Home Blog Page 344

Cybersecurity startup Exein grabs €2M investment

Startup Funding

The cybersecurity startup Exein recently raised €2 million ($22,69,748) in Series A funding round led by the venture capital firm United Ventures. The Italy-based startup stated the new investment will help in further research and development of the EXEIN’s solutions platform.

Founded in July 2018 by Gianni Cuozzo, EXEIN seeks to secure the Internet of Things (IoT), Supervisory control, and data acquisition using its firmware security solutions. The startup is specialized in preventing security threats posed by the connected smart devices and the critical infrastructure devices by using its firmware platform that includes Offline Monitoring, Autonomous Security, Hardware Profiling, Parallel Learning, and Artificial Intelligence.

“The IOT market is set to reach $267 Billion by 2020. The SCADA market similarly reaches $32.7 Billion by the same date and with 90% of firmware unsecured, there is a clear and vital need for a unique solution like EXEIN which a retrofitting application is not only but already compatible with most firmware such as bare-metal firmware, real-time based firmware, and Linux based firmware. We are very excited to move our project forward with a fresh injection of funding from United Ventures and hope to benefit many businesses and the general public with our cybersecurity tools,” said Gianni Cuozzo, Founder, and CEO of EXEIN.

EXEIN claims that it provides a world-first firmware security software and middleware solution that can be installed in the hardware to defend it from inside.

Speaking on the investment round, Massimiliano Magrini, Co-Founder of United Ventures, commented, “Critical to the success of any start-up is the people at the helm and with EXEIN, we are investing in a very talented entrepreneur with a proven track record. A regular attendee of NATO workshops and nominated for the MIT Italy ‘Innovators Under 35 Award’, Gianni has proven excellence in combining entrepreneurial and technical capability. We are incredibly excited to be investing in his company with the mission of protecting the privacy and security of millions around the world.”

USPS site’s vulnerability exposes 60 million users’ data

United States Postal Service

A security vulnerability in the United States Postal Service (USPS) exposed more than 60 million customers’ personal information to all the users who have an account with the USPS.com. The USPS is an independent mail service agency in the United States and authorized by the United States Constitution.

However, the mail service provider patched the vulnerability recently after Brian Krebs, an investigating reporter, flagged the issue. The security flaw was first identified by an independent researcher a year ago, but USPS never patched it until this week, Krebs stated in his blog KrebsonSecurity.

Krebs stated that he was contacted by an anonymous researcher, who discovered the problem, and said he informed the USPS about his finding a year ago but never received a response. After confirming the research findings, Krebs contacted the USPS officials to report the problem.

The research findings revealed an authentication weakness in the USPS website’s API (Application Program Interface) that lets any usps.com user access other users’ information such as email address, username, user ID, account number, street address, phone number, authorized users, and mailing campaign data.

In a statement shared with KrebsOnSecurity, the USPS stated the information shared by Krebs helped them to immediately mitigate the issue. “Computer networks are constantly under attack from criminals who try to exploit vulnerabilities to illegally obtain information.  Similar to other companies, the Postal Service’s Information Security program and the Inspection Service uses industry best practices to constantly monitor our network for suspicious activity,” the UPSC added. “Any information suggesting criminals have tried to exploit potential vulnerabilities in our network is taken very seriously. Out of an abundance of caution, the Postal Service is further investigating to ensure that anyone who may have sought to access our systems inappropriately is pursued to the fullest extent of the law.”

“There is no better time than now to get into cybersecurity”

Jamal Mekdachi

Jamal Mekdachi, Head of Operations, Cyberteq, is a 20-year veteran in information technology and security. A performance-driven and result-oriented professional, Mekdachi has worked for a number of reputed organizations in the past. He talks to CISO MAG about his journey, cybersecurity skill gap, and gender neutrality in the domain.

Tell us about your journey. Why did you choose cybersecurity as a domain?

To become a good cybersecurity professional, you must be able to simulate the activities of the hacker (the robber) or the person with malicious intent as well as the security analyst (the cop). You have the opportunity to take on both roles (all in one job!), both attack and defend-how cool is that!

