most account-specific inquiries in public,” Reddit added.

Data hacks on social media handles become common. Recently, the social networking site Twitter revealed that it has discovered and fixed a security bug that could have exposed users’ phone country codes and locked accounts details. The micro-blogging giant stated they noticed unusual activity in its Application Programming Interface (API) and observed a large amount of traffic coming from IP addresses located in China and Saudi Arabia.

Also, the social media giant Facebook suffered from multiple data breaches in 2018. In December 2018, Facebook reported a data breach that exposed 6.8 million users’ private photos to third-party application developers. The company announced that its internal team discovered a photo API bug that allowed third-party apps to access users’ photos for 12 days between September 13, 2018, to September 25, 2018. Earlier, Facebook discovered a security breach that has affected nearly 50 million users globally. The vulnerability existed in the basic ‘View As’ feature which was often used to show how the account looks like to the public.

SingHealth data breach caused by lack of basic security measures: Report

The investigation into cyber-attack on SingHealth database which affected around 1.5 million people, including Singapore’s Prime Minister Lee Hsien Loong, revealed that the incident occurred due to lack of basic security, employee training, and other flaws. The investigation committee which was formed shortly after the breach stated the breach went on about for a year between August 2017 and July 2018.

The report also highlighted the failures of the Integrated Health Information System (IHIS) and the IT agency responsible for the public health system’s security for not having adequate cybersecurity awareness, resources, and training to respond to cyber-attacks. The committee also stated that most of the United States health organizations still fail to educate their employees, apply patches, and follow basic security methods.

“There were a number of vulnerabilities, weaknesses, and misconfigurations in the SingHealth network and SCM system that contributed to the attacker’s success in obtaining and exfiltrating the data, many of which could have been remedied before the attack,” the report stated.

“The attacker had a clear goal in mind, namely the personal and outpatient medication data of the Prime Minister in the main, and also that of other patients. The attacker employed advanced TTPs, as seen from the suite of advanced, customized, and stealthy malware used, generally stealthy movements, and its ability to find and exploit various vulnerabilities in SingHealth’s IT network and the SCM application,” the report added.

On July 4, 2018, the security officials at SingHealth detected and stopped an unusual activity that occurred between June 27, 2018 and July 04, 2018. The hackers allegedly compromised more than 1.5 million patients’ personal information. Singapore’s Prime Minister Lee Hsien Loong’s personal particulars and outpatient medication data were also exposed in the breach. The Singapore government disconnected computers from the internet at public healthcare centers and set up a four-member Committee of Inquiry (COI) to investigate the incident.