Home Blog Page 340

Date of Death for Google+ is March 07, 2019

After the disclosure of a second vulnerability that had exposed around 52.5 million users’ personal information to third-party developers, Google had announced that it will be shutting down its social media platform Google+ for consumers by April 2019.

In a recent media statement, the California-based firm stated that all Google+ APIs and integrations will be closed permanently on March 7, 2019. Google stated that the process of sunsetting Google+ will initiate on January 28, 2019.

The shutdown includes Google+ Sign-in system as well as all web and mobile app integrations, plugins, +1 buttons, and share buttons which will cease working on March 07, 2019. Google has recommended developers to migrate their in-app authentication to the main Google Sign-in by the end of January.

“As part of the sunset of Google+ for consumers, we will be shutting down all Google+ APIs on March 7, 2019. This will be a progressive shutdown beginning in late January, so we are advising all developers reliant on the Google+ APIs that calls to those APIs may start to intermittently fail as early as January 28, 2019,” Google said in a statement.

“On or around December 20, 2018, affected developers should also receive an email listing recently used Google+ API methods in their projects. Whether or not an email is received, we strongly encourage developers to search for and remove any dependencies on Google+ APIs from their applications,” the statement added.

In October 2018, Google announced that it was going to shut down its social media network Google+ for consumers in the next 10 months. The declaration had come after a vulnerability was disclosed which exposed data of around 500,000 users’ including their personal information to third-party developers.  The original intention was to close Google+ in August 2019, however, earlier this month the company stated that it is moving the date to April 2019. It was after Google+ encountered second data breach that exposed personal information of 52.5 million users.

The tech giant admitted that the incident occurred due to an existing bug in its software update that was introduced in November 2018, before the company fixed it.

 

Forcepoint partners with ITQAN to boost cybersecurity in UAE

partnership

The cybersecurity firm Forcepoint recently signed a partnership agreement with the systems integrator and solutions provider ITQAN Al Khaleej Computers. The partnership enables Forcepoint to extend its product range, including Data Loss Prevention (DLP), the User and Entity Behavior Analytics (UEBA), Cloud Access Security Broker (CASB), Next Generation Firewall (NGFW), and web/email security.

ITQAN is a Systems Integrator in the UAE region. Established in 1984, the company claims that it’s best known for providing enterprise clients with advanced technology solutions, including ICT infrastructure, cybersecurity, optical network solutions, workflow automation, healthcare information systems, enterprise resource planning, and security system management solutions.  ITQAN stated the new alliance with Forcepoint will increase the adoption of advanced cybersecurity solutions in the UAE region.

“We have had a very positive partnership to date with ITQAN in the UAE, and their shift to Platinum partner status will further increase dividends from our joint work. We believe now is the time to invest in the kind of valuable services that will help channel partners and business customers to implement efficient technology solutions,” said Neal Lillywhite, Vice President of EMEA Channel at Forcepoint.

Speaking on the new partnership deal, Walid El Saikali, VP & General Manager of ITQAN stated, “ITQAN is delighted to become a Forcepoint Platinum Partner as this is strategic to our company’s roadmap. Together, ITQAN and Forcepoint will deliver next-generation security solutions which are increasingly in demand in the UAE. The upcoming regional digital transformation must be managed with risk-adaptive, data protection, and leading end-to-end threat and security solutions. With our team’s capabilities, we will strive to deliver our solutions to continually meet our customer’s needs and requirements in an ever-evolving threat landscape.”

Democrats urge US government to boost pipeline cybersecurity

Pipeline Cybersecurity

Two Democratic lawmakers urged the Department of Homeland Security (DHS) recently to strengthen the protection of oil and gas conduits in the United States from potential cyber-attacks.

According to the official statement, the ranking member of the Senate Energy and Natural Resources Committee Maria Cantwell and House Energy & Commerce ranking member Frank Pallone released a letter to DHS Secretary Kirstjen Nielsen suggesting to take immediate actions to protect the country’s pipelines from cyber-attacks.

“Our nation’s energy assets are critical to our safety, security and economic well-being. Protecting our pipelines, and the people who live and work near them, must be a top priority for our government and I hope this report will prompt the Trump administration to start treating this challenge with the urgency it deserves,” said Cantwell in the letter.

“It’s clear from GAO’s work that while pipelines are reliable today, the Transportation Security Administration (TSA) is not fully prepared to face the challenges of tomorrow. I’m concerned that TSA lacks both the resources and expertise in energy delivery systems to keep up with its obligations under the law.  Secretary Nielsen must address the concerns Senator Cantwell and I raise in our letter to ensure the security of our nation’s pipelines,” said Pallone.