Cybersecurity has become critical to the fabric of any modern business. As breach after breach hits the headlines, it’s clear to everyone that organizations need more professionals focused on cybersecurity.

Security professionals get the chance to work directly with teams on technologies and systems from robots to cars to websites serving millions of users and its needed in almost every domain, from the government to corporate, military to medical, financial to personal, because each one collects, stores and transmits data, much of which is sensitive information.

As the amount of digital data and transactions grow, so does the need for cybersecurity professionals in a variety of roles. This has opened the doors to a career move for both seasoned IT professionals and those making a lateral career move into a new field.

There was a recent article that said, ‘there are millions of cybersecurity jobs waiting. And they need more than just experts’. Do you think there is a skill shortage in cybersecurity space?

There is no better time than now to get involved in the cybersecurity space. The rising demand is overtaking the number of cybersecurity experts qualified for the roles, to the point that companies are looking at Artificial Intelligence (AI) for solutions, thus so many career opportunities are available for cybersecurity professionals.

 How important is cybersecurity education or training for employees to keep cyber threats at bay?

Businesses continue to be hit harder and harder by ever increasing cyber-attacks from outside company walls and inside (employees). Employees are at the heart of every business and can be a company’s greatest asset or its biggest threat when it comes to securing sensitive data and information.

Lack of employee cybersecurity education and awareness, along with human error or careless behavior have been the cause of many major security breaches from phishing attacks luring employees to click suspicious links that contain spyware, to weak passwords and leaks on social media. All attack vectors can be avoided with effective cybersecurity awareness training. It should be conducted base on employee’s role, responsibilities and risk profile, and it should be supported with enforceable policies and keep on updating it as well as a program for testing employee cybersecurity knowledge by simulating attacks.

Moreover, it is very important to make cybersecurity awareness training part of the onboarding process.

The representation of women in cybersecurity has remained stagnant at 11 percent for the past four years. This is despite growing awareness on cybersecurity, and expanding career options. Most of the times, the reasons cited is the lack of women role model and the impression the industry carries. What can be done to break the gender stereotype so that women, even in their teens are inclined to join the cybersecurity space?

There are many initiatives that corporations can take to attract more women in cybersecurity, including specifically asking for female applicants, sponsoring more female professionals, etc. Businesses have to ensure that both men and women receive equal professional development support in their industry

What advice would you give to a budding information security professional?

Security professionals must continually adapt to stay a step ahead of cyber-criminals. This involves monitoring current trends in cyber-crime, the latest methods and exploits used by attackers to infiltrate systems, and new developments in technology

The most important quality a security professional require is a strong ethical code. They often work with highly confidential information and have access to critical infrastructure. It is important to maintain integrity and accountability.

An inquisitive nature and ingenuity in discovering new methods to achieve desired outcomes and, at a technical level, an understanding of web development, programming, security fundamentals and networking is crucial.

Get professionally certified based on your career path. Attend info and IT security training courses and conferences.

Blackberry acquires Cylance to expand its cybersecurity capabilities

Blackberry

Blackberry Limited recently announced the acquisition of AI & cybersecurity startup Cylance in a cash deal for $1.4 billion to expand its technology and cybersecurity portfolio. According to the acquisition deal, which is expected to complete by February 2019, Cylance will function as a separate entity within the BlackBerry.

Founded in 2012, Cylance help organizations with its antivirus programs and other kinds of computer software that prevent viruses and malware. The American software firm claims that it’s a pioneer in applying artificial intelligence, algorithmic science, and machine learning to cybersecurity software to predict and prevent the known and unknown cyber threats.

“Cylance’s leadership in artificial intelligence and cybersecurity will immediately complement our entire portfolio, UEM, and QNX in particular. We are very excited to onboard their team and leverage our newly combined expertise,” said John Chen, Executive Chairman and CEO of BlackBerry. “We believe adding Cylance’s capabilities to our trusted advantages in privacy, secure mobility, and embedded systems will make BlackBerry Spark indispensable to realizing the Enterprise of Things.”

