Home Blog Page 346

Symantec announces acquisitions of Appthority and Javelin Networks

Symantec

Symantec Corporation recently acquired Appthority and Javelin Networks to strengthen its mobile and enterprise security products and services. Symantec, better known for its Norton security software suite, stated the acquisitions reinforce the company’s commitment to protect clients against emerging threats.

Appthority, a San Francisco-based cybersecurity startup specializing in enterprise mobile threat detection, offers comprehensive Mobile Application Security Analysis services, including automated app-vetting, app-threat scoring, and continuous app analysis. The acquisition allows Symantec to use Appthority’s technology to analyze mobile apps for malicious threats and other vulnerabilities.

“Armed with Symantec’s industry-leading security research and tools, SEP Mobile integrated with Appthority technology is expected to deliver the most comprehensive Mobile Threat Defense solution, with enhanced app analysis capabilities, both in real-time and on-demand,” said Anne Bonaparte, Appthority CEO.

The acquisition of Javelin Networks allows Symantec to defend organizations against Active Directory-based attacks. Founded in 2014, Javelin Networks focuses on protecting enterprises from Microsoft Active Directory (AD) attacks. The buyout helps Symantec to integrate Javelin Networks’ technology into its endpoint security platform to prevent online intruders.

“In the cloud generation, identity management services, such as Active Directory, are a critical part of a user’s interaction with their organization’s applications and services. They are also a critical information repository that attackers regularly exploit,” said Javed Hasan, senior vice president of endpoint and data center products, Symantec. “The addition of Javelin Networks technology to our industry-leading endpoint security portfolio gives Symantec customers a unique advantage in one of the most vulnerable and critical areas of IT infrastructure. Most importantly, it can help expose exploitable backdoors in the AD and stop attacks at the point of the breach while preventing lateral movement.”

In related news, Symantec recently unveiled its largest Security Operations Center in Chennai, India. The center will provide security intelligence insights and faster detection and response through greater regional coverage and visibility of the threat landscape for customers in India and overseas.

Data breaches due to insiders increased in Q3 2018: Report

Insider Threats

The latest report on data breaches revealed that a total of 4.4 million medical records were breached in 117 health data hacks in the third quarter of 2018 affecting 4,390,512 patients’ medical history, diagnoses, addresses, and financial information.

The report, jointly prepared by security firm Protenus and DataBreaches.net, stated the number of data breaches in the third quarter increased in comparison to 3.15 million records compromised in 142 breaches in the second quarter and 1.13 million patient records compromised in 110 breaches in the first quarter. The findings of the report specified that the data heists due to insiders increased from 4,597 in the first quarter to 290,689 in the third quarter.

Of the 117 incidents in the third quarter, 86 were disclosed by healthcare providers, 13 by a health plan, 13 by business associates, and 5 by businesses, according to the report.

“It’s important to note that the number of affected patient records has continued to climb each quarter in 2018, reinforcing the need for healthcare organizations to use advanced analytics and artificial intelligence to review 100% of accesses to patient data in order to prevent these breaches from occurring and to save organizations from post-breach costs that divert money from enhancing patient care,” the report stated.

According to the report, around 51 percent of data breaches were due to hacking, while 23 percent were due to insiders. The report also specified that the Florida state reported a greater number of data hacks with 11 cyber incidents compared to Canada with 10 incidents and Texas with nine.

In related news, the security rating provider SecurityScorecard released a report titled “SecurityScorecard 2018 Healthcare Report: A Pulse on The Healthcare Industry’s Cybersecurity Risks,” which pulls data from more than 1,200 healthcare companies. The report revealed insights on how the healthcare industry performs compared to others and specific areas of cybersecurity weakness within healthcare organizations.

Almost all the banks in Pakistan hacked

Pakistan

This might be the biggest news for the people of Pakistan. Every person holding a bank account may have just become vulnerable to cyber threats, as data from almost all the banks of the nation was stolen in a recent security breach. The incident was revealed by Federal Investigation Agency’s (FIA) cybercrime chief, Captain (retd) Mohammad Shoaib.  In an interview with Geo News, he said, “Almost all [Pakistani] banks’ data has been breached. According to the reports that we have, most of the banks have been affected.”

He also said that “The hackers have stolen large amounts of money from people’s accounts,” during an interaction with DawnNewsTV, while adding that the attacks were initiated by hackers outside Pakistan“The recent attack on banks has made it quite clear that there is a need for improvement in the security system of our banks,” he added.

He informed that the FIA has reached out to the banks and its security teams where all the parties concerned will be involved in stepping up the security of Pakistan banks. “Banks are the custodians of the money people have stored in them,” Shoaib told DawnNewsTV. “They are also responsible if their security features are so weak that they result in pilferage. An element of banking fraud which is a cause of concern is that banks hide the theft [that involves them]… and the clients report [the theft] to the banks and not to us, resulting in a loss of people’s money,” he said, while adding, “We are trying to play a proactive role in preventing bank pilferage.