The letter comes on the heels of the Government Accountability Office (GAO) report highlighting the vulnerabilities in the American pipeline systems. In its report, “Actions Needed to Address Significant Weaknesses in TSA’s Pipeline Security”, GAO stated that they found weaknesses in how the Transportation Security Administration (TSA) manages its pipeline security.

“The nation depends on the interstate pipeline system to deliver oil, natural gas, and more. This increasingly computerized system is an attractive target for hackers and terrorists,” the GAO report stated. GAO issued ten recommendations for the TSA, including executing a better process for reviewing, necessary revising, and updating security guidelines at regular intervals.

Malware attack on BJC HealthCare affects 5,850 people

BazaCall BazaLoader

BJC HealthCare, a non-profit healthcare networks in the United States, recently revealed that it has discovered a data breach on November 19, 2018, that affected 5,850 people.

In an official statement, BJC stated that unknown intruders illegally gained access to its patients’ payment portal and uploaded malware that potentially compromised the personal and credit/debit card information. The security professionals at BJC determined that the malicious code exploited the payment portal and exposed the payment information from October 25, 2018, to November 08, 2018, affecting 5,850 of its users.

The Health Center said the information that could have been compromised included the patients’ names, dates of birth and billing data. The credit card or bank account information for some people also got compromised. However, BJC clarified that no social security numbers and medical information affected due to the incident.

“BJC has no indication to date that any information was actually misused. As a precaution, individuals whose payment information may have been exposed are advised to carefully review credit card and bank statements and immediately contact their credit card holder or banking institution about any inconsistencies or suspicious activity,” BJC statement read. “BJC takes the confidentiality and protection of patient information seriously and regrets any inconvenience or concern this incident caused patients, family members or other individuals making payments through the site. To help prevent a similar incident from occurring in the future, BJC has implemented additional security procedures to enhance protection against malware.”

In related news, the U.S. government’s health insurance system HealthCare.gov suffered a data breach that resulted in the theft of thousands of patients’ records. According to the official statement, unknown attackers breached the government portal’s sign-up system named Federally Facilitated Exchanges (FFE) and compromised around 75,000 patients’ personal data. Managed by the Centers for Medicare & Medicaid Services (CMS), the HealthCare.gov is a platform for insurance agents and brokers to enroll users in Obamacare insurance plans.

The CMS stated they discovered the suspicious activity on October 13, 2018, and notified the Federal law enforcement for an immediate investigation. On October 19, the CMS officials declared that the portal was compromised between October 13 and 16, and it is unclear what information was exposed in the unauthorized activity.

4 Sources of Income: Who Pays to Keep the Tor Browser Going?

Cybersecurity

Contributed by SecureWorld

If you pay taxes in the United States, you are supporting the Tor browser.

The Tor Project, and its web browser which gives users anonymity, is a tool of choice for cybercriminals of all kinds who buy and sell things on the Dark Web like drugs, child pornography, and hacking tools.

Some see it as an enabler of this cyber underworld.

However, if you read the Tor Project’s new 2017 financial transparency report, it is clear the organization views itself as fighting for freedom.

When revealing 2017 revenue of $4.2 million and the organization’s balance sheet, Tor’s new director, Isabela Bagueros, says this about her budget:

“… it is dwarfed by the budgets that our adversaries are spending to make the world a more dangerous and less free place.”

Tor advocates argue this danger comes from oppressive regimes and the growing power of surveillance and data collection by governments, law enforcement, and corporations around the globe.

Yes, Tor sees itself as making the world safer.

United States government pays Tor millions each year

Right now, the United States government is the number one funder of Tor. The organization’s newly-released financial report says that number is dropping, however:

“In terms of percentages, while 2015 saw 85% of our funding coming from US government sources, 2016 saw the fraction drop to 76%, and in 2017 we’re down to 51%.”

What does Tor promise the U.S. government for its millions in funding each year? Tor director Bagueros says that is the wrong question:

“I should take a brief moment to explain how funding proposals work, for those who worry that governments come to us wanting to pay us to do something bad. The way it works is that we try to find groups with funding for the general area that we want to work on, and then we go to them with a specific plan for what we’d like to do and how much it will cost, and if we’re lucky they say ok. There is never any point where somebody comes to us and says ‘I’ll pay you $X to do Y.'”

4 ways Tor gets funded

The report also lists the four main areas of Tor funding.

Here is that particular paragraph of the report, in its entirety. It’s an interesting read because it explains why each source reportedly supports Tor:

(A) Research funding from groups like the National Science Foundation to do fundamental research on privacy and censorship, including studying how to improve Tor’s performance and safety, and inventing new censorship circumvention techniques.

(B) R&D funding from groups like Radio Free Asia and DARPA to actually build safer tools. Different funders might have different audiences in mind when they help us make Tor Browser safer and easier to use, but they want the same things out of Tor Browser: in all cases we make all of our work public, and also remember that anonymity loves company.