Cylance claims that it’s embeddable AI technology will accelerate the development of the BlackBerry Spark EoT Platform, a platform for Ultra-secure Hyperconnectivity, in critical areas. BlackBerry enables the Enterprise of Things (EoT) with its robust technology that allows fixed endpoints to communicate securely and maintain privacy. The Ontario-based firm claims its Spark Platform is a secure chip-to-edge communications platform for the EoT that will create trusted connections between any endpoint.

“Our highly skilled cybersecurity workforce and market leadership in next-generation endpoint solutions will be a perfect fit within BlackBerry where our customers, teams, and technologies will gain immediate benefits from BlackBerry’s global reach,” said Stuart McClure, Co-Founder, Chairman, and CEO of Cylance. “We are eager to leverage BlackBerry’s mobility and security strengths to adapt our advanced AI technology to deliver a single platform.”

In related news, Blackberry disclosed a cybersecurity software dubbed Jarvis for self-driving cars earlier this year. Being offered as a pay-as-you-go service, Jarvis will allow easier evaluation of software in production with complete adherence to industry guidelines. It’s also an advanced security software for the much-arguable self-driven cars.

Coronation Merchant Bank joins hands with Irish firms on cybersecurity

Coronation Merchant Bank, a Nigeria-based investment bank, recently announced its collaboration with the Irish firms to accelerate trade promotion and strengthen cybersecurity capabilities. The cybersecurity collaboration was announced during a courtesy visit by the Irish ambassador Sean Hoy to Nigeria. The latest collaboration is intended to strengthen the bilateral relationship of Irish firms in Nigeria.

“We have already started with some Irish companies in the area of cyber technology. This is an area, as a financial institution, we have to be strong in. As an institution that is going to focus significantly on fintech, our relationship with Irish companies cannot be taken for granted,” said Abubakar Jimoh, CEO of Coronation Merchant Bank. “As an investment bank, we advise institutions that are either trying to come into Nigeria or export to countries like Ireland. We are a very young merchant bank, as we grow bigger and get established.”

Headquartered in Lagos, the Coronation Merchant Bank provides long-term financial solutions to public and private corporations, government entities, and other fintech companies.

 “Today, we are one of the leading countries in fintech. We are working with banks all over the world to provide financial solutions in a world that is becoming forever more complex. In the area of cybersecurity, which we have discussed today with Coronation, we have Irish companies providing specialized services. When I first came to Nigeria in 2014, people were afraid to use a credit card. Now, people are using credit cards all the time,” said Sean Hoy.

In related news, a survey recently revealed that Irish companies face little or no difference in day-to-day operations post Global Data Protection and Regulation (GDPR).  According to the survey by MicroWarehouse, more than half of the Irish companies do not think that the introduction of GDPR has influenced their day-to-day operations.

Indonesia and United States ink agreement on cybersecurity training

Indonesia United States

The Indonesian government has inked partnership agreement with the United States to strengthen the bilateral collaboration against transnational cyber and financial crimes.

The agreement between the Indonesian National Police and the U.S. Attorney-General’s Office is intended to increase U.S. training of Indonesian law enforcement officials to fight against cyber-attacks using digital forensics, the Straits Times reported.

The cybersecurity pact was signed by the Indonesian police chief Tito Karnavian and the US Deputy Attorney-General Rod Rosenstein on November 19, 2018, at the 87th Interpol General Assembly held in Dubai. The new alliance will see Indonesian police officers undergoing law enforcement-related training and programs led by the US Attorney-General’s Office, General Tito Karnavian stated.

“The education and training programmes will help improve the knowledge and skills of Indonesian National Police personnel,” Tito added. Describing the alliance as a strategic move, Rosenstein stated  the cybersecurity cooperation between the two countries is aimed to strengthen security capabilities against cyber threats.

The latest collaboration between Indonesia and the United States comes days after the adoption of the security leaders’ statements on cybersecurity cooperation at the 33rd ASEAN Summit, witnessed by Prime Minister Lee Hsien Loong of Singapore and the U.S. Vice-President Mike Pence.