According to him, there are over 100 cases that the agency has currently been investigating. The agency has also arrested several gangs that have been involved in cybercrime and recovered stolen money. One of the recent apprehended gang used to withdraw money from people’s accounts while masquerading themselves as military officials.

The revelation came while responding to a report from Group-IB, a global cyber security firm, which stated that hackers had released a huge trove of credit and debit cards of Pakistan citizens on the dark web forums.

Amid these, krebsonsecurity.com recently notified that data of over 8,000 account holders of about 10 Pakistani banks were sold on the dark web recently.

The first reported incident occurred at BankIslami, in which the bank nearly lost 2.6 million rupees in theft from international payment cards. Post the incident, the bank stopped international transfers and allowed only biometrically verified payments within the nation. The central bank, State Bank of Pakistan later issued directives to all banks to ensure that cybersecurity measures are met on all vectors of banking

“Cybersecurity is an enabler to the new digital age”

Yasser N. Alswailem

Yasser N. Alswailem currently serves as the General Manager of Cyber Security for Saudi Telecom Group, and is responsible for establishing and maintaining the Group’s cybersecurity vision, strategy, and program to secure and enable the digital transformation journey in KSA in support of vision 2030. He has 15 years of applied experience in cybersecurity, enterprise risks management, corporate governance, technology audit and compliance.

Tell us about your journey in the field of cybersecurity?

My journey began when I graduated from King Saud University with a Bachelors of Science in Computer Sciences.  I was fortunate being interviewed and selected by a new and innovative company called IT Security Training & Solutions or I(TS)2.  The company was focused on leveraging security education and awareness to increase the maturity of the market.  Through that experience which lasted almost 8 years, I was able to work across dozens of projects, consultancy engagements, security technologies, and attain many cybersecurity certifications and skills.

My tenure at I(TS)2 gave me a 360-degree view of cybersecurity ranging from training to consultancy, a vast portfolio of security technologies, and introduction to Managed Security Services long before it was mainstream in the region.   After leaving I(TS)2, I enjoyed working with Dell Emerging Market, where I leveraged my expertise in digital forensics to architect solutions for very large enterprises and government agencies in Middle East. This eventually led me to a slightly different role working in Internal Audit for Mobily which the second leading telecommunications provider in Saudi Arabia.  However, when the opportunity to go back and focus on Cybersecurity presented itself at STC, I joined in 2016 as the GM and since have been working to build a world-class practice and organization.

Can you throw some light on privacy and infrastructure security policies followed by Saudi Telecom Company, especially at a time when IoT-enabled devices has caused a surge in data usage?

STC has made issues like cybersecurity, privacy, and data protection top priorities to support the companies’ ambitious digital transformation journey.  At STC, we work with our regulator, Communications & IT Commission (CITC) and Ministry of ICT as well as the newly formed National Cybersecurity Authority (NCA), to ensure our policies are protecting our subscriber and employee data.  We are in the midst of a major cybersecurity transformation program which is preparing STC for all the new and innovative opportunities and challenges from IoT, Data Analytics, broader Cloud adoption, and more.

How does cybersecurity effectively align to your business goals?

Actually, I believe it is the other way around.  We are working to ensure that our value to business achieving its goals are linked to cybersecurity.  Through education, we have won support from the business and they have worked closely with us to align as they now understand that cybersecurity is an enabler to the new digital age.  Without it, businesses and government agencies will fail to deliver the value propositions to their customers and citizens.

A number of telecom operators are looking to adopt cloud to improve efficiencies in business operations. How much is the industry aware of the cloud security and the cyber risk associated with it?

STC has invested in expanding its portfolio to provide cloud services to our clients as well as our group.  We are investing in cloud security services including assessments and audits as well as CASB and other security solutions.  The cloud like any other technology innovation is important for growing our business, so we continue to invest in our people to ensure they are aware of the challenges and risks so that we can mitigate them.

In a telecom company, a number of functions are outsourced. What are the checks that an organization should do to with the outsourced partners to ensure complete security?

Third Party Governance is critical when relying on partners and contractors to deliver critical functions in your organization.  Therefore, we have strict contracts that include requirement for all our suppliers to adopt or adhere to security policies and protocols that are equal to or better than those of STC.  We conduct regular assessments including site visits, simulations, and reviews as well as requiring independent certifications bodies to validate and affirm the security posture of a partner of vendor.

What would be your advice to a budding information security professional?