(C) Deployment and teaching funding from organizations like the US State Dept and Sweden’s foreign ministry to do in-country security trainings, user-oriented documentation, and otherwise help activists around the world learn how to be safer on the internet.

(D) Core organizational support, primarily from individual donations (that’s you!) and the Mozilla match, to cover the day-to-day operations of the non-profit, and most importantly to let us spend time on critical tasks that we can’t convince a funder to care enough about.

Whether you love Tor or hate Tor because of what it allows users to do, now you know more about who is paying to support the Tor Project and its Tor browser.

(Note: The Tor name is derived from an acronym for the original software project name “The Onion Router.”)

The article was originally posted here first and is published with SecureWorld’s permission.

The opinions expressed within this article are the personal opinions of the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Stockpiling Cryptocurrency May Not Be a Silver Bullet

Cryptocurrency

Payment will be raised on 5/15/2017 21:13:40,” read the screen as Robert Gren looked at the clock on his computer. He had 26 minutes to decide whether to pay the ransom to the hackers to decrypt his files. After the deadline, the ransom was going to double. “I’m still battling my thoughts,” he said over the phone. “I have found some people that claim that their friends or acquaintances have had their files decrypted. But on the other hand, I haven’t been able to verify it in any way or get in touch with anyone directly.” He needed to pay up $300 worth Bitcoins. on giving experts a central point for coordinating responses to network emergencies, thus laying the foundation for information security.

This was three days after WannaCry had wreaked havoc on the entire world—holding the data of millions hostage for billions in Bitcoins. The same year, Bitcoin reached an all-time high of nearly $20,000 per coin. Bitcoin was hacker gold and always had been. In fact, two years after the birth of Bitcoin, people had created a clandestine marketplace on the dark web called Silk Road, where drugs and guns were sold via limited time flash sales. Things changed only after Ross Ulbricht, the founder of the Silk Road, was apprehended by the FBI and his stash of Bitcoins was seized. But Bitcoins continued to carry the dubious distinction of being the currency for everything illegal because of the currency’s anonymity.

WannaCry was no different and continued to make Bitcoins synonymous with hushed illegal activities. In fact, what the cyber- attack set in motion was something alarming. Organizations started stockpiling Bitcoins to pay hackers in case they ever found themselves in the midst of an attack. One study found that 73 percent of CEOs and CISOs were setting aside cryptocurrency to pay up ransomware demands. The study was conducted by a data security firm called Code 42. The results were shocking. The company not only found that nearly three-quarters of CISOs were involved in buying cryptocurrency, but nearly 79 percent said that within the last year, they had paid a ransom to hackers post an attack.

Read More

 

NASA discloses data breach; employees’ personal information at stake

NASA

The National Aeronautics and Space Administration (NASA) recently reported a cyber-attack that took place this year. In a statement sent to its employees, NASA stated that an unknown intruder illegally gained access to one of its servers that stores current and former employees’ Personally Identifiable Information (PII), including the social security numbers.

NASA stated the hack occurred on October 23, 2018, and it didn’t have the information on the exact number of employees who were affected. However, NASA said its Civil Service employees who were on-boarded or transferred to other centers from July 2006, to October 2018, may have been affected.

“NASA cybersecurity personnel began investigating a possible compromise of NASA servers where personally identifiable information (PII) was stored. After initial analysis, NASA determined that information from one of the servers containing Social Security numbers and other PII data of current and former NASA employees may have been compromised,” NASA said in a statement.

NASA confirmed that its cybersecurity officials took immediate actions to secure the data servers and it’s working with federal cybersecurity partners to determine the potential data exfiltration and identify the affected employees. The agency is notifying all the employees and suggesting precautionary measures to counter against the possible fraud.

“This message is being sent to all NASA employees for awareness, regardless of whether or not your information may have been compromised. Those NASA Civil Service employees who were on-boarded, separated from the agency, and/or transferred between Centers, from July 2006 to October 2018, may have been affected. Once identified, NASA will provide specific follow-up information to those employees, past and present, whose PII was affected, to include offering identity protection services and related resources, as appropriate,” the statement further read.

Most agencies not implementing cybersecurity practices: GAO

cybersecurity practices, Automotive Cybersecurity

A new audit report revealed that 17 of 23 Chief Financial Officer Act agencies are failed to implement the core functions of the cybersecurity framework of the National Institute for Standards and Technology. According to a report from the United States Government Accountability Office (GAO), 17 agencies have material vulnerabilities in their internal security systems and only 13 agencies are following proper cybersecurity risk management.

“The 23 civilian agencies covered by the Chief Financial Officers Act of 1990 (CFO Act) have often not effectively implemented the federal government’s approach and strategy for securing information systems. Until agencies more effectively implement the government’s approach and strategy, federal systems will remain at risk,” the GAO report stated.