A couple of days back, the governments of Singapore and the United States joined hands to strengthen their collaboration in the infrastructure sector, digital economy, and cybersecurity. Both countries renewed their Collaboration Platform Memorandum of Understanding (MOU) and signed a Declaration of Intent (DOI) to work together on a Singapore-US Cybersecurity Technical Assistance Program for ASEAN (Association of Southeast Asian Nations).

The MOU between the Ministry of Trade and Industry (MTI) permanent secretary Loh Khum Yean and the U.S. Embassy Singapore chargé d’affaires, ad interim, Stephanie Syptak-Ramnath is intended to extend bilateral cooperation in infrastructure areas, support the digital economy, and to work together on the Singapore-US Cybersecurity Technical Assistance Program.

Vision Direct hacked, financial data of customers at risk

cyber attack

United Kingdom-based online optical retailer Vision Direct has become the latest victim of a cyber-attack after hackers breached its website and stole customer data including their financial data. The firm notified in a release that customers who either made an ordered or updated their financial details between between 12.11am on 3 November and 12.52pm on 8 November may have had their details compromised.

“The stolen data included personal and financial details of customers logging in and making changes on the VisionDirect.co.uk website. Vision Direct has taken the necessary steps to prevent any further data theft, the website is working normally, and we are working with the authorities to investigate how this theft occurred,” Vison Direct stated in a notification. The compromised data includes the names of the customers, their phone numbers, email addresses and passwords as well as card numbers, expiry dates and CVVs.

“This data was compromised when entering data on the website and not from the Vision Direct database. The breach has been resolved and our website is working normally,” the notification read.

The payment details stored in the database were not affected unless the data was used to make any transaction during the aforementioned time duration. “There is no risk of data already stored in our database. The breach only impacted new information added or updated on the VisionDirect.co.uk website between 12.11am GMT 3rd November 2018 and 12.52pm GMT 8th November 2018,” it said.

Customers who used PayPal to make the transactions are not affected, while users of Visa, Mastercard, and Maestro are on the red zone. The optical retailers offered their apologies and have requested customers to reach out to their respective banks and follow their instructions.

According to BBC, nearly 6,600 customers may have had their financial data compromised, while,700 people had had personal data exposed. “This particular breach is known as Shoplift and was already known to our technology team, who installed a patch provided by our web platform provider to prevent this form of malware,” a spokeswoman for Vision Direct told the publication. “Unfortunately, this current incident appears to be a derivative against which the patch proved ineffective. We are continuing to investigate the breach and have made numerous steps to ensure this does not happen again.”

Dark Web Service Provider suffers cyber-attack; 6500 sites down

web application attacks

Daniel’s Hosting, a dark web hosting service provider, recently suffered a breach that affected more than 6,500 dark websites.

According to Daniel Winzen, the software developer behind the hosting service, hackers breached into Daniel’s Hosting server on November 15, 2018, bringing down the websites that hosted on the platform.

“On November 15th around 10:06 PM UTC the hosting server was logged in to via phpmyadmin and adminer with the correct hosting management password and deleted all accounts. Noteworthy, also the account “root” has been deleted, which was injected into the database at 10:53 PM UTC and deleted at 12:50 AM, shortly after remaining databases from the chat, link list and hit counter got deleted,” said Daniel Winzen in a post.

Daniel stated the attackers might have exploited a PHP zero-day bug leaked just a day before the hack, that was already fixed. However, Daniel clarified that hackers apparently used other vulnerabilities to break into the database and it’s unable to find the root cause for the incident

“To this day around 6500 Hidden Services were hosted on the server. There is no way to recover from this breach, all data is gone. I will re-enable the service once the vulnerability has been found, but right now I first need to find it. Most likely in December, the service will be back up,” Daniel added.

Daniel specified the investigation is ongoing and requested ethical hackers and other users to help find the vulnerabilities. The data that were not affected included, the mail, XMPP service, the static content, and the short-link service, Daniel stated.