Read, then read some more.  The amount of information and online content available to information security professionals now is significantly more than when I started my career.  YouTube, Google, and so many free resources are available with valuable content.  Furthermore, online labs and training can be found by credible sources for less than $150 in many cases.  I’m always pushing my teams to read, get trained, pursue professional certifications because these are golden years in our profession and we must be prepared to meet the opportunities and challenges that come along.

More than 80% companies cyber insured in India: Report

Cyber Insurance

FICO, an analytics software company, recently suggested that 82 percent of the companies in India are cyber insured. The research and consultancy firm Ovum recently conducted a survey for FICO that included participation from more than 500 senior executives across 11 countries, including United Kingdom, the U.S., Canada, Brazil, Mexico, Germany, India, Finland, Norway, Sweden, and South Africa. Most of the participated respondents are from industries such as financial services, telecommunications, retail and e-commerce, and power and utilities.

The United Kingdom grabbed the top spot with 90 percent of the businesses having cyber insurance. India was second followed by Canada, U.S., and Brazil. While most of the business in India claimed that they are cyber insured, only half of them (48 percent) said their cybersecurity insurance covers all risks.

The survey suggested that 80 percent of Indian telecommunications firms have cybersecurity insurance, while 60 percent of firms reported they hold a comprehensive cover. However, 44 percent of the firms stated that their premiums are based on an accurate analysis of their risk profile.

“It’s is very encouraging to see the high uptake of cybersecurity insurance across India,” said Vishal Goyal, country manager for India at FICO. “India has a well-developed IT sector and is on the front-foot with this issue. The data breaches in India in the past 12 months have continued to have an impact on local businesses, so there is recognition that insurance plays an important role in risk mitigation and is an important consideration to minimizing disruption.”

“Indian companies are clearly leading the way when it comes to the take-up of cyber-insurance, with almost half having a comprehensive policy and a further one-third with at least some cover,” said Maxine Holt, research director at Ovum. “Around two-thirds of surveyed organizations in India either use software to give a breach likelihood score or use an external agency to carry out risk assessments.

A couple of months ago, FICO did a study that revealed that 62 percent of UK firms lack complete cybersecurity insurance. According to the study, only 38 percent of the UK firms surveyed had cybersecurity insurance that covered all risks.

 

Vietnam issues new cybersecurity draft decree

Vietnam cybersecurity law

The Vietnam government has released a draft declaration on guidelines to implement a new cybersecurity law to remediate the shortcomings in Vietnam’s legal corridors and ensure a secure cyberspace. The long-awaited draft recommends social media users to abide by the Constitution and legal regulations while voicing their opinion and discontent.

According to the new draft, the technology firms are required to offer a range of services, including email or social media to set up offices in Vietnam. Also, they need to store users’ data on local servers and prevent the circulation of content that’s anti-state, fake, slandering or inciting violence. The Law which will take effect on January 1, 2019, is now open for public consultation for two months.

“We applaud the Government of Vietnam for launching a public consultation and hope to work with them to reach an outcome which benefits all stakeholders in Vietnam,” said Alex Botting, director of the U.S. Chamber of Commerce’s Center for Global Regulatory Cooperation. “The text of Vietnam’s Law on Cybersecurity included some of the most draconian data localization provisions seen anywhere in the world.”

In June 2018, the Vietnam National Assembly passed the cybersecurity law amid protests and ambiguity from tech companies, rights groups, and Western governments including the United States.

The new draft will focus on social media usage, data localization, cybersecurity audit of information systems of agencies and organizations, handling illegal content, and protection of children. The Law also addresses the protection of human rights and civil rights, as well as protection of secrets of businesses, individuals and families.

It also mandates domestic and foreign telecommunications service providers to keep personal information and accounts of users secured. The type of data required to be stored ranged from job titles to contact details like credit card information, biometric data, and medical records, according to the draft decree.

Cybersecurity startup Attila Security raises $2.5 million

Cybersecurity firm Attila Security recently raised $2.5 million in a funding round led by the cybersecurity startup foundry DataTribe, Bull City Venture Partners (BCVP), and TEDCO’s Seed Fund. Attila stated the new proceeds will be used to expand its sales and marketing platform, product development, and to complete the NIAP certification of its GoSilent product suite.

“We are fortunate to have secured this round with funding from DataTribe, BCVP, and TEDCO as we continue to develop our zero-touch, next-gen products,” said Gregg Smith, CEO of Attila Security. Attila’s award-winning GoSilent technology protects government agencies and enterprises from advanced cyber-attacks.”

Based in Fulton, Attila Security offers visibility, control, and threat defense services across physical, virtual, and cloud applications. Attila claims that its products help government and private agencies secure data accessed by employees on mobile devices, servers, or in the cloud. Attila Security’s GoSilent technology includes a portable device that is a part-mobile firewall, part-virtual private network, and part-WiFi hotspot.