“While agencies have gotten better at preventing and detecting intrusions into their systems, they are still vulnerable to attacks such as “phishing”—emails designed to trick staff into clicking malicious links. Moreover, many agencies have not yet fully implemented effective security programs or practices, leaving them vulnerable to future attacks,” the report added.

The GAO stated that they suggested recommendations to the Department of Homeland Security and the Office of Management and Budget to help agencies progress their detection and prevention abilities.

The Government Accountability Office recently conducted a study to evaluate the state of the Department of Defense (DOD) weapon systems cybersecurity. The legislative branch government agency stated that most of the new weapons designed by DOD are vulnerable to cyber-attacks. GAO pointed out that DOD does not even know the full extent of the problems that existed in their weapons. In the report, GOA stated that it and others have warned DOD of cyber risks for decades, until recently, DOD did not prioritize weapon systems cybersecurity.

Egress raises $40 million to accelerate data security platform development

Funding

Cybersecurity startup Egress announced that it has raised £31 million ($40 million) in a Series C financing round led by FTV Capital along with the participation of the existing investor AlbionVC. The London-based company stated the new investment will help accelerate the development of new technology across its data security platform.

Established in 2007, Egress offers a wide range of data protection services, including email and document classification and accidental send prevention. The company claims that it helps organizations with its data privacy and compliance software designed to secure unstructured data that enable them to control and secure their data and to meet the compliance requirements. The company claims that a large customer base, from government agencies to finance and utility companies, are using its security solutions. Egress’s advanced security solutions provide real-time message auditing that encrypts emails, attachments, and other sensitive content.

“Today’s heightened security threats, combined with an increasingly complex regulatory landscape, means that organizations face considerable risk from data breaches, resulting in reputational damage and significant financial loss. At Egress, we help businesses mitigate this risk by wrapping security around the user and managing their experience using machine learning and AI. This risk-based approach helps users avoid potential mistakes, such as sending information to the wrong recipients, and provides security administrators with insight into behavioral anomalies across the business,” said Tony Pepper, CEO, and co-founder of Egress.

“We are delighted to be partnering with FTV as we enter the next phase of our development. A prominent growth equity firm with an impressive track record of helping similar companies in our space to scale rapidly, FTV will bring invaluable strategic expertise to help expand our technical capabilities and business operations into new markets and geographies,” Pepper added.

As per the investment agreement, FTV partner Kyle Griswold will join the Egress board of directors. “The need for comprehensive data security systems that help prevent data breaches and maintain compliance has become one of the key strategic priorities for businesses globally,” stated Griswold. “Egress’ user-centric strategy, combined with their use of AI-driven technical innovation, is helping to tackle these challenges head-on. Their success in highly regulated markets is evidenced by their rapid growth and exceptional customer retention rates, which make them an ideal partner for FTV and an attractive solution for the financial institutions in our Global Partner Network.”

Twitter reports security bug

PM Modi Twitter

Social networking site Twitter revealed that it has discovered and fixed a security bug that could have exposed users’ phone country codes and locked accounts details.

The micro-blogging giant stated they noticed unusual activity in its Application Programming Interface (API) and observed a large amount of traffic coming from IP addresses located in China and Saudi Arabia. Twitter stated the bug was fixed on November 16, 2018, and informed the users that may have been affected due to the security bug.

“We have become aware of an issue related to one of our support forms, which is used by account holders to contact Twitter about issues with their account. We began working to resolve the issue on November 15 and it was fixed by November 16. This could be used to discover the country code of people’s phone numbers if they had one associated with their Twitter account, as well as whether or not their account had been locked by Twitter. We lock an account if it appears to be compromised or in violation of the Twitter Rules or our Terms of Service,” Twitter stated in a statement.

Twitter said the IP addresses might have been linked to state-sponsored actors, and the company is investigating on the same to find the origins. Apologizing for the incident, Twitter said, “No action is required by account holders and we have resolved the issue. We recognize and appreciate the trust you place in us, and are committed to earning that trust every day. We are sorry this happened.”

A number of social media handles like Facebook and Google+ suffered multiple data breaches this year. Facebook recently reported that it has suffered a data breach that exposed 6.8 million users’ private photos to third-party application developers. The social networking giant announced that its internal team discovered a photo API bug that allowed third-party apps to access users’ photos for 12 days between September 13 to September 25, 2018.

Google had earlier announced that it will be shutting down its social media platform Google+ for consumers by August 2019, after the disclosure of a vulnerability that exposed around 500,000 users’ personal information to third-party developers. But, in a recent media statement, the California-based firm stated that it is moving the date to April 2019. The declaration came after Google+ encountered another data breach that exposed personal information of 52.5 million users.