The dark web hosting service providers allow users to host a website without revealing their identity. It’s considered as the underground internet which involves several illegal activities. Recently, cybercriminals have obtained unauthorized access to the U.S. voter registration databases and put them for sale in dark web forums, according to a report from threat intelligence firms Anomali and Intel 471.

Singapore and US sign MOU to collaborate on cybersecurity training

Singapore US

The governments of Singapore and United States joined hands to strengthen their collaboration in the infrastructure sector, digital economy, and cybersecurity. Both countries renewed their Collaboration Platform Memorandum of Understanding (MOU) and signed a Declaration of Intent (DOI) to work together on a Singapore-US Cybersecurity Technical Assistance Program for ASEAN (Association of Southeast Asian Nations).

The MoU exchange took place at the 33rd ASEAN Summit and was witnessed by Prime Minister Lee Hsien Loong of Singapore and the U.S. Vice-President Mike Pence.

The MOU between the Ministry of Trade and Industry (MTI) permanent secretary Loh Khum Yean and the U.S. Embassy Singapore chargé d’affaires, ad interim, Stephanie Syptak-Ramnath is intended to extend bilateral cooperation in infrastructure areas, support the digital economy, and to work together on the Singapore-US Cybersecurity Technical Assistance Program. The technical assistance program will deliver three cybersecurity training workshops on various aspects of technical cybersecurity capacity building.

Speaking on the initiative, Loh Khum Yean said, “Singapore and the US share robust and longstanding bilateral economic relations. The renewal of the US-Singapore Collaboration Platform MOU signifies our shared commitment to continue strengthening our economic partnership in order to stay relevant and useful to our businesses and industries and bring about the mutual benefit for both our countries.”

Ramnath also signed the Declaration of Intent (DOI) between the Cyber Security Agency of Singapore (CSA) and the U.S. Department of State, along with CSA chief executive David Koh.

Mr. Png Cheong Boon, CEO of Enterprise Singapore, one of the implementing agencies for the MOU, said, “The first MOU paved the way for both countries to focus on and foster collaboration in mutually beneficial opportunities in infrastructure development. Building on the progress made, the renewal of the MOU enables us to explore cooperation in other areas such as standards development and technology partnerships.”

 

Arkose Labs grabs strategic investment from PayPal

Funding

Arkose Labs, an online fraud prevention technology provider, recently announced that PayPal has made a strategic investment in the company. Arkose stated the new investment will be used to expand its product range and marketing capabilities.

PayPal, an American-based online payment system, stated the new investment represents the increasing momentum of cybersecurity startup in the online fraud prevention platform.

“When it comes to online e-commerce and financial transactions, PayPal is the titan of the industry,” said Kevin Gosschalk, CEO of Arkose Labs. “Their strategic investment in Arkose Labs signals their continued commitment to fighting fraud and ensuring that millions of users around the world can confidently complete transactions whether they are online, on a mobile device, in an app, or in person.”

Based out in California, Arkose Labs help preventing online fraud for global organizations in various sectors like travel, banking, social media, online communities and marketplaces, ticketing and gaming. The company claims its sophisticated global telemetry and user behavioral risk assessment provides immediate feedback insights on attacker identification.

“Our customers are some of the most respected global brands, and we are seeing some alarming statistics when we look at the combined data on our platform. We see a 10-to-1 ratio in automated, fraudulent login attempts versus legitimate account logins. Furthermore, these attacks are only one method that bad actors are using to commit fraud. We have prevented over $100 million of fraudulent activity within our customer base over the last 12 months,” Gosschalk added.

In related news, a survey published by MarketsandMarkets predicted the Fraud Detection and Prevention Market is expected to grow from USD 16.62 Billion in 2017 to $41.59 billion by 2022 at a Compound Annual Growth Rate (CAGR) of 20.1 percent.  It also revealed the demand for solutions, which can help enterprises detect fraudulent activities and prevent them from occurring, is increasing with a high growth rate. The number of frauds is increasing at a stagnant rate, but it is the increase in the revenue loss that is driving the demand for FDP solutions.