The company claims its GoSilent product suite was designed to protect governments and enterprises from rising cyber-attacks, zero-day threats, and personal identity theft. “The GoSilent product is smaller than a wallet and slightly bigger than a tic tac container,” Smith added.

Frank Glover, Lead Director of TEDCO’s Seed Fund said, “Attila represents a unique opportunity to back an early-stage company with sophisticated technology, large tangible market and a high-quality team at the helm. We believe Gregg Smith is the ideal leader to drive this to a big outcome for the region. We are excited to partner with the company and DataTribe to capture this opportunity.”

Is education the key to closing the cybersecurity skills gap?

Amid the perennial arguments around the skills gap that has marred the information security space, the topic of cybersecurity education usually makes an appearance. But how big really is the dearth of infosec professionals? At present, there’s a 25 percent gap between the demand for cyber talent and the existing supply.

According to a report by Peninsula Press, in 2016, more than 209,000 cybersecurity jobs in the U.S. were unfilled, “and postings are up 74 percent over the past five years.” Within months, the demand for cybersecurity professionals will increase to approximately six million globally.

How did we get here? In the late eighties, the Internet was still a very new thing most people had not even heard of, but there were a lot of early adopters who saw the potential in connecting the world’s computers. Most of these pioneers homed in on the positive, productivity-enhancing aspects of the new technology while others set out to test its limits. On November 2, 1988, a coder named Robert Tappan Morris released one of the very first malware programs in history out of his curiosity to know how quickly a malicious code could spread.

The worm, eventually dubbed the Morris Worm, infected nearly 10 percent of the internet in a span of days. The result was major damage, widespread outages, a conviction under the Computer Fraud and Abuse Act for Morris, and the creation of the CERT Coordination Center by the Defense Advanced Research Projects Agency (DARPA). The center was focused on giving experts a central point for coordinating responses to network emergencies, thus laying the foundation for information security.

Read More

Data breaches in Washington continue to rise: Report

Washington DC

In the third annual data breach report, Attorney General Bob Ferguson stated that around 3.4 million residents of Washington fell victim to data breaches between July 2017 and July 2018 and the number keeps rising.

Out of the three categories that Ferguson defined—malicious cyber-attacks, theft or mistake, and unauthorized access—malicious cyber-attacks are the leading cause of data breaches affecting Washington residents.

“Data breaches are a significant threat to Washington individuals and businesses. For the second straight year, the number of Washingtonians impacted by data breaches increased, with nearly 3.4 million Washingtonians affected in 2018. This represents a 26% increase compared to 2017 and more than 700% compared to 2016,” Ferguson stated in its report.

Further, the report also identified deficiencies in Washington state’s data breach notification law and suggested ways to strengthen the same. “The number of Washingtonians impacted by data breaches increased for the second consecutive year. We must strengthen our law to help Washingtonians secure their sensitive information,” Ferguson added.

Some recommendations to toughen Washington’s data breach notification law were:

  • Reduction in the deadline for notifying affected individuals and the Attorney General’s Office to 30 days after discovery of a breach
  • A preliminary notification to the Attorney General’s Office within ten days after the breach’s discovery
  • Expansion of the legal definition of personally identifiable information to include full dates of birth, usernames in combination with passwords, digital signatures, DNA profiles or other forms of biometric data
  • Obligation for entities to provide information about the timeline of a breach in their notices to affected individuals and the Attorney General’s Office

FIFA hacked; dark cloud of secrets may shower

FIFA

World soccer’s governing body Federation Internationale de Football Association (FIFA) has come out stating that their computer systems were hacked earlier this year. This is the second major attack on the soccer federation after 2016, when Russian military intelligence had hacked into the servers of the federation resulting in the reports of anti-doping investigations and lab results being published online.

FIFA is yet to reveal the data that was compromised, but a consortium of European media organizations has been mulling on publishing a series of reports around the internal documents. Football Leak originally were the ones who obtained the documents.

Football Leaks have been publishing several controversial since 2015. Since the leak, German weekly newsmagazine Der Spiegel had obtained a trove of information. With the volume of information that is out, Der Spiegel sought to share the documents with investigative reporting consortium called European Investigative Collaborations.

“We condemn any attempt to compromise the confidentiality, integrity and availability of data,” football’s world governing body said in a statement. “We are concerned by the fact that some information has been obtained illegally. In response to the increasing number of internet-enabled computer attacks, Fifa is continually modifying its systems and practices and allocates significant budgets for the continuous improvement of its information security posture.”

“Following a hack in March 2018, Fifa took a number of measures to improve IT security, in order to protect employees. It’s an ongoing issue, which Fifa has to face just like countless organizations around the world who are all dealing with data security challenges,” it